Skip to content

Signin  >  Operations  >  revoke_o_auth2_token_with_iam

revoke_o_auth2_token_with_iam

Operation

revoke_o_auth2_token_with_iam async

revoke_o_auth2_token_with_iam(input: RevokeOAuth2TokenWithIAMInput, plugins: list[Plugin] | None = None) -> RevokeOAuth2TokenWithIAMOutput

Grants permission to revoke an OAuth 2.0 refresh token and its associated refresh tokens Revokes a refresh_token issued by AWS Sign-In, invalidating the entire token chain so that the refresh_token can no longer be used to mint new access_tokens. Idempotency: revoking an already-revoked, expired, or otherwise invalid token still returns 200 OK with an empty body. Only the refresh_token type is accepted.

Parameters:

Name Type Description Default
input RevokeOAuth2TokenWithIAMInput

An instance of RevokeOAuth2TokenWithIAMInput.

required
plugins list[Plugin] | None

A list of callables that modify the configuration dynamically. Changes made by these plugins only apply for the duration of the operation execution and will not affect any other operation invocations.

None

Returns:

Type Description
RevokeOAuth2TokenWithIAMOutput

An instance of RevokeOAuth2TokenWithIAMOutput.

Input

RevokeOAuth2TokenWithIAMInput dataclass

Input structure for RevokeOAuth2TokenWithIAM operation RFC 7009 §2.1 revocation request. Contains the refresh_token to revoke.

Attributes

token class-attribute instance-attribute
token: str | None = field(repr=False, default=None)

The refresh_token to revoke. Must be a refresh_token issued by AWS Sign-In (prefix "ASOR"); access_tokens are not accepted for revocation.

Output

RevokeOAuth2TokenWithIAMOutput dataclass

Output structure for RevokeOAuth2TokenWithIAM operation RFC 7009 §2.2 revocation response. The endpoint returns 200 OK with an empty body on success; there are no response fields.

Attributes

response_metadata class-attribute instance-attribute
response_metadata: ResponseMetadata = field(default=EMPTY_RESPONSE_METADATA, repr=False, compare=False)

Metadata about the response that produced this output. Use this to recover the request identifiers a service's support team needs in order to investigate a call. Members of the metadata are individually optional.