Revoke one pull URL

Search Documentation

Search across all developer documentation

inboxes

Revoke one pull URL

DELETE /v1/inboxes/{id}/pull-tokens/{token_id}
Auth required api.inboxes.manage

Cuts one URL off. This is the answer to "a link leaked" or "that user should not see this any more".

Everything else is untouched. The inbox keeps receiving, the mail already delivered stays there, and the other pull URLs keep working. If you want the mail gone as well, DELETE /v1/inboxes/{id} — which is irreversible.

What it cannot undo is what the holder has already read. That was true the moment you handed the URL over.

Idempotent, unlike DELETE /v1/inboxes/{id}. A second call is 204, because your intent — that this URL stops working — is satisfied either way, and a client retrying a timed-out revoke must not be told the revoke failed.

A token_id that is not a token on this inbox is 404, as is a value that is not a UUID.

Path parameters

id string<uuid> required

The inbox's UUID, exactly as returned by POST /v1/inboxes. A value that is not a UUID is a 404 rather than a 422 — it names nothing, and saying "that is not a valid UUID" would confirm the format of ids that do exist.

token_id string<uuid> required

The pull token's UUID — pull_token.id from the mint response, or an id from POST/GET /v1/inboxes/{id}/pull-tokens. THE TOKEN'S DATABASE ID, never the token itself: a raw token in a path on this host would be a live secret written verbatim into the access log. A value that is not a UUID, or one belonging to a different inbox, is a 404.

Responses

Errors follow the RFC 7807 problem format — see the error reference.

204 The URL no longer opens this inbox
401 Missing, malformed, or unknown API key application/problem+json
403 Either the credential lacks the required scope (code: invalid_scope), or it is bound to the test environment and this operation is irreversible (code: test_environment_forbidden). Branch on code: the first is fixed by granting the scope, the second only by using a live credential. See the "Live and test credentials" section of the API description. application/problem+json
404 Resource not found application/problem+json
429 Per-org rate limit exceeded application/problem+json
500 Unexpected server-side failure. The code is internal_error. The request_id field can be quoted to SendOps support to investigate. application/problem+json