Revoke a CLI refresh token family
Revoke a CLI refresh token's family. Idempotent. Per RFC 7009 §2.2 the response is uniform ({ revoked: true }) even when the token is unknown or client-mismatched — the underlying hit/miss discriminator is kept in the audit log only, so a caller cannot probe token validity through the response shape.
curl -X POST "https://your-instance/api/auth/cli/revoke" \ -H "Content-Type: application/json" \ -d '{ "token": "string", "client_id": "string" }'{
"revoked": true
}{
"error": "string",
"error_description": "string"
}