> ## Documentation Index
> Fetch the complete documentation index at: https://www.vitalog.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Revoke all managed API keys

> Revoke all API keys and MCP connections, including expired records, and cancel pending OAuth authorization codes. An optional kind filter revokes only manual keys or MCP connections. Dashboard and management sessions remain signed in. The environment AUTH_KEY is unaffected.



## OpenAPI

````yaml /openapi.json delete /auth/key-management/api-keys
openapi: 3.1.1
info:
  title: Vitalog
  version: 1.0.1
  description: >-
    Single-user structured observations with equivalent REST and MCP domain
    services. Environment AUTH_KEY or revocable personal Bearer keys with
    required name, permissions and explicit expiry (including Never); Primary
    key management requires AUTH_KEY; the UI uses separate, root-verified
    30-minute management sessions. MCP clients use OAuth authorization code with
    S256 PKCE, issued after root sign-in. Clients are resolved through HTTPS
    metadata, pre-registration or dynamic registration. OAuth tokens grant MCP
    access only.
servers:
  - url: https://vitalog-api.example.com
    description: Production REST and MCP API
  - url: http://localhost:3000
    description: Loopback development; production requires TLS ingress
security: []
paths:
  /auth/key-management/api-keys:
    delete:
      tags:
        - Key management
      summary: Revoke all managed API keys
      description: >-
        Revoke all API keys and MCP connections, including expired records, and
        cancel pending OAuth authorization codes. An optional kind filter
        revokes only manual keys or MCP connections. Dashboard and management
        sessions remain signed in. The environment AUTH_KEY is unaffected.
      operationId: revoke_all_managed_api_keys
      parameters: []
      responses:
        '200':
          description: >-
            Revoke all API keys and MCP connections, including expired records,
            and cancel pending OAuth authorization codes. An optional kind
            filter revokes only manual keys or MCP connections. Dashboard and
            management sessions remain signed in. The environment AUTH_KEY is
            unaffected.
          content:
            application/json:
              schema:
                $schema: https://json-schema.org/draft/2020-12/schema
                type: object
                properties:
                  revoked_count:
                    type: integer
                    minimum: 0
                    maximum: 9007199254740991
                required:
                  - revoked_count
                additionalProperties: false
        '401':
          description: Authentication or request validation failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Authentication or request validation failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: Authentication or request validation failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '413':
          description: Authentication or request validation failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '422':
          description: Authentication or request validation failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Authentication or request validation failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Authentication or request validation failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '503':
          description: Authentication or request validation failed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - keyManagementSession: []
components:
  schemas:
    Error:
      type: object
      additionalProperties: false
      required:
        - code
        - message
        - catalog_version
        - issues
      properties:
        code:
          type: string
          enum:
            - VALIDATION_ERROR
            - NOT_FOUND
            - VERSION_CONFLICT
            - IDEMPOTENCY_CONFLICT
            - DAILY_TOTAL_EXISTS
            - CATALOG_VERSION_MISMATCH
            - LIMIT_EXCEEDED
            - UNAUTHORIZED
            - FORBIDDEN
            - RATE_LIMITED
            - UNAVAILABLE
            - TIMEOUT
            - INTERNAL_ERROR
        message:
          type: string
        catalog_version:
          type: string
        issues:
          type: array
          items:
            type: object
            properties:
              path:
                type: string
              reason:
                type: string
              message:
                type: string
              suggested_keys:
                type: array
                items:
                  type: string
              discovery:
                type: object
        existing_id:
          type: string
        current_version:
          type: integer
        current_catalog_version:
          type: string
  securitySchemes:
    keyManagementSession:
      type: http
      scheme: bearer
      description: >-
        Opaque vlm_ token valid for 30 minutes. API-key management only; ledger
        and MCP routes reject it. The UI stores it in a separate host-only
        HttpOnly cookie.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.