Plum / developers
REST APIUser

POST /me/sign-out

Signs out. With no body, signs out only the calling app: an OAuth caller's grant (its access and refresh tokens) is revoked, or an app session is ended. With `{"everywhere": true}`, which requires account:manage, revokes every OAuth grant for every client and installation, deletes Plum sign-in sessions, revokes every personal access token, and, when called with an app session, signs out every app session. Works for a deleted account. If the access token has expired, refresh it first. Personal access tokens cannot call this endpoint.

POST/me/sign-out

Authorization

bearerAuth
AuthorizationBearer <token>

Send Authorization: Bearer <token> with one of: an app session access token from /auth/verify-otp or /auth/refresh; an OAuth access token from /oauth/token issued for the API origin (its scopes are its permissions); or a personal access token starting with optima_pat_ (see /docs/personal-access-tokens). Personal access tokens cannot create or list tokens, revoke other tokens, sign out, or delete or restore the account. Content routes need the permission of their layer: audio:read/audio:write for recordings, turns:read/turns:write for turns, contacts, source signals, and events, and insights:read/insights:write for suggestions and session summaries; search and recall need turns:read and insights:read. A request without the permission, or for an account whose layer is turned off, returns 403 FORBIDDEN. See /docs/authentication#scopes.

In: header

Header Parameters

X-API-Version?"1"

Send 1 to pin the documented API contract. If omitted, the latest version is selected.

Default"1"

Value in

  • "1"

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

curl -X POST "https://example.com/me/sign-out" \  -H "X-API-Version: 1" \  -H "Content-Type: application/json" \  -d '{}'
Empty