Skip to main content
POST
Create an access revocation

Completing a revocation

This endpoint starts a revocation, but there is no endpoint to mark one complete. For an application without a provisioning integration, the revocation stays pending until someone uses Mark as removed in the UI (on the user profile, under Revocations in progress, click the magnifying glass next to the app, then the three-dot menu).
Revoking access states does not offboard a user. There is no endpoint to trigger an offboarding, no inbound webhook, and suspending the user’s account in your directory does not start an offboarding on its own. Revoking every access state and suspending the directory account leaves the user Active in AccessOwl and sends no offboarding notification, because the Offboard action never ran. Offboardings start from Slack, the web app, or an HRIS source only. If you automate employee lifecycle events outside AccessOwl, connect an HRIS integration as the trigger instead. Reactivating someone returning from leave is manual today, use the Reactivate button on their profile.

Authorizations

Authorization
string
header
required

Bearer token authentication. Pass your AccessOwl API token in the Authorization header as Bearer <token>.

Headers

Idempotency-Key
string

Optional key (1–255 chars) for safely retrying a request. Reusing the same key for the same request returns 409 Conflict and is not processed again — this confirms the request was already received. Keys are retained for 14 days.

Required string length: 1 - 255

Body

application/json

Access revocation parameters

Request body for creating an access revocation from an access state

access_state_id
string<uuid>
required

Access state ID identifying the access to revoke

reason
string
required

Reason for the revocation

Maximum string length: 255

Response

Access revocation created

An access revocation

application_id
string<uuid>
required

Application ID

id
string<uuid>
required

Access revocation ID

reason
string
required

Revocation reason

status
enum<string>
required

Current status of the revocation

Available options:
processing_access,
rejected,
revoked
grantee_user_id
string<uuid>

User ID of the grantee

inserted_at
string<date-time>

Creation timestamp

permission_ids
string<uuid>[] | null

Permission IDs being revoked

provisioning_type
enum<string> | null

Provisioning type

Available options:
application_admin,
automatic
requestor_user_id
string<uuid>

User ID of the requestor

resource_id
string<uuid> | null

Resource ID (null for app-wide revocations)

Last modified on August 28, 2026