Revoke all tenant sessions
POST/tenants/{tenant_id}/session-controls/revoke-all
Immediately invalidates all active user sessions within the tenant workspace by inserting a session revocation fence. Subsequent API calls from existing session tokens will receive 401 responses. Use in response to a suspected account compromise or during a forced password reset event.
Request
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
tenant_id | string | Yes | The tenant identifier. |
Request body
Content type application/json.
| Field | Type | Required | Description |
|---|---|---|---|
reason | string | No | Reason for the revocation, recorded in the audit log. Max length: 255 |
Example
{
"reason": "Credential exposure suspected after phishing report from tenant admin."
}
Responses
200 All tenant sessions revoked. Existing tokens are immediately invalidated
Content type application/json, object.
| Field | Type | Required | Description |
|---|---|---|---|
revoked_at | string (date-time) | No | Timestamp of the revocation fence; sessions established before this time are invalidated. |
Example
{
"revoked_at": "2026-04-08T15:00:00Z"
}
404 Tenant not found
Example request
Paths are relative to the control-plane API base URL ($BASE_URL below).
curl -X POST "$BASE_URL/tenants/{tenant_id}/session-controls/revoke-all" \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-d '{"reason": "Credential exposure suspected after phishing report from tenant admin."}'