Logout
POST/auth/logout
Sign out of this session: revoke its refresh tokens and clear the cookie.
The session is the one the web session cookie names; the account's other
sessions are untouched (/auth/logout-all ends those). Its access tokens
stop working at once (ASVS 5.0 7.4.1). Needs X-Scrift-Web-Session and an
allow-listed Origin (403 cross_site_request_refused otherwise).
Returns 204 and clears the cookie even when no session was found:
idempotent, and it never tells a real token from a guessed one.
Responses
- 204
Successful Response