Logout Current Session
const url = 'https://example.com/auth/logout/session/';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"refresh_token":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/auth/logout/session/ \ --header 'Content-Type: application/json' \ --data '{ "refresh_token": "example" }'Revoke only the presented session’s refresh-token family.
Other devices and API keys survive. Access JWTs remain usable until their normal expiry; /logout/ still immediately revokes every access and refresh session. A valid signed access JWT with sid, a refresh body token, or a refresh cookie authorizes this operation. Legacy JWTs without sid must use the refresh credential. Cookie authorization requires double-submit CSRF.
Bearer/body revocation does not change cookies, allowing a captured old session to be discarded safely after a newer login. Cookie authorization clears the browser’s refresh and CSRF cookies.
Parameters
Section titled “ Parameters ”Header Parameters
Section titled “ Header Parameters ”Request Body
Section titled “ Request Body ”object
Example generated
{ "refresh_token": "example"}Responses
Section titled “ Responses ”Successful Response
Bad request — invalid query parameters or payload
Unauthorized — missing or invalid credentials
Forbidden — caller lacks access to this resource
Not found
Validation error
Too many requests — retry after the advertised interval
Headers
Section titled “ Headers ”Seconds until the request may be retried
Internal server error
Service unavailable — the database could not serve the request