
OliverY.69040 (Customer) asked a question.
Revoke the access token using `/revoke` doesn't invalid the token using authorization server
Hi Community I try to follow the example to revoke the access token.
```
import requests
import base64
data = {
"token": token,
"token_type_hint": "access_token,
}
credential = f"{OKTA_CLIENT_ID}:{OKTA_CLIENT_SECRET}"
headers = {"Authorization": f"Basic {base64.b64encode(credential.encode()).decode()}"}
requests.post(url="https://${my_domain}/oauth2/v1/revoke", data=data, headers=headers)
```
However, when I try to valid if the revoke successfully by requesting "\introspect"
```
response = requests.post(url="https://${my_domain}/oauth2/default/v1/introspect", data=data, headers=headers)
```
It still shows the token is active. Any idea? Here's the setting of my app.

Hi @OliverY.69040 (Customer),
Looks like you're possibly missing some required headers? These below are from Okta's Postman collection.
-Jani
Thanks. Ends up the problem is the url is incorrect. It should be oauth2/default/v1/revoke (with `default`). Not sure why it returns 200 even the url is incorrect. 😅 Hopefully someone could clarify a bit more about why we need to include `default` in the url.