Skip to main content
DELETE
Revoke browser session

Authorizations

Authorization
string
header
required

Opaque vls_ browser token, valid for 30 days unless revoked. Read-only REST access. The UI stores it in a host-only HttpOnly SameSite=Lax cookie; it never reaches browser JavaScript. Key administration and MCP reject this token.

Response

Revoke the authenticated browser session. Accepts no body or query arguments. The environment AUTH_KEY can also revoke sessions through API-key management.

signed_out
boolean
required