# Revoke one pull URL

`DELETE /v1/inboxes/{id}/pull-tokens/{token_id}`

- Authentication: required (Bearer token)
- Required scope: `api.inboxes.manage`

Cuts one URL off. This is the answer to "a link leaked" or "that user
should not see this any more".

**Everything else is untouched.** The inbox keeps receiving, the mail
already delivered stays there, and the other pull URLs keep working. If
you want the mail gone as well, `DELETE /v1/inboxes/{id}` — which is
irreversible.

**What it cannot undo** is what the holder has already read. That was
true the moment you handed the URL over.

**Idempotent**, unlike `DELETE /v1/inboxes/{id}`. A second call is
`204`, because your intent — that this URL stops working — is satisfied
either way, and a client retrying a timed-out revoke must not be told
the revoke failed.

A `token_id` that is not a token on this inbox is `404`, as is a value
that is not a UUID.

## Path parameters

- `id` (string<uuid>, required) — The inbox's UUID, exactly as returned by `POST /v1/inboxes`. A value that is not a UUID is a 404 rather than a 422 — it names nothing, and saying "that is not a valid UUID" would confirm the format of ids that do exist.
- `token_id` (string<uuid>, required) — The pull token's UUID — `pull_token.id` from the mint response, or an `id` from `POST`/`GET /v1/inboxes/{id}/pull-tokens`. THE TOKEN'S DATABASE ID, never the token itself: a raw token in a path on this host would be a live secret written verbatim into the access log. A value that is not a UUID, or one belonging to a different inbox, is a 404.

## Example request

```bash
curl -X DELETE 'https://api.sendops.dev/v1/inboxes/00000000-0000-0000-0000-000000000000/pull-tokens/00000000-0000-0000-0000-000000000000' \
  -H "Authorization: Bearer $SENDOPS_API_KEY"
```

## Responses

### 204 — The URL no longer opens this inbox

### 401 — Missing, malformed, or unknown API key

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 403 — Either the credential lacks the required scope (`code: invalid_scope`), or it is bound to the `test` environment and this operation is irreversible (`code: test_environment_forbidden`). Branch on `code`: the first is fixed by granting the scope, the second only by using a live credential. See the "Live and test credentials" section of the API description.

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 404 — Resource not found

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 429 — Per-org rate limit exceeded

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 500 — Unexpected server-side failure. The `code` is `internal_error`. The
`request_id` field can be quoted to SendOps support to investigate.

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```
