# Revoke an API key

`DELETE /o/{org}/api-keys/{key}`

The next request with the key is refused, and its pending webhook retries are dropped. Any org admin may revoke.

## Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `org` | path | string | yes | The org's slug or id. A caller with no role in the org gets `404`. |
| `key` | path | string | yes | The key's `id` (`key_…`), not its secret. |

## Example request

```bash
curl -X DELETE "https://api.prix.dev/o/$RUSH_ORG/api-keys/$KEY_ID" \
  -H "Authorization: Bearer $RUSH_TOKEN"
```

```typescript
const org = process.env.RUSH_ORG;
const keyId = process.env.KEY_ID;

const res = await fetch(`https://api.prix.dev/o/${org}/api-keys/${keyId}`, {
  method: "DELETE",
  headers: {
    Authorization: `Bearer ${process.env.RUSH_TOKEN}`,
  },
});

console.log(res.status, await res.text());
```

```python
import os

import requests

org = os.environ["RUSH_ORG"]
key_id = os.environ["KEY_ID"]

res = requests.delete(
    f"https://api.prix.dev/o/{org}/api-keys/{key_id}",
    headers={"Authorization": f"Bearer {os.environ['RUSH_TOKEN']}"},
)

print(res.status_code, res.text)
```

## Responses

### 204

Revoked.

### 401

No bearer, an unknown, revoked or expired one, or an API key on a route keys cannot call.

### 404

No such resource for the caller, including one that exists in an org the caller cannot see.

## Example response (204)

```http
HTTP 204 Revoked.
```
