revoke_realm_keys
Generated automatically from the published contract sources.
Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.
A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/revoke_realm_keys, with a bearer credential and the action's payload as the JSON body.
Contract description
Revoke every signing key of one of an application's sign-in realms, for a suspected key compromise. Every end-user session token the keys signed is refused as `key_revoked` once the serving routers sync the key set (within about 30 seconds). Every user of the realm signs in again, and the accounts service mints the replacement key at the realm's next sign-in. The `environment` argument is required: `development` or `production`, the realm whose keys are revoked. Answers the revoked key identifiers and the key set's new version.
Access and action metadata
{
"name": "revoke_realm_keys",
"resource": "realm",
"tier": "reversible",
"summary": "Revoke every signing key of one realm: every session token the keys signed is refused as key_revoked once the routers sync, every user signs in again, and the accounts service mints the replacement at the next sign-in.",
"annotations": {
"readOnlyHint": false,
"destructiveHint": true,
"openWorldHint": false
}
}
MCP catalog entry
{
"name": "revoke_realm_keys",
"tier": "reversible",
"summary": "Revoke every signing key of one of an application's sign-in realms, for a suspected key compromise. Every end-user session token the keys signed is refused as `key_revoked` once the serving routers sync the key set (within about 30 seconds). Every user of the realm signs in again, and the accounts service mints the replacement key at the realm's next sign-in. The `environment` argument is required: `development` or `production`, the realm whose keys are revoked. Answers the revoked key identifiers and the key set's new version.",
"owners": [
"ACS-L0-08",
"PLD-L0-40"
],
"scenario": "ACS-L0-08"
}
request
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["application","environment"] Additional properties: false |
| / |
The application id, from `list_applications`. Type: string |
| / |
Required. The environment whose realm's signing keys are revoked, `development` or `production` (the accounts service PRD's realm statement). Type: string Pattern: ^(development|production)$ |
response
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["contract_version","realm","application","environment","revoked","keys_changed_at"] Additional properties: false |
| / |
Required value: 1 |
| / |
The realm identifier: the application id for production, `<id>:development` for development. Type: string |
| / |
Type: string |
| / |
Type: string Pattern: ^(development|production)$ |
| / |
The key identifiers stamped revoked by this call; empty where the realm held no live key. Type: array |
| / |
Type: string |
| / |
The realm key set's version after the call, the value the sync route and the key-set route answer as `version`. Type: ["string","null"] |
| / |
Type: string |
Complete payload contract
{
"request": {
"type": "object",
"required": [
"application",
"environment"
],
"properties": {
"application": {
"type": "string",
"description": "The application id, from `list_applications`."
},
"environment": {
"type": "string",
"pattern": "^(development|production)$",
"description": "Required. The environment whose realm's signing keys are revoked, `development` or `production` (the accounts service PRD's realm statement)."
}
},
"additionalProperties": false
},
"response": {
"type": "object",
"required": [
"contract_version",
"realm",
"application",
"environment",
"revoked",
"keys_changed_at"
],
"properties": {
"contract_version": {
"const": 1
},
"realm": {
"type": "string",
"description": "The realm identifier: the application id for production, `<id>:development` for development."
},
"application": {
"type": "string"
},
"environment": {
"type": "string",
"pattern": "^(development|production)$"
},
"revoked": {
"type": "array",
"items": {
"type": "string"
},
"description": "The key identifiers stamped revoked by this call; empty where the realm held no live key."
},
"keys_changed_at": {
"type": [
"string",
"null"
],
"description": "The realm key set's version after the call, the value the sync route and the key-set route answer as `version`."
},
"detail": {
"type": "string"
}
},
"additionalProperties": false
}
}
Shared contracts
- Refusals: every refusal, by surface, with its cause and its remedy
- schemas/wire_error.schema.json
- schemas/wire_errors.json
- schemas/action_payloads.json (includes shared shapes)
- management_api_contract.md