Skip to content
POST
/v1/organizations/{organizationId}/projects/{projectId}/environments/{environmentId}/service-principals/{principalId}/grants/{grantId}/revoke

Revoke a Grant for an Environment-scoped ServicePrincipal

Permanently revoke one Grant while preserving its lifecycle metadata.

Authentication

Send an API key as a Bearer token in the Authorization header.

Parameters

NameLocationRequiredDescription
organizationIdpathYes
The Organization to address.
stringA Cantora Organization identifier, prefixed with `org_`.
  • maximum length 64
  • pattern ^org_[\s\S]+$
projectIdpathYes
The Project to address.
stringA Cantora Project identifier, prefixed with `proj_`.
  • maximum length 64
  • pattern ^proj_[\s\S]+$
environmentIdpathYes
The Environment to address.
stringA Cantora Environment identifier, prefixed with `env_`.
  • maximum length 64
  • pattern ^env_[\s\S]+$
principalIdpathYes
The Principal to address.
stringA Cantora Principal identifier, prefixed with `principal_`.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
grantIdpathYes
The Grant to address.
stringA Cantora Grant identifier, prefixed with `grant_`.
  • maximum length 64
  • pattern ^grant_[\s\S]+$

Responses

200GrantMetadata
application/json
401Unauthorized
application/json
403Forbidden
application/json
404NotFound
application/json

Reusable schemas

GrantMetadataEncoded

object
  • unknown properties allowed false
grantIdrequired
stringThe Grant identifier.
  • maximum length 64
  • pattern ^grant_[\s\S]+$
principalIdrequired
stringThe Principal identifier.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
rolerequired
MachineGrantRoleThe Organization role granted to the provisioned identity.
scoperequired
PrincipalScopeThe immutable structural scope of this machine identity.
grantedByPrincipalIdrequired
stringThe Principal that created this Grant.
  • maximum length 64
  • pattern ^principal_[\s\S]+$
createdAtrequired
stringWhen the resource was created, in UTC.
  • format date-time
expiresAtrequired
When the resource expires, in UTC, or null when it does not expire.
  • format date-time
Any of
string
null
revokedAtrequired
When the resource was revoked, in UTC, or null while it remains active.
  • format date-time
Any of
string
null

UnauthorizedEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Unauthorized"
reasonrequired
stringA safe explanation of why the credential was rejected.

ForbiddenEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "Forbidden"
permissionrequired
stringThe permission required by the refused operation.

NotFoundEncoded

object
  • unknown properties allowed false
_tagrequired
stringThe stable machine-readable error type.
  • allowed values "NotFound"
resourcerequired
stringThe resource type relevant to the error.
idrequired
stringThe identifier supplied for the resource that was not found.

MachineGrantRole

string
  • allowed values "admin", "developer", "viewer", "configurationDeployer"

PrincipalScope

OrganizationScope

object
  • unknown properties allowed false
levelrequired
stringThe tenancy level of this structural scope.
  • allowed values "organization"
organizationIdrequired
stringThe Organization identifier.
  • maximum length 64
  • pattern ^org_[\s\S]+$

ProjectScope

object
  • unknown properties allowed false
levelrequired
stringThe tenancy level of this structural scope.
  • allowed values "project"
organizationIdrequired
stringThe Organization identifier.
  • maximum length 64
  • pattern ^org_[\s\S]+$
projectIdrequired
stringThe Project identifier.
  • maximum length 64
  • pattern ^proj_[\s\S]+$

EnvironmentScope

object
  • unknown properties allowed false
levelrequired
stringThe tenancy level of this structural scope.
  • allowed values "environment"
organizationIdrequired
stringThe Organization identifier.
  • maximum length 64
  • pattern ^org_[\s\S]+$
projectIdrequired
stringThe Project identifier.
  • maximum length 64
  • pattern ^proj_[\s\S]+$
environmentIdrequired
stringThe Environment identifier.
  • maximum length 64
  • pattern ^env_[\s\S]+$

TenantScope

object
  • unknown properties allowed false
levelrequired
stringThe tenancy level of this structural scope.
  • allowed values "tenant"
organizationIdrequired
stringThe Organization identifier.
  • maximum length 64
  • pattern ^org_[\s\S]+$
projectIdrequired
stringThe Project identifier.
  • maximum length 64
  • pattern ^proj_[\s\S]+$
environmentIdrequired
stringThe Environment identifier.
  • maximum length 64
  • pattern ^env_[\s\S]+$
tenantIdrequired
stringThe Tenant identifier.
  • maximum length 64
  • pattern ^tenant_[\s\S]+$