0D54z000080gJh8CAEOkta Classic EngineAuthenticationAnswered2024-04-02T16:23:39.000Z2022-08-25T02:09:52.000Z2022-08-26T07:41:27.000Z

OliverY.69040 (Customer) asked a question.

Revoke the access token using `/revoke` doesn't invalid the token using authorization server

Hi Community I try to follow the example to revoke the access token.

```

import requests

import base64

 

data = {

"token": token,

"token_type_hint": "access_token,

}

credential = f"{OKTA_CLIENT_ID}:{OKTA_CLIENT_SECRET}"

headers = {"Authorization": f"Basic {base64.b64encode(credential.encode()).decode()}"}

requests.post(url="https://${my_domain}/oauth2/v1/revoke", data=data, headers=headers)

```

 

However, when I try to valid if the revoke successfully by requesting "\introspect"

 

```

response = requests.post(url="https://${my_domain}/oauth2/default/v1/introspect", data=data, headers=headers)

```

 

It still shows the token is active. Any idea? Here's the setting of my app.

 


  • JaniK.29243 (Customer)

    Hi @OliverY.69040 (Customer)​,

     

    Looks like you're possibly missing some required headers? These below are from Okta's Postman collection.

     

    postman OIDC revoke token 

    -Jani

    Expand Post
  • OliverY.69040 (Customer)

    Thanks. Ends up the problem is the url is incorrect. It should be oauth2/default/v1/revoke (with `default`). Not sure why it returns 200 even the url is incorrect. 😅 Hopefully someone could clarify a bit more about why we need to include `default` in the url.

This question is closed.

Recommended content

No recommended content found...