> ## Documentation Index
> Fetch the complete documentation index at: https://docs.simplepay.mx/llms.txt
> Use this file to discover all available pages before exploring further.

# Revoke an API key (developer)

> Customer-bearer and admin-only revocation. Obtain a single-use step-up proof for action api_key.revoke and params_hash over canonical stable JSON {key_ref_id:<id>}; reuse the same Idempotency-Key. Revocation takes effect at the uncached lifecycle gate on the next service-key request.



## OpenAPI

````yaml /en/openapi.json post /v1/api-keys/{id}/revoke
openapi: 3.1.0
info:
  title: SimplePay API
  version: '2026-06-13'
  description: >-
    Contrato público para integrar SimplePay desde un backend. Incluye
    únicamente operaciones para comercios y administración protegida de
    credenciales.
servers:
  - description: Live
    url: https://api.simplepay.mx
  - description: Sandbox
    url: https://api.test.simplepay.mx
security:
  - SimplePayApiKey: []
tags:
  - name: API keys
  - name: Hosted Checkout
  - name: Payment Links
  - name: Payments
  - name: Refunds
  - name: Webhooks
  - name: Digital Catalog
  - name: Payment Policy
  - name: Reporting
  - name: Workspace
  - name: Customer Hub
  - name: Bookable Payments
  - name: Table Pay
  - name: Physical Checkout
  - name: In-person Payments
  - name: Terminal
  - name: Tap to Pay
  - name: Ticketing
  - name: Admission Control
  - name: Intelligence
externalDocs:
  description: SimplePay developer documentation
  url: https://docs.simplepay.mx
paths:
  /v1/api-keys/{id}/revoke:
    post:
      tags:
        - API keys
      summary: Revoke an API key (developer)
      description: >-
        Customer-bearer and admin-only revocation. Obtain a single-use step-up
        proof for action api_key.revoke and params_hash over canonical stable
        JSON {key_ref_id:<id>}; reuse the same Idempotency-Key. Revocation takes
        effect at the uncached lifecycle gate on the next service-key request.
      operationId: revokeApiKey
      parameters:
        - $ref: '#/components/parameters/StepUpToken'
        - $ref: '#/components/parameters/IdempotencyKey'
        - name: id
          in: path
          required: true
          schema:
            type: string
            format: uuid
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              additionalProperties: false
              required:
                - tenant_environment
                - tenant_id
              properties:
                tenant_environment:
                  type: string
                  enum:
                    - sandbox
                    - live
                tenant_id:
                  type: string
                  minLength: 1
                  maxLength: 128
                  pattern: ^[A-Za-z0-9][A-Za-z0-9_-]{0,127}$
      responses:
        '200':
          description: API key revoked.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiKeyMutationResponse'
      security:
        - SimplePayCustomerBearer: []
components:
  parameters:
    StepUpToken:
      name: x-sp-step-up-token
      in: header
      required: true
      description: >-
        Short-lived, single-use SimplePay recent-auth proof bound to this
        mutation and Idempotency-Key.
      schema:
        type: string
        minLength: 32
        maxLength: 4096
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      required: true
      schema:
        type: string
        minLength: 8
        maxLength: 255
  schemas:
    ApiKeyMutationResponse:
      type: object
      additionalProperties: false
      required:
        - key
        - object
      properties:
        key:
          $ref: '#/components/schemas/ApiKeySummary'
        object:
          const: simplepay.v1.api_key
    ApiKeySummary:
      type: object
      additionalProperties: false
      required:
        - created_at
        - created_by_email
        - description
        - environment
        - expires_at
        - id
        - obfuscated_value
        - scopes
        - status
      properties:
        created_at:
          type:
            - string
            - 'null'
          format: date-time
        created_by_email:
          type:
            - string
            - 'null'
          format: email
        description:
          type: string
          maxLength: 120
        environment:
          type: string
          enum:
            - sandbox
            - live
        expires_at:
          type:
            - string
            - 'null'
          format: date-time
        id:
          type: string
          format: uuid
        obfuscated_value:
          type: string
        scopes:
          type: array
          uniqueItems: true
          items:
            type: string
        status:
          type: string
          enum:
            - active
            - failed
            - provisioning
            - revoked
            - revoking
            - rotating
  securitySchemes:
    SimplePayApiKey:
      type: http
      scheme: bearer
    SimplePayCustomerBearer:
      type: http
      scheme: bearer
      description: SimplePay customer session bearer. Never a tenant API credential.

````