> ## Documentation Index
> Fetch the complete documentation index at: https://learn.biq.li/llms.txt
> Use this file to discover all available pages before exploring further.

# Revoke a connection

> Invalidate an OAuth installation and remove its owned webhook endpoints.

```http theme={null}
POST https://biq.li/api/v1/oauth/revoke
Content-Type: application/x-www-form-urlencoded
```

Send either the current access token or a refresh token belonging to the
connection.

| Field | Required | Description |
| :- | :- | :- |
| `client_id` | Yes | OAuth client ID |
| `client_secret` | Confidential clients | Current client secret |
| `token` | Yes | Access or refresh token to revoke |

```bash theme={null}
curl --request POST \
  --url https://biq.li/api/v1/oauth/revoke \
  --header 'Content-Type: application/x-www-form-urlencoded' \
  --data-urlencode 'client_id=YOUR_CLIENT_ID' \
  --data-urlencode 'client_secret=YOUR_CLIENT_SECRET' \
  --data-urlencode 'token=TOKEN_TO_REVOKE'
```

Public clients omit `client_secret` and identify the same PKCE-enabled client
used to create the connection.

Revocation deletes the active access token, invalidates the refresh-token
family, and removes webhook endpoints owned by that OAuth connection. It does
not delete links or other workspace resources created through the connection.

The endpoint returns an empty JSON object for a successful request, including
when the supplied token is already invalid or unknown. This makes disconnect
operations idempotent without revealing token state.
