Revoke a CLI refresh token family

Revoke a CLI refresh token's family. Idempotent. Per RFC 7009 §2.2 the response is uniform ({ revoked: true }) even when the token is unknown or client-mismatched — the underlying hit/miss discriminator is kept in the audit log only, so a caller cannot probe token validity through the response shape.

POST/api/auth/cli/revoke

Request Body

application/json

curl -X POST "https://your-instance/api/auth/cli/revoke" \  -H "Content-Type: application/json" \  -d '{    "token": "string",    "client_id": "string"  }'
{
  "revoked": true
}
{
  "error": "string",
  "error_description": "string"
}