본문 바로가기
WIKI 기술 지식 베이스

조직 API 토큰 폐기

원문 보기 위키 갱신

조직 API 토큰 폐기 (Revoke Organization API Token)

조직에 묶인 토큰을 무효화하는 엔드포인트예요. 경로에서 토큰 이름이 아니라 ID를 받는다는 점이 특징이에요.

출처: 문서

본문

Revokes a token scoped to this organization.

경로가 토큰 이름이 아니라 토큰 ID를 받는 이유는, 이름은 사용자별로만 고유하고 사용자 사이에서는 고유하지 않기 때문이에요. 관리자가 멤버의 토큰을 폐기할 때 이름만으로는 구분할 수 없어요.

인가 규칙은 목록 조회 엔드포인트와 대칭을 이뤄요:

  • 관리자와 소유자는 조직에 묶인 모든 토큰(누가 발급했는지와 무관하게 조직 범위·그룹 범위 모두)을 폐기할 수 있어요.
  • 멤버와 뷰어는 자신이 발급한 토큰만 폐기할 수 있어요.

다른 조직에 묶인 토큰을 대상으로 하면 403이 아니라 404를 돌려줘요. 그래서 이 엔드포인트는 다른 조직의 토큰 ID 존재 여부를 새어 나르지 않아요. 무제한 토큰도 여기서는 다룰 수 없고, DELETE /v1/auth/api-tokens/{tokenName}으로 폐기해야 해요.

이 엔드포인트는 토큰 이름이 아닌 토큰 **ID**를 받아요. 조직 안에서 토큰 이름은 사용자 사이에서 고유하지 않기 때문이에요. 관리자와 소유자는 조직에 묶인 모든 토큰을, 멤버와 뷰어는 자기 토큰만 폐기할 수 있어요. 무제한 토큰은 [`DELETE /v1/auth/api-tokens/{tokenName}`](https://docs.turso.tech/api-reference/tokens/revoke)으로 폐기하세요. ```bash cURL theme={null} curl -L -X DELETE 'https://api.turso.tech/v1/organizations/{organizationSlug}/api-tokens/{tokenId}' \ -H 'Authorization: Bearer ***' ```

OpenAPI

openapi: 3.0.1
info:
  title: Turso Platform API
  description: API description here
  license:
    name: MIT
  version: 0.1.0
servers:
  - url: https://api.turso.tech
    description: Turso's Platform API
security: []
paths:
  /v1/organizations/{organizationSlug}/api-tokens/{tokenId}:
    delete:
      summary: Revoke Organization API Token
      description: >-
        Revokes a token scoped to this organization.


        The path takes a token **ID**, not a name, because names are unique per
        user but not across users — an admin revoking a member's token can't
        disambiguate by name alone.


        Authorization is symmetric with the list endpoint:


        - **Admins and owners** can revoke any token scoped to the organization
        (org-scoped or group-scoped, regardless of who minted it).

        - **Members and viewers** can revoke only tokens they minted themselves.


        A token scoped to a different organization returns `404`, not `403`, so
        the endpoint does not leak the existence of cross-org token IDs.
        Unrestricted tokens are also unreachable here and must be revoked via
        [`DELETE
        /v1/auth/api-tokens/{tokenName}`](/api-reference/tokens/revoke).
      operationId: revokeOrganizationAPIToken
      parameters:
        - $ref: '#/components/parameters/organizationSlug'
        - name: tokenId
          in: path
          required: true
          schema:
            type: string
          description: The ID of the token to revoke (from the list endpoint).
          example: clGFZ4STEe6fljpFzIum8A
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  token:
                    type: string
                    description: The ID of the revoked token.
                    example: clGFZ4STEe6fljpFzIum8A
components:
  parameters:
    organizationSlug:
      in: path
      name: organizationSlug
      required: true
      schema:
        type: string
      description: The slug of the organization or user account.

더 알아보기 (Learn more)