> Call POST /v1/check before a tool that writes. DENY means do not invoke the tool. For clean Markdown of any page, append .md to the page URL. For the complete index, fetch https://docs.withwrit.com/llms.txt.

# Revoke all of a principal's keys

POST https://api.withwrit.com/v1/principals/{principalId}/revoke
Content-Type: application/json

API key required. One click to kill every live key of the principal —
contractor offboarding, incident response. Each revoked key gets its
own REVOKE receipt carrying the given reason, so every key stays
individually visible in the audit log. The principal itself is
untouched.


Reference: https://docs.withwrit.com/api-reference/principals/revoke-all-of-a-principals-keys

## Servers

- `https://api.withwrit.com` (Writ gate, default)
- `https://j72ckh66ukck2kcbq3oiwxaalm0olxwb.lambda-url.us-east-1.on.aws` (Direct Lambda Function URL (fallback))

## Request

### Path parameters

- `principalId` (string, required)

### Body (application/json)

This endpoint expects an object.

- `reason` (string, optional) — Why the keys are being revoked; written into each REVOKE receipt.

## Response

### 200

The revoked key ids.

## Errors

### 401 Unauthorized Error

API key required — missing, malformed, or unknown key.

- `any`

### 404 Not Found Error

No such live principal in this tenant.

## Examples

**Request**

```json
{
  "reason": "contractor offboarded"
}
```

**Response**

```json
{
  "principalId": "prn_9d2f4a1b2c3d",
  "revokedCount": 2,
  "revokedKeys": [
    "key_9d2f4a1b2c3d4e5f",
    "key_1a2b3c4d5e6f7081"
  ]
}
```

**SDK Code**

```python Principals_revokeAllOfAPrincipalsKeys_example
import requests

url = "https://api.withwrit.com/v1/principals/principalId/revoke"

payload = { "reason": "contractor offboarded" }
headers = {"Content-Type": "application/json"}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript Principals_revokeAllOfAPrincipalsKeys_example
const url = 'https://api.withwrit.com/v1/principals/principalId/revoke';
const options = {
  method: 'POST',
  headers: {'Content-Type': 'application/json'},
  body: '{"reason":"contractor offboarded"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go Principals_revokeAllOfAPrincipalsKeys_example
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.withwrit.com/v1/principals/principalId/revoke"

	payload := strings.NewReader("{\n  \"reason\": \"contractor offboarded\"\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby Principals_revokeAllOfAPrincipalsKeys_example
require 'uri'
require 'net/http'

url = URI("https://api.withwrit.com/v1/principals/principalId/revoke")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n  \"reason\": \"contractor offboarded\"\n}"

response = http.request(request)
puts response.read_body
```

```java Principals_revokeAllOfAPrincipalsKeys_example
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://api.withwrit.com/v1/principals/principalId/revoke")
  .header("Content-Type", "application/json")
  .body("{\n  \"reason\": \"contractor offboarded\"\n}")
  .asString();
```

```php Principals_revokeAllOfAPrincipalsKeys_example
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://api.withwrit.com/v1/principals/principalId/revoke', [
  'body' => '{
  "reason": "contractor offboarded"
}',
  'headers' => [
    'Content-Type' => 'application/json',
  ],
]);

echo $response->getBody();
```

```csharp Principals_revokeAllOfAPrincipalsKeys_example
using RestSharp;

var client = new RestClient("https://api.withwrit.com/v1/principals/principalId/revoke");
var request = new RestRequest(Method.POST);
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"reason\": \"contractor offboarded\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift Principals_revokeAllOfAPrincipalsKeys_example
import Foundation

let headers = ["Content-Type": "application/json"]
let parameters = ["reason": "contractor offboarded"] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://api.withwrit.com/v1/principals/principalId/revoke")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```