Revoke Capability From Principal
Take one or more capabilities away from a principal: a user, a role, or a tenant.
A member keeps the capability if another level still grants it, since resolution is a union. Revoking something the principal never had succeeds and changes nothing, so a retry is safe.
The caller needs the revoke_capabilities capability in the target tenant; the tenant owner always has it.
Several capabilities can be revoked in one call by repeating the capability parameter, all or nothing like granting.
Error Codes
- 400 Bad Request: A capability is not in the catalog
- 403 Forbidden: Caller lacks revoke_capabilities in the target tenant, or the principal or tenant does not exist. These answer the same, so the endpoint cannot be used to discover which ids are real
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Query Parameters
Capability to take away. Repeat the parameter to revoke several at once: ?capability=a&capability=b.
Tenant the revoke is scoped to when the principal is a user. Defaults to the caller's current tenant. Ignored for a role or a tenant, whose own tenant is always used.
Response
Successful Response