Skip to content

Vendors and discovery

Propose revoking a key at its vendor

POST/api/w/:wid/discovery/items/:id/revoke

Owners. Files a proposal; nothing changes at the vendor until another owner confirms. OpenAI does not let an admin key delete a key owned by a service account, so that is refused with vendor_cannot_revoke.

#Authentication

Session cookie

A signed-in person: the console's session cookie. Every state-changing request also carries the header x-immiscible-csrf: 1, and the member's role decides what it may do. Bearer tokens are ignored on these routes, so no machine credential can reach them.

#Path parameters

widstringrequired

Workspace id

idstringrequired

Object id