Revoke API Key
curl --request DELETE \
--url https://api.zbdpay.com/api/v1/rewards/app/{rewardsAppId}/api-key/{apiKeyId} \
--header 'Authorization: <authorization>' \
--header 'z-client: <z-client>'import requests
url = "https://api.zbdpay.com/api/v1/rewards/app/{rewardsAppId}/api-key/{apiKeyId}"
headers = {
"z-client": "<z-client>",
"Authorization": "<authorization>"
}
response = requests.delete(url, headers=headers)
print(response.text)const options = {
method: 'DELETE',
headers: {'z-client': '<z-client>', Authorization: '<authorization>'}
};
fetch('https://api.zbdpay.com/api/v1/rewards/app/{rewardsAppId}/api-key/{apiKeyId}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.zbdpay.com/api/v1/rewards/app/{rewardsAppId}/api-key/{apiKeyId}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "DELETE",
CURLOPT_HTTPHEADER => [
"Authorization: <authorization>",
"z-client: <z-client>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.zbdpay.com/api/v1/rewards/app/{rewardsAppId}/api-key/{apiKeyId}"
req, _ := http.NewRequest("DELETE", url, nil)
req.Header.Add("z-client", "<z-client>")
req.Header.Add("Authorization", "<authorization>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.delete("https://api.zbdpay.com/api/v1/rewards/app/{rewardsAppId}/api-key/{apiKeyId}")
.header("z-client", "<z-client>")
.header("Authorization", "<authorization>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.zbdpay.com/api/v1/rewards/app/{rewardsAppId}/api-key/{apiKeyId}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Delete.new(url)
request["z-client"] = '<z-client>'
request["Authorization"] = '<authorization>'
response = http.request(request)
puts response.read_body{
"success": true,
"message": "API key revoked successfully."
}
API Keys
Revoke API Key
Revoke an API key to prevent it from being used for authentication
DELETE
/
api
/
v1
/
rewards
/
app
/
{rewardsAppId}
/
api-key
/
{apiKeyId}
Revoke API Key
curl --request DELETE \
--url https://api.zbdpay.com/api/v1/rewards/app/{rewardsAppId}/api-key/{apiKeyId} \
--header 'Authorization: <authorization>' \
--header 'z-client: <z-client>'import requests
url = "https://api.zbdpay.com/api/v1/rewards/app/{rewardsAppId}/api-key/{apiKeyId}"
headers = {
"z-client": "<z-client>",
"Authorization": "<authorization>"
}
response = requests.delete(url, headers=headers)
print(response.text)const options = {
method: 'DELETE',
headers: {'z-client': '<z-client>', Authorization: '<authorization>'}
};
fetch('https://api.zbdpay.com/api/v1/rewards/app/{rewardsAppId}/api-key/{apiKeyId}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.zbdpay.com/api/v1/rewards/app/{rewardsAppId}/api-key/{apiKeyId}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "DELETE",
CURLOPT_HTTPHEADER => [
"Authorization: <authorization>",
"z-client: <z-client>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://api.zbdpay.com/api/v1/rewards/app/{rewardsAppId}/api-key/{apiKeyId}"
req, _ := http.NewRequest("DELETE", url, nil)
req.Header.Add("z-client", "<z-client>")
req.Header.Add("Authorization", "<authorization>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.delete("https://api.zbdpay.com/api/v1/rewards/app/{rewardsAppId}/api-key/{apiKeyId}")
.header("z-client", "<z-client>")
.header("Authorization", "<authorization>")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.zbdpay.com/api/v1/rewards/app/{rewardsAppId}/api-key/{apiKeyId}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Delete.new(url)
request["z-client"] = '<z-client>'
request["Authorization"] = '<authorization>'
response = http.request(request)
puts response.read_body{
"success": true,
"message": "API key revoked successfully."
}
Use this endpoint to immediately prevent it from being used for authentication with your Rewards App.
Revoking an API key immediately prevents it from being used for authentication. Any services using this key will no longer be able to access your Rewards App.
If Send Reward v2 is using this API key, it will stop working once the key is revoked, as the key becomes invalid.
Permanent Action. Once revoked, an API key cannot be reactivated. You will need to create a new API key if needed.
Configuration
Header Parameters
string
required
Client identifier (use
“developer-dashboard” )string
required
Bearer token for authenticationFormat:
Bearer {JWT_TOKEN}Path Parameters
string
required
Your Rewards App ID
string
required
The ID of the API key to revoke
Get this ID from the “List API Keys” endpoint
{
"success": true,
"message": "API key revoked successfully."
}
{
"success": false,
"message": "Invalid UUID"
}
{
"success": false,
"message": "Authentication required"
}
{
"success": false,
"message": "Developer does not own this app"
}
{
"success": false,
"message": "API key not found or does not belong to this app"
}
{
"success": false,
"message": "Internal server error"
}
Response Fields
| Field | Type | Description |
|---|---|---|
success | boolean | Whether the revocation was successful |
message | string | Confirmation message |
Response Status Codes
| Code | Description |
|---|---|
200 | API key revoked successfully |
400 | Bad request - invalid UUID |
401 | Unauthorized - authentication required |
403 | Forbidden - developer does not own this app |
404 | API key not found or does not belong to this app |
500 | Internal server error |
Code Examples
const rewardsAppId = 'YOUR_REWARDS_APP_ID';
const apiKeyId = 'YOUR_API_KEY_ID';
const jwtToken = 'YOUR_JWT_TOKEN';
async function revokeApiKey(rewardsAppId, apiKeyId) {
const response = await fetch(
`https://api.zbdpay.com/api/v1/rewards/app/${rewardsAppId}/api-key/${apiKeyId}`,
{
method: 'DELETE',
headers: {
'z-client': 'developer-dashboard',
'Authorization': `Bearer ${jwtToken}`
}
}
);
const data = await response.json();
if (data.success) {
console.log('✅ API key revoked successfully!');
console.log('This key can no longer be used for authentication.');
return data;
} else {
throw new Error(`Failed: ${data.message}`);
}
}
// Revoke key
await revokeApiKey(
'b28e0306-2c06-4092-8d56-a1623d6b97fb',
'78b411d8-1f61-4824-97c6-e3c3a571f1c5'
);
curl --location --request DELETE 'https://api.zbdpay.com/api/v1/rewards/app/{rewardsAppId}/api-key/{apiKeyId}' \
--header 'z-client: developer-dashboard' \
--header 'Authorization: Bearer {JWT_TOKEN}'
import requests
import os
jwt_token = os.getenv('JWT_TOKEN')
def revoke_api_key(rewards_app_id, api_key_id):
"""Revoke an API key to prevent authentication"""
url = f"https://api.zbdpay.com/api/v1/rewards/app/{rewards_app_id}/api-key/{api_key_id}"
headers = {
"z-client": "developer-dashboard",
"Authorization": f"Bearer {jwt_token}"
}
response = requests.delete(url, headers=headers)
data = response.json()
if data["success"]:
print("✅ API key revoked successfully!")
print("This key can no longer be used for authentication.")
return data
else:
raise Exception(f"Failed: {data['message']}")
# Revoke key
revoke_api_key(
"b28e0306-2c06-4092-8d56-a1623d6b97fb",
"78b411d8-1f61-4824-97c6-e3c3a571f1c5"
)
What Happens After Revocation?
Before Revocation API Key Active
Key can be used for authentication
After Revocation API Key Revoked
Key can no longer authenticate
Try It Out
Ready to revoke an API key? Use our API playground on the right to test with your JWT token.Was this page helpful?
⌘I