access

POST /v1/orgs/{orgId}/delegated-access/revoke

Revoke one person from every site, or from chosen sites.

All access endpoints

All developer docs →

Authentication

Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.

Where your organisation id goes

This endpoint takes your organisation id in the URL itself, as orgId. Substitute it into the path — there is no header or query parameter that will do instead.

Your organisation id is on the API keys screen in your dashboard, beside the key itself. It is the same id in every call you make.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/orgs/{orgId}/delegated-access/revoke \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "email": <string> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Revokes the person's grants in this organisation — all of them when site_ids is omitted, or only those sites. Rows are kept and marked revoked. A pending person's invitation is withdrawn with their last pending grant. When nothing is left their site_collaborator membership is removed (membership_removed). Takes effect on the person's next request, in the app, the API and the CLI alike, whatever token they hold: a collaborator's reach is resolved from their live grants on every request. Idempotent — revoking somebody who holds nothing answers 200 with revoked: 0.

Parameters

NameTypeRequiredWhat it is
orgId (path)UuidYesOrganization ID (UUIDv7).

Request body

NameTypeRequiredWhat it is
emailstringYes—
site_idsstring[]NoOmitted revokes every site; given, only these.

Response

NameTypeRequiredWhat it is
revokedintegerYes—
membership_removedbooleanYes—
wp_admin_sitesintegerYesSites where this person had opened WordPress admin from the dashboard recently enough for a live session to still exist, and where one is therefore being ended. Ending it happens…
wp_admin_sites_stale_pluginintegerYesHow many of wp_admin_sites are running a Zinn® plugin older than the release that can end a live session. On those the person keeps WordPress admin until WordPress ends the…

Errors this endpoint can return

401 · 403 · 404 · 422 · 429