Sign somebody out everywhere
const url = 'https://api.sloose.com/staff/people/c1d2e3f4/sessions/revoke';const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.sloose.com/staff/people/c1d2e3f4/sessions/revoke \ --header 'Authorization: Bearer <token>'Backoffice route: a staff session, or ADMIN_TOKEN. Ends every session this person holds, in every org — a session is a row, so this deletes them and the next request with any of those bearers is unauthenticated. Their API tokens are not touched: those belong to an org, not a person, and are revoked from the org’s own Tokens tab. Written down as user.sessions.revoke.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”The person
Example
c1d2e3f4The person
Responses
Section titled “Responses”Signed out.
object
Sessions ended.
Examplegenerated
{ "revoked": 1}A bearer that is neither the token nor a live session (code: AUTH_REQUIRED).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}A customer’s session, an API token, or no bearer at all — not staff, and not the ADMIN_TOKEN (code: ADMIN_REQUIRED).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}No such person, or it is not visible to this session.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}