> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://contentful.com/developers/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://contentful.com/developers/docs/_mcp/server.

# Revoke an access token

PUT https://api.contentful.com/users/me/access_tokens/{token_id}/revoked

Revokes a CMA token, setting `revokedAt` to the current timestamp. **This action cannot be undone.**

Reference: https://contentful.com/developers/docs/references/content-management-api/access-tokens/revoke-an-access-token

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Request

### Path parameters

- `token_id` (string, required) — ID of the personal access token in a form of a string

## Response

### 200

OK - Request successful

- `map from string to any`

## Examples

**Response**

```json
{
  "name": "My Token",
  "revokedAt": "2025-03-04T05:23:09.000Z",
  "scopes": [
    "content_management_manage"
  ],
  "sys": {
    "application": {
      "sys": {
        "id": "<application_id>",
        "linkType": "Application",
        "type": "Link"
      }
    },
    "createdAt": "2025-02-14T04:18:43.000Z",
    "expiresAt": null,
    "id": "exampletokenid",
    "lastUsedAt": null,
    "redactedValue": "TmTU",
    "type": "PersonalAccessToken",
    "updatedAt": "2025-02-14T04:18:43.000Z"
  }
}
```

**SDK Code**

```android Android
// Create the Contentful client.
final CMAClient client =
    new CMAClient
        .Builder()
        .setAccessToken("<access_token>")
        .setSpaceId("<space_id>")
        .setEnvironmentId("<environment_id>")
        .build();

client
    .personalAccessTokens()
    .async()
    .fetchOne(
        "<token_id>",
        new CMACallback<CMAPersonalAccessToken>() {
          @Override protected void onSuccess(CMAPersonalAccessToken token) {
            client
                .personalAccessTokens()
                .async()
                .revoke(
                    token,
                    new CMACallback<CMAPersonalAccessToken>() {
                      @Override protected void onSuccess(CMAPersonalAccessToken result) {
                        new AlertDialog.Builder(context)
                            .setTitle("Contentful")
                            .setMessage("Successfully revoked your favorite access token." +
                                "\n\nResult: " + result)
                            .show();
                      }

                      @Override protected void onFailure(RuntimeException exception) {
                        // An error occurred! Inform the user.
                        new AlertDialog.Builder(context)
                            .setTitle("Contentful Error")
                            .setMessage("Could not revoke the token." +
                                "\n\nReason: " + exception.toString())
                            .show();

                        super.onFailure(exception);
                      }
                    }
                );
          }

          @Override protected void onFailure(RuntimeException exception) {
            // An error occurred! Inform the user.
            new AlertDialog.Builder(context)
                .setTitle("Contentful Error")
                .setMessage("Could not fetch the token." +
                    "\n\nReason: " + exception.toString())
                .show();

            super.onFailure(exception);
          }
        }
    );
```

```java Java
// Create the Contentful client.
final CMAClient client =
    new CMAClient
        .Builder()
        .setAccessToken("<access_token>")
        .setSpaceId("<space_id>")
        .setEnvironmentId("<environment_id>")
        .build();

// fetch access token from Contentful.
final CMAPersonalAccessToken token = client
    .personalAccessTokens()
    .fetchOne("<token_id>");

// Revoke it on Contentful.
final CMAPersonalAccessToken revokedToken = client
    .personalAccessTokens()
    .revoke(token);
```

```kotlin Kotlin
// Create the Contentful client.
val client = CMAClient.Builder()
    .setAccessToken("<access_token>")
    .setSpaceId("<space_id>")
    .setEnvironmentId("<environment_id>")
    .build()

// fetch access token from Contentful.
val token = client
        .personalAccessTokens()
        .fetchOne("<token_id>")

// Revoke it on Contentful.
val revokedToken = client
        .personalAccessTokens()
        .revoke(token)
```

```swift Swift
We currently don't provide a CMA SDK for this platform.
```

```js-legacy JavaScript (legacy)
import { createClient } from 'contentful-management'

const client = createClient({
  accessToken: '<content_management_api_key>'
}, { type: 'legacy' })

client.getAccessToken('<token-id>')
 .then((accessToken) => accessToken.revoke())
 .catch(console.error)
```

```javascript JavaScript
import { createClient } from 'contentful-management'

// Client init
const client = createClient({
  accessToken: '<content_management_api_key>'
})

await client.accessToken.revoke({
  tokenId: '<token_id>',
});
```

```php PHP
$client = new \Contentful\Management\Client('<content_management_api_key>');

$token = $client->getPersonalAccessToken('<personal_access_token_id>');
$token->revoke();
```

```ruby Ruby
require 'contentful/management'

client = Contentful::Management::Client.new('<content_management_api_key>')

personal_access_token = client.personal_access_tokens.find('<personal_access_token_id>')
personal_access_token.destroy
```

```python Python
from contentful_management import Client

client = Client('<content_management_api_key>')

personal_access_token = client.personal_access_tokens().find('<personal_access_token_id>')
personal_access_token.delete

# or

client.personal_access_tokens().revoke('<personal_access_token_id>')
```

```.net .NET
// This client should only be created once per application.
var httpClient = new HttpClient();

var client = new ContentfulManagementClient(httpClient, "<content_management_api_key>", "<space_id>");

var revokedToken = await client.RevokeManagementToken("<personal_access_token_id>");
```