Skip to content

Revoke all tenant sessions

POST/tenants/{tenant_id}/session-controls/revoke-all

Immediately invalidates all active user sessions within the tenant workspace by inserting a session revocation fence. Subsequent API calls from existing session tokens will receive 401 responses. Use in response to a suspected account compromise or during a forced password reset event.

Request

Path parameters

NameTypeRequiredDescription
tenant_idstringYes

The tenant identifier.

Request body

Content type application/json.

FieldTypeRequiredDescription
reasonstringNo

Reason for the revocation, recorded in the audit log.

Max length: 255

Example

{
  "reason": "Credential exposure suspected after phishing report from tenant admin."
}

Responses

200 All tenant sessions revoked. Existing tokens are immediately invalidated

Content type application/json, object.

FieldTypeRequiredDescription
revoked_atstring (date-time)No

Timestamp of the revocation fence; sessions established before this time are invalidated.

Example

{
  "revoked_at": "2026-04-08T15:00:00Z"
}

404 Tenant not found

Example request

Paths are relative to the control-plane API base URL ($BASE_URL below).

curl -X POST "$BASE_URL/tenants/{tenant_id}/session-controls/revoke-all" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"reason": "Credential exposure suspected after phishing report from tenant admin."}'
Loading