> ## Documentation Index
> Fetch the complete documentation index at: https://www.1password.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Disconnect a user

> Revoke a person's entire connection from your backend when they disconnect 1Password or when you need to replace a lost integration key.

export const StatusBadge = ({children}) => <span className="op-status-badge not-prose">{children}</span>;

<StatusBadge>Partner preview</StatusBadge>

When a person selects **Disconnect 1Password** in your product, revoke their connection from your backend. Use the same call to recover from a lost integration key or reset a test user so the next connection returns a new key.

<Warning>
  Revocation is permanent. It ends the person's entire connection to your integration, and every login they granted stops working. To use 1Password again, they must repeat the connection and consent flow and approve the logins again.
</Warning>

## Revoke the connection

Call the API origin, the same host as the token endpoint, with a current access token. If the token has expired, refresh it first: an expired token gets `403`.

```http theme={null}
POST {api origin}/v1alpha1/oauth-integrations/self:revoke
Authorization: Bearer <access token>
Content-Type: application/json

{}
```

The access token identifies the OAuth client, account, and person to disconnect. Don't put client, account, or user identifiers in the body.

A successful request returns:

```http theme={null}
HTTP/1.1 200 OK
Content-Type: application/json

{}
```

```bash Example theme={null}
curl -s -X POST https://api.1password.com/v1alpha1/oauth-integrations/self:revoke \
  -H "Authorization: Bearer ${OP_ACCESS_TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{}'
```

## What revocation does

* Removes the person's OAuth consent for your integration.
* Invalidates the access token and refresh token.
* Revokes the integration key, so later fills with this connection fail.

## After the call

Only after a successful response:

1. Delete the access token, refresh token, and integration key you stored for this person.
2. Delete the credential references you stored for this connection. They no longer work.
3. Mark the connection as disconnected in your product.

If the call fails, keep the stored credentials and the connected state, so the person can try again.

When the person connects again, they go through the full authorization and consent flow, and 1Password returns a new integration key.

## What isn't available yet

* **Revoking a single login.** Revocation is all or nothing. To stop using one login, stop filling it and drop its reference.
* **Revoking from inside 1Password.** A person disconnects from your product. Make the **Disconnect 1Password** action easy to find.

## How long a connection lasts

A connection doesn't last forever even if no one revokes it:

* Access tokens expire after 15 minutes. Refresh them from your backend.
* Refresh tokens rotate on every use. A connection lasts about 90 days at most, and ends sooner if you stop refreshing it.
* Grants last 30 days at launch. See [How long a grant lasts](/agentic-autofill/partners/approval#how-long-a-grant-lasts).

When a refresh returns `invalid_grant`, the connection has ended. Mark it disconnected and ask the person to connect again.


## Related topics

- [Use 1Password to securely provide credentials to AI agents](/agentic-autofill.md)
- [user](/cli/reference/management-commands/user.md)
- [Get a user](/users-api/get-user.md)
