Skip to main content
DELETE
Revoke an API key

Authorizations

Authorization
string
header
required

Either a Supabase user access token (from a password login, or the passwordless magic-link flow) or a long-lived forge_sk_… API key. Both are sent as Authorization: Bearer <value> and resolve to the same owner, so every endpoint accepts either. Session tokens expire in ~1h; API keys do not expire and are the credential for MCP clients, CI, and partner integrations.

Path Parameters

key_id
string
required

The key id from the listing (never the key itself).

Response

Revoked

ok
boolean
id
string