Revoke an authorization grant
DELETE /v1/access-policy/grants/{id}: Soft-revokes one grant and returns its durable historical row. Repeating the request is idempotent while the caller retains MANAGE_ACCESS on the target.
Soft-revokes one grant and returns its durable historical row. Repeating the request is idempotent while the caller retains MANAGE_ACCESS on the target.
In: header
Path Parameters
Grant UUID
Header Parameters
Optional waiting budget in milliseconds, measured from REST servlet ingress and shared across all internal gRPC calls. Supply one decimal integer from 1 to 86400000. Omission adds no deadline. Existing shorter deadlines still apply. Expiry returns HTTP 504 before streaming starts; after streaming starts, no successful completion event is sent. Use SSE or opt into GoodMem-Stream-Terminal for an explicit terminal outcome. Retrieval work is cooperatively cancelled. An accepted mutation may still commit after timeout or disconnect; a failed response does not imply rollback.
int641 <= value <= 86400000Response Body
curl -X DELETE "https://your-goodmem-server.example.com/v1/access-policy/grants/f276b9a4-73d6-4e04-95c5-87b974221f92" \ -H "GoodMem-Timeout-Ms: 30000"{
"grantId": "f276b9a4-73d6-4e04-95c5-87b974221f92",
"audience": {
"principalId": "70e025f6-76ca-4cbe-b8fc-7dab8e84590a"
},
"rule": {
"operation": "CREATE_USER",
"selector": "ANY",
"assignedResource": {
"resourceId": "550e8400-e29b-41d4-a716-446655440000"
}
},
"createdAt": 0,
"createdById": "70e025f6-76ca-4cbe-b8fc-7dab8e84590a",
"revokedAt": 0,
"revokedById": "114ad558-323d-4b76-85b8-37af103b8650"
}List scoped role assignments
GET /v1/access-policy/role-assignments: Lists assignments attached to one required INSTANCE or SPACE boundary after requiring MANAGE_ACCESS. Continuation tokens are bound to the caller and filters.
Revoke a scoped role assignment
DELETE /v1/access-policy/role-assignments/{id}: Soft-revokes one non-ROOT assignment and returns its durable historical row. Repeating the request is idempotent while the caller retains MANAGE_ACCESS.