access

DELETE /v1/sites/{siteId}/collaborators/{grantId}

Revoke one person's access to this site.

All access endpoints

Authentication

Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X DELETE https://api.zinndigital.com/v1/sites/{siteId}/collaborators/{grantId} \
  -H "Authorization: Bearer zdk_live_…"

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Ends the grant. The row is kept and marked revoked rather than deleted, so the audit question survives. When it was that person's last live grant in this organisation their `site_collaborator` membership is removed too — left behind it is a dormant unrestricted membership waiting for somebody to add a second role to it. Idempotent: revoking an already-revoked grant answers `204`, not `404` or `409`. A client retrying after a dropped response must not be told it failed.

Parameters

NameTypeRequiredWhat it is
siteId (path)UuidYesSite ID (UUIDv7).
grantId (path)stringYesThe grant to revoke.

Errors this endpoint can return

401 · 403 · 404 · 429