Revoke an API key
Permanently revoke a key — do this the moment one might have leaked. Owner-scoped: a key id that is not on the calling account is a 404 even if it exists elsewhere. An already-running server may honour the revoked key for up to API_KEY_CACHE_TTL_S (default 60s) while its auth cache expires.
Authorizations
Either a Supabase user access token (from a password login, or the passwordless magic-link flow) or a long-lived forge_sk_… API key. Both are sent as Authorization: Bearer <value> and resolve to the same owner, so every endpoint accepts either. Session tokens expire in ~1h; API keys do not expire and are the credential for MCP clients, CI, and partner integrations.
Path Parameters
The key id from the listing (never the key itself).

