Revoke a specific user session by its ID, optionally revoking associated target grants and tokens.
Query parameters
-
Optional target for revoking associated grants and tokens. 'all' revokes grants for every application authorized by this session. 'firstParty' revokes only first-party app grants; third-party app grants remain active. If omitted, grants remain active when the session authorizations include offline_access; otherwise they are revoked.
Values are
allorfirstParty.
DELETE
/api/users/{userId}/sessions/{sessionId}
curl \
--request DELETE 'https://[tenant_id].logto.app/api/users/{userId}/sessions/{sessionId}' \
--header "Authorization: Bearer $ACCESS_TOKEN"