Skip to main content

Logout

POST 

/auth/logout

Sign out of this session: revoke its refresh tokens and clear the cookie.

The session is the one the web session cookie names; the account's other sessions are untouched (/auth/logout-all ends those). Its access tokens stop working at once (ASVS 5.0 7.4.1). Needs X-Scrift-Web-Session and an allow-listed Origin (403 cross_site_request_refused otherwise). Returns 204 and clears the cookie even when no session was found: idempotent, and it never tells a real token from a guessed one.

Responses​

Successful Response