Skip to main content

API access token revocation (1.7.0)

Sam Critchley
Co-Founder

A security improvement to privileged authentication in the Spaaza API.

  • Fixed the checks made on each request that uses privileged (Bearer access token) authentication. A request is now rejected if the access token is inactive or deleted, or if the service client that owns the access token is disabled or deleted. Previously such a request could still authenticate for a period of time after the token or service client was revoked. See access token revocation.
  • Changed the error returned for a request made with a revoked access token, or with an access token of a disabled or deleted service client. Such requests now return access_token_invalid (code 266, HTTP status 401) at authentication time instead of access_denied (code 424). This change is not tied to an API version. API clients that check for access_denied in this situation should check for access_token_invalid instead.