Skip to main content
POST
Revoke an embed session
πŸ”’ Admin only. Requires administrator privileges β€” the authenticated principal (API key, embed JWT, or any bearer token) must belong to a user with the admin role. Ends an embed session from the server side β€” call it from your application’s logout handler. Pass the sessionId that POST /api/v1/embed/generate-session returned. Works in either state the session can be in: an id that has not been exchanged yet can no longer be redeemed via POST /api/v1/embed/session/token, and the token an already-exchanged id produced is rejected with 401 from this moment on. The embedded iframe does not tear itself down β€” remove it on logout as before. Idempotent: revoking an unknown, expired or already-revoked id also responds 204 β€” so the response alone never tells you whether a token was still revocable. That depends on Cube, not on the client library you call from: only tokens Cube issued after this endpoint shipped carry the claim revocation is checked against, and an older token keeps working until it expires on its own, within 24 hours. A Cube API token the embed obtained from POST /api/v1/deployments/{deploymentId}/token is a separate credential and is not affected. Embedding must be enabled for the account, otherwise 403 is returned.

Authorizations

Authorization
string
header
required

Token authentication. Send Authorization: Bearer <YOUR_TOKEN>.

Body

application/json

RevokeEmbedSessionInput

sessionId
string
required

The session id returned by POST /api/v1/embed/generate-session. Works whether or not the session has already been exchanged for a token.

Pattern: ^[0-9a-f]{32}$

Response

Successful response