xPlantAPI
API referenceDevices

Revoke a device token

Stops one device token working: the next request made with it is refused as unauthorized. The token stays in the device's token list, marked revoked with the time it was revoked, so the list remains a complete history of the device's credentials.

DELETE/api/v1/devices/{deviceId}/tokens/{tokenId}
Scope write:devices

Revoking a token that is already revoked is not an error — you get the token back as it stands, with its original revocation time. Taking a device out of service revokes all of its tokens at once.

Path parameters

NameTypeRequiredDescription
deviceIdstring (uuid)YesThe device's id.
tokenIdstring (uuid)YesThe token's id, as the token list returns it.

Example

curl -X DELETE https://app.xplantpro.com/api/v1/devices/5f7a9c1e-3b5d-4f7a-9c1e-3b5d7f9a1c3e/tokens/3c5e7a9b-1d3f-4b5d-8f7a-9c1e3b5d7f9a \
  -H "Authorization: Bearer $XPLANT_API_KEY"

Response

200 with { "ok": true, "data": … }. data holds the result.

FieldTypeRequiredDescription
idstring (uuid)Yes—
deviceIdstring (uuid)YesThe device the token belongs to.
namestring | nullYesThe label it was given when it was minted.
prefixstringYesThe first characters of the token — enough to recognise it, never enough to use it.
statusstringYesactive, or revoked once it can no longer be used.
lastUsedAtstring | nullYesWhen the token last authenticated a request, as an ISO 8601 timestamp. Null if never.
revokedAtstring | nullYesWhen the token was revoked, as an ISO 8601 timestamp. Null while it is active.
createdAtstringYesWhen the token was minted.
Response
{
  "ok": true,
  "data": {
    "id": "4f8a2c6e-9d1b-4e7a-b3c5-6a0d8f2e4b19",
    "deviceId": "8e3b1f52-6c0d-4a7e-9b21-5f4d8c2a7e13",
    "name": "Grow room Pi",
    "prefix": "xpd_live_0123456789a",
    "status": "revoked",
    "lastUsedAt": "2026-09-25T14:05:00.000Z",
    "revokedAt": "2026-09-25T15:00:00.000Z",
    "createdAt": "2026-09-01T09:40:00.000Z"
  }
}
Response headerMeaning
X-Request-IdIdentifies this request. Include it when you contact support.

Errors

StatusCodeWhen
401UNAUTHORIZEDThe key is missing, malformed or revoked, or its owner is no longer a member of the workspace.
402PAID_PLAN_REQUIREDThe workspace has no paid plan. Connecting devices is included with every paid plan.
403FORBIDDENThe key lacks a scope this operation requires, or its owner's current role in the workspace cannot use it — a key never does more than its owner can in xPlant. error names the scope, and for a role, the role it needs.
403DEVICE_TOKEN_NOT_ACCEPTEDA device token was sent; this operation needs a workspace API key.
404NOT_FOUNDNo token with this id belongs to this device in the key's workspace.
429RATE_LIMIT_EXCEEDEDToo many requests for this key, device token or workspace. Wait Retry-After seconds.
500DEVICE_TOKEN_REVOKE_FAILEDThe token could not be revoked and may still work. Retry.

Branch on code, never on the error text. See Errors.

On this page