Skip to navigation

End a session

Ends the session the refresh token belongs to, immediately — no grace window applies. If the token was spent moments ago by a concurrent refresh, its successor is revoked too, so the session still ends. The access token stays valid until it expires — that is inherent to stateless JWT — so a client should also discard its own copy of both tokens.

Refuses API-token auth: a token minted for automation must not be able to end its owner’s interactive session.

Authentication

AuthorizationBearer

JWT access token obtained from POST /api/v1/auth/login, or a finput_sk_... API token

Request

This endpoint expects an object.
refreshstringRequired
The refresh token for the session to end.

Response

Logged out. No body.

Errors

400
Bad Request Error
403
Forbidden Error