KintsugiKintsugi

Revoke an API key

DELETE/api-keys/{api_key_id}

Revoke an API key. Requires a user credential (an Owner or Admin) or a PORTFOLIO-scope Api-Key. Select an organization with an Organization-Id to revoke one of its keys; omit it to revoke a portfolio key if you are a portfolio Owner or Admin bearer. A PORTFOLIO Api-Key caller must always send Organization-Id naming a client in its own portfolio and can revoke only that client's keys; it can never revoke the portfolio's own portfolio-wide key. Returns 404 if the key is not one you can revoke; the response is empty on success.

Authorization

Api-KeystringRequired

Your secret API key. Include it with every request.

Headers

Api-Versiondate

Release date, as YYYY-MM-DD. Defaults to 2026-07-21.

Organization-Idstring

Target organization id (Organization-Id selector). Omit to manage portfolio keys as a bearer. Required for a PORTFOLIO-scope Api-Key, which may only manage one client org's keys at a time.

Connection-Idstring

Target connection id; resolves to its organization.

Entity-Idstring

Platform entity id; resolves to a connection's organization.

Entity-Sourcestring

Optional source to disambiguate an Entity-Id.

Path parameters

api_key_idstringRequired

Opaque identifier of the API key to revoke. Treat as opaque.

Response

204

Successful Response

400

The request was invalid.

401

Authentication failed or was missing.

403

The credential is not permitted for this request.

404

The requested resource was not found.

409

The request conflicts with existing state.

422

The request failed validation.

503

A service this request depends on was unavailable. Retry the request.

cURL
DELETE /api-keys/{api_key_id}
-H "Api-Key: ***"
-H "Api-Version: 2026-07-21"
Example request
https://api.trykintsugi.com/api-keys/{api_key_id}
Response
{
"code": "invalid_request",
"message": "The API key could not be revoked as requested.",
"requestId": "req_8f3k2mNpQr7Ls",
"errors": []
}
Revoke an API key (2026-07-21) | Kintsugi API Reference