Skip to main content
Send either the current access token or a refresh token belonging to the connection.
Public clients omit client_secret and identify the same PKCE-enabled client used to create the connection. Revocation deletes the active access token, invalidates the refresh-token family, and removes webhook endpoints owned by that OAuth connection. It does not delete links or other workspace resources created through the connection. The endpoint returns an empty JSON object for a successful request, including when the supplied token is already invalid or unknown. This makes disconnect operations idempotent without revealing token state.