Skip to main content
POST
Create an access revocation

Authorizations

Authorization
string
header
required

Bearer token authentication. Pass your AccessOwl API token in the Authorization header as Bearer <token>.

Headers

Idempotency-Key
string

Optional key (1–255 chars) for safely retrying a request. Reusing the same key for the same request returns 409 Conflict and is not processed again — this confirms the request was already received. Keys are retained for 14 days.

Required string length: 1 - 255

Body

application/json

Access revocation parameters

Request body for creating an access revocation from an access state

access_state_id
string<uuid>
required

Access state ID identifying the access to revoke

reason
string
required

Reason for the revocation

Maximum string length: 255

Response

Access revocation created

An access revocation

application_id
string<uuid>
required

Application ID

id
string<uuid>
required

Access revocation ID

reason
string
required

Revocation reason

status
enum<string>
required

Current status of the revocation

Available options:
processing_access,
rejected,
revoked
grantee_user_id
string<uuid>

User ID of the grantee

inserted_at
string<date-time>

Creation timestamp

permission_ids
string<uuid>[] | null

Permission IDs being revoked

provisioning_type
enum<string> | null

Provisioning type

Available options:
application_admin,
automatic
requestor_user_id
string<uuid>

User ID of the requestor

resource_id
string<uuid> | null

Resource ID (null for app-wide revocations)