Revoke a credential; the record stays for the audit trail
- In the sandbox
In plain words
Revokes a credential and keeps its record.
POST
apiKeyheader
AuthorizationBearer <token>Send your key as a bearer token: Authorization: Bearer <your-api-key>. Health is the only call that needs no key.
id*stringRevoked.
application/json- response
id?stringclient?stringroute?stringkind?stringissued_by?stringissued_on?stringexpires_on?stringenvironment?|sandbox or production; null for a credential stored before 3 Oct 2026, which only a sandbox uses.
legal_entity?stringrevoked_at?stringstored?booleancurl -X POST "https://example.com/credentials/string/revoke" \ -H "Authorization: Bearer <your-api-key>"{ "id": "string", "client": "string", "route": "string", "kind": "string", "issued_by": "string", "issued_on": "string", "expires_on": "string", "environment": "string", "legal_entity": "string", "revoked_at": "string", "stored": true}Replace the value (and expiry) of a live credential POST
Previous
Store a credential, encrypted; the value is never returned POST
A process stores credentials for its own environment only. legal_entity ties one to the seller id it acts for (VAT id, NIP, SIREN or company id); an untagged one serves the client's other invoices. A client's admin key stores for its own client only.