Revoke a single CLI session owned by the caller

Revoke a single CLI session owned by the caller. Cookie auth required. revoked: false is returned when the family does not exist, does not belong to the caller, or has already been revoked — the route layer does not distinguish these cases at the HTTP shape so an attacker who somehow guessed a family_id cannot probe ownership through the response.

POST/api/auth/cli/sessions/revoke

Authorization

cookieAuth
better-auth.session_token<token>

Cookie session from Better Auth. Requires X-Org-Id header for org-scoped routes.

In: cookie

Request Body

application/json

curl -X POST "https://your-instance/api/auth/cli/sessions/revoke" \  -H "Content-Type: application/json" \  -d '{    "familyId": "string"  }'
{
  "revoked": true
}
{
  "error": "string",
  "error_description": "string"
}