revoke_realm_keys

Generated automatically from the published contract sources.

Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.

A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/revoke_realm_keys, with a bearer credential and the action's payload as the JSON body.

Contract description

Revoke every signing key of one of an application's sign-in realms, for a suspected key compromise. Every end-user session token the keys signed is refused as `key_revoked` once the serving routers sync the key set (within about 30 seconds). Every user of the realm signs in again, and the accounts service mints the replacement key at the realm's next sign-in. The `environment` argument is required: `development` or `production`, the realm whose keys are revoked. Answers the revoked key identifiers and the key set's new version.

Access and action metadata

{
  "name": "revoke_realm_keys",
  "resource": "realm",
  "tier": "reversible",
  "summary": "Revoke every signing key of one realm: every session token the keys signed is refused as key_revoked once the routers sync, every user signs in again, and the accounts service mints the replacement at the next sign-in.",
  "annotations": {
    "readOnlyHint": false,
    "destructiveHint": true,
    "openWorldHint": false
  }
}

MCP catalog entry

{
  "name": "revoke_realm_keys",
  "tier": "reversible",
  "summary": "Revoke every signing key of one of an application's sign-in realms, for a suspected key compromise. Every end-user session token the keys signed is refused as `key_revoked` once the serving routers sync the key set (within about 30 seconds). Every user of the realm signs in again, and the accounts service mints the replacement key at the realm's next sign-in. The `environment` argument is required: `development` or `production`, the realm whose keys are revoked. Answers the revoked key identifiers and the key set's new version.",
  "owners": [
    "ACS-L0-08",
    "PLD-L0-40"
  ],
  "scenario": "ACS-L0-08"
}

request

JSON pointer Description and constraints
"" (root) Type: object
Required fields: ["application","environment"]
Additional properties: false
/properties/application The application id, from `list_applications`.

Type: string
/properties/environment Required. The environment whose realm's signing keys are revoked, `development` or `production` (the accounts service PRD's realm statement).

Type: string
Pattern: ^(development|production)$

response

JSON pointer Description and constraints
"" (root) Type: object
Required fields: ["contract_version","realm","application","environment","revoked","keys_changed_at"]
Additional properties: false
/properties/contract_version Required value: 1
/properties/realm The realm identifier: the application id for production, `<id>:development` for development.

Type: string
/properties/application Type: string
/properties/environment Type: string
Pattern: ^(development|production)$
/properties/revoked The key identifiers stamped revoked by this call; empty where the realm held no live key.

Type: array
/properties/revoked/items Type: string
/properties/keys_changed_at The realm key set's version after the call, the value the sync route and the key-set route answer as `version`.

Type: ["string","null"]
/properties/detail Type: string

Complete payload contract

{
  "request": {
    "type": "object",
    "required": [
      "application",
      "environment"
    ],
    "properties": {
      "application": {
        "type": "string",
        "description": "The application id, from `list_applications`."
      },
      "environment": {
        "type": "string",
        "pattern": "^(development|production)$",
        "description": "Required. The environment whose realm's signing keys are revoked, `development` or `production` (the accounts service PRD's realm statement)."
      }
    },
    "additionalProperties": false
  },
  "response": {
    "type": "object",
    "required": [
      "contract_version",
      "realm",
      "application",
      "environment",
      "revoked",
      "keys_changed_at"
    ],
    "properties": {
      "contract_version": {
        "const": 1
      },
      "realm": {
        "type": "string",
        "description": "The realm identifier: the application id for production, `<id>:development` for development."
      },
      "application": {
        "type": "string"
      },
      "environment": {
        "type": "string",
        "pattern": "^(development|production)$"
      },
      "revoked": {
        "type": "array",
        "items": {
          "type": "string"
        },
        "description": "The key identifiers stamped revoked by this call; empty where the realm held no live key."
      },
      "keys_changed_at": {
        "type": [
          "string",
          "null"
        ],
        "description": "The realm key set's version after the call, the value the sync route and the key-set route answer as `version`."
      },
      "detail": {
        "type": "string"
      }
    },
    "additionalProperties": false
  }
}

Shared contracts