Begin a Connection revocation session
curl --request POST \
--url https://api.checkfu.com/v1/principals/{id}/connections/{connectionId}/revocation-sessions \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'checkfu-version: <checkfu-version>' \
--header 'idempotency-key: <idempotency-key>' \
--data '
{
"expected_version": 1
}
'import requests
url = "https://api.checkfu.com/v1/principals/{id}/connections/{connectionId}/revocation-sessions"
payload = { "expected_version": 1 }
headers = {
"checkfu-version": "<checkfu-version>",
"idempotency-key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'checkfu-version': '<checkfu-version>',
'idempotency-key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({expected_version: 1})
};
fetch('https://api.checkfu.com/v1/principals/{id}/connections/{connectionId}/revocation-sessions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.checkfu.com/v1/principals/{id}/connections/{connectionId}/revocation-sessions",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'expected_version' => 1
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"checkfu-version: <checkfu-version>",
"idempotency-key: <idempotency-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.checkfu.com/v1/principals/{id}/connections/{connectionId}/revocation-sessions"
payload := strings.NewReader("{\n \"expected_version\": 1\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("checkfu-version", "<checkfu-version>")
req.Header.Add("idempotency-key", "<idempotency-key>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.checkfu.com/v1/principals/{id}/connections/{connectionId}/revocation-sessions")
.header("checkfu-version", "<checkfu-version>")
.header("idempotency-key", "<idempotency-key>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"expected_version\": 1\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.checkfu.com/v1/principals/{id}/connections/{connectionId}/revocation-sessions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["checkfu-version"] = '<checkfu-version>'
request["idempotency-key"] = '<idempotency-key>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"expected_version\": 1\n}"
response = http.request(request)
puts response.read_body{
"session": {
"id": "<string>",
"workspace_id": "<string>",
"owner_principal_id": "<string>",
"connection_id": "<string>",
"connection_revision_id": "<string>",
"operation": "connect",
"flow": {
"kind": "oauth"
},
"status": "pending_runtime",
"failure": "client_rejected",
"cleanup_pending": true,
"expires_at": "<string>",
"version": 1,
"created_at": "<string>",
"updated_at": "<string>"
},
"next_action": {
"kind": "open_url",
"completion": "callback",
"url": "<string>",
"expires_at": "<string>"
}
}{
"error": {
"type": "validation.malformed",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-malformed"
}
}{
"error": {
"type": "auth.invalid_key",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-invalid-key"
}
}{
"error": {
"type": "auth.disabled_tenancy",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-disabled-tenancy"
}
}{
"error": {
"type": "validation.not_found",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-not-found"
}
}{
"error": {
"type": "validation.conflict",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-conflict"
}
}{
"error": {
"type": "budget.exceeded",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#budget-exceeded"
}
}{
"error": {
"type": "runtime.internal",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#runtime-internal"
}
}Begin a Connection revocation session
Begin revocation for the named Principal’s exact Integration Gateway Connection and optimistic version. First read getConnectionRevocationImpact and use its returned version as this CAS fence. Checkfu denies the Connection locally before supplier cleanup and returns the durable ConnectionSession; a terminal revoked session can still report cleanup_pending while safe reconciliation finishes. Requires an Idempotency-Key.
Checkfu support posture: alpha; hosted. Required evidence journey: connection-lifecycle. Deployment-specific readiness and the latest proven release are available from GET /v1/support/capabilities.
POST
/
v1
/
principals
/
{id}
/
connections
/
{connectionId}
/
revocation-sessions
Begin a Connection revocation session
curl --request POST \
--url https://api.checkfu.com/v1/principals/{id}/connections/{connectionId}/revocation-sessions \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'checkfu-version: <checkfu-version>' \
--header 'idempotency-key: <idempotency-key>' \
--data '
{
"expected_version": 1
}
'import requests
url = "https://api.checkfu.com/v1/principals/{id}/connections/{connectionId}/revocation-sessions"
payload = { "expected_version": 1 }
headers = {
"checkfu-version": "<checkfu-version>",
"idempotency-key": "<idempotency-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'checkfu-version': '<checkfu-version>',
'idempotency-key': '<idempotency-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({expected_version: 1})
};
fetch('https://api.checkfu.com/v1/principals/{id}/connections/{connectionId}/revocation-sessions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.checkfu.com/v1/principals/{id}/connections/{connectionId}/revocation-sessions",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'expected_version' => 1
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"checkfu-version: <checkfu-version>",
"idempotency-key: <idempotency-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.checkfu.com/v1/principals/{id}/connections/{connectionId}/revocation-sessions"
payload := strings.NewReader("{\n \"expected_version\": 1\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("checkfu-version", "<checkfu-version>")
req.Header.Add("idempotency-key", "<idempotency-key>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.checkfu.com/v1/principals/{id}/connections/{connectionId}/revocation-sessions")
.header("checkfu-version", "<checkfu-version>")
.header("idempotency-key", "<idempotency-key>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"expected_version\": 1\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.checkfu.com/v1/principals/{id}/connections/{connectionId}/revocation-sessions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["checkfu-version"] = '<checkfu-version>'
request["idempotency-key"] = '<idempotency-key>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"expected_version\": 1\n}"
response = http.request(request)
puts response.read_body{
"session": {
"id": "<string>",
"workspace_id": "<string>",
"owner_principal_id": "<string>",
"connection_id": "<string>",
"connection_revision_id": "<string>",
"operation": "connect",
"flow": {
"kind": "oauth"
},
"status": "pending_runtime",
"failure": "client_rejected",
"cleanup_pending": true,
"expires_at": "<string>",
"version": 1,
"created_at": "<string>",
"updated_at": "<string>"
},
"next_action": {
"kind": "open_url",
"completion": "callback",
"url": "<string>",
"expires_at": "<string>"
}
}{
"error": {
"type": "validation.malformed",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-malformed"
}
}{
"error": {
"type": "auth.invalid_key",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-invalid-key"
}
}{
"error": {
"type": "auth.disabled_tenancy",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-disabled-tenancy"
}
}{
"error": {
"type": "validation.not_found",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-not-found"
}
}{
"error": {
"type": "validation.conflict",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-conflict"
}
}{
"error": {
"type": "budget.exceeded",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#budget-exceeded"
}
}{
"error": {
"type": "runtime.internal",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#runtime-internal"
}
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Headers
Available options:
2026-08-24 Required string length:
1 - 255Path Parameters
Pattern:
^prin_[0-9a-f]{32}$Pattern:
^conn_[0-9a-f]{32}$Body
application/json
Required range:
x > 0