Kill switch — revoke the principal
Kill switch — revoke the principal
Authentication
Headers
Bearer <sponsor token>.
Kill switch — revoke the principal
Bearer <sponsor token>.
Sponsor token required. Revokes the principal identified by
sponsorId + agentId within the sponsor’s tenant: every later check
for that principal is DENY, even under an allow policy, until
POST /v1/reinstate undoes it. Use it the moment an agent looks
compromised or a runaway loop starts issuing checks. Revocation
itself writes a REVOKE receipt, so the kill-switch action is in the
audit log too.
Your Writ API key (writ_…) as an Authorization Bearer header. The sponsor token (writ_sp_…) is a separate credential used only for grants, revokes, and reinstate — it goes in the same Authorization header on those endpoints. In the Fern docs playground, paste the key here; it is stored in this browser only.