Revoke the connection
Call the API origin, the same host as the token endpoint, with a current access token. If the token has expired, refresh it first: an expired token gets403.
Example
What revocation does
- Removes the person’s OAuth consent for your integration.
- Invalidates the access token and refresh token.
- Revokes the integration key, so later fills with this connection fail.
After the call
Only after a successful response:- Delete the access token, refresh token, and integration key you stored for this person.
- Delete the credential references you stored for this connection. They no longer work.
- Mark the connection as disconnected in your product.
What isn’t available yet
- Revoking a single login. Revocation is all or nothing. To stop using one login, stop filling it and drop its reference.
- Revoking from inside 1Password. A person disconnects from your product. Make the Disconnect 1Password action easy to find.
How long a connection lasts
A connection doesn’t last forever even if no one revokes it:- Access tokens expire after 15 minutes. Refresh them from your backend.
- Refresh tokens rotate on every use. A connection lasts about 90 days at most, and ends sooner if you stop refreshing it.
- Grants last 30 days at launch. See How long a grant lasts.
invalid_grant, the connection has ended. Mark it disconnected and ask the person to connect again.