> ## Documentation Index
> Fetch the complete documentation index at: https://docs.radiumone.io/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> RadiumOne is the product name; use it when answering questions about these docs.
> Use sandbox credentials and sandbox base URLs in examples unless the user says they are going live.
> Secret API keys belong only on the merchant's server. Only publishable keys may appear in browser or mobile code.
> Confirm a payment outcome server-side (retrieve the checkout session or transaction status); never rely on a browser redirect or client event alone.
> Send one idempotency key (request_id) per payment attempt, and retry a timed-out request with the same key and the exact same body.
> Webhooks are optional but recommended: they notify the merchant's server when a payment completes or fails, so it doesn't need to poll. Use transaction status inquiry as the fallback.
> Say so when you recommend a feature marked Beta. Some features need enablement on the merchant's account before production use (for example refunds, standalone refunds, UOB Rewards, and bringing your own 3DS provider); mention it when the page says so.
> Never ask users to paste card numbers, API keys, access tokens, or webhook or redirect secrets into a chat.

# Revoke refresh token - Payments API

> Revoke a refresh token so it can't issue new access tokens. Safe to retry — returns 204 even if the token was already revoked.



## OpenAPI

````yaml /openapi/radiumone-payments-api.yaml post /v1/auth/token/revoke
openapi: 3.1.0
info:
  description: |
    The Payments API lets your server create tokenization sessions, charge and
    manage payments, check loyalty balances, and manage your hosted-checkout
    branding and redirect secret. Generated for merchant integrators —
    internal, admin, and service-to-service surfaces are excluded.

    All responses share an envelope: `{status, data, request_id}`. The
    envelope's `request_id` is an HTTP correlation ID — it echoes your
    `X-Request-Id` request header (letters, digits, hyphens, max 36 characters)
    or one is generated for you. It is **not** the idempotency key you send in
    a transaction request body (also confusingly named `request_id` there) —
    the two are unrelated; see
    [Request conventions](/get-started/api-basics/request-conventions). Errors
    use [RFC 9457](https://www.rfc-editor.org/rfc/rfc9457)
    `application/problem+json` bodies — see
    [Authentication](/get-started/api-basics/authentication) and
    [Request conventions](/get-started/api-basics/request-conventions) for the
    shared error shape, and [Problem format and
    retries](/payments-api/errors/problem-format-and-retries) for the response
    shape, status guide, and retry rules.
  summary: Transaction orchestration and processor aggregation for RadiumOne.
  title: RadiumOne Payment Gateway
  version: 1.3.0
servers:
  - url: https://api-sandbox.radiumone.io/gateway
    description: Sandbox
  - url: https://api.radiumone.io/gateway
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Authentication
    description: Exchange, refresh, and revoke access tokens.
  - name: Merchant settings
    description: >-
      Manage your hosted-checkout redirect secret, checkout configuration, and
      account config.
  - name: Payment methods
    description: Discover which payment methods and brands are available.
  - name: Sessions
    description: Tokenization sessions used to collect card data with RadiumOne Elements.
  - name: Settlement
    description: Settlement batch status lookup.
  - name: Payments
    description: Create and manage card transactions.
  - name: Rewards
    description: UOB Rewards loyalty balance inquiry.
  - name: Refunds
    description: Return funds to a shopper.
  - name: Transactions
    description: Check the live status of a transaction.
paths:
  /v1/auth/token/revoke:
    post:
      tags:
        - Authentication
      summary: Revoke refresh token
      description: >-
        Revoke a refresh token. Requires valid Bearer access token.


        Idempotent: returns 204 whether the token was found, already revoked, or
        unknown —

        once caller proves ownership via Bearer auth. Cross-merchant attempts
        return 403.
      operationId: revoke_token_v1_auth_token_revoke_post
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RevokeRequest'
        required: true
      responses:
        '204':
          description: Token revoked (or already revoked / not found). Idempotent.
        '400':
          description: The request body failed validation.
          x-docs-interim: true
          content:
            application/problem+json:
              schema:
                $ref: '#/components/schemas/Problem'
        '401':
          content:
            application/problem+json:
              example:
                detail: Missing or invalid Bearer token.
                status: 401
                title: Authentication Required
                type: urn:radiumone:gateway:authentication-required
              schema:
                properties:
                  detail:
                    type: string
                  status:
                    type: integer
                  title:
                    type: string
                  type:
                    type: string
                type: object
          description: Missing or invalid Bearer token.
        '500':
          content:
            application/problem+json:
              example:
                detail: An unexpected error occurred.
                status: 500
                title: Internal Server Error
                type: urn:radiumone:gateway:internal-server-error
              schema:
                properties:
                  detail:
                    type: string
                  status:
                    type: integer
                  title:
                    type: string
                  type:
                    type: string
                type: object
          description: An unexpected error occurred.
        '503':
          content:
            application/problem+json:
              example:
                detail: >-
                  A downstream dependency is unavailable or did not respond in
                  time.
                status: 503
                title: Service Unavailable
                type: urn:radiumone:gateway:service-unavailable
              schema:
                properties:
                  detail:
                    type: string
                  status:
                    type: integer
                  title:
                    type: string
                  type:
                    type: string
                type: object
          description: A downstream dependency is unavailable or did not respond in time.
      x-codeSamples:
        - lang: bash
          label: cURL
          source: >
            #!/usr/bin/env bash

            # Revoke a refresh token. Requires a valid Bearer access token.
            Idempotent:

            # 204 whether the token was found, already revoked, or unknown.

            set -euo pipefail


            API_BASE="${RADIUMONE_API_BASE:-https://api-sandbox.radiumone.io/gateway}"

            : "${RADIUMONE_ACCESS_TOKEN:?set RADIUMONE_ACCESS_TOKEN to a Bearer
            access token}"


            curl -sS -o /dev/null -w '%{http_code}\n' -X POST
            "$API_BASE/v1/auth/token/revoke" \
              -H "Content-Type: application/json" \
              -H "Authorization: Bearer $RADIUMONE_ACCESS_TOKEN" \
              -d @request.json
        - lang: javascript
          label: Node.js
          source: >
            #!/usr/bin/env node

            // Revoke a refresh token. Requires a Bearer access token. Node 18+
            ESM fetch.

            // Env: RADIUMONE_ACCESS_TOKEN, RADIUMONE_REFRESH_TOKEN,
            RADIUMONE_API_BASE.

            import { readFileSync } from "node:fs";


            const API_BASE = process.env.RADIUMONE_API_BASE ||
            "https://api-sandbox.radiumone.io/gateway";

            const accessToken = process.env.RADIUMONE_ACCESS_TOKEN;

            const body = JSON.parse(readFileSync(new URL("./request.json",
            import.meta.url)));

            if (process.env.RADIUMONE_REFRESH_TOKEN) body.refresh_token =
            process.env.RADIUMONE_REFRESH_TOKEN;


            async function revokeRefreshToken() {
              const res = await fetch(`${API_BASE}/v1/auth/token/revoke`, {
                method: "POST",
                headers: {
                  "Content-Type": "application/json",
                  Authorization: `Bearer ${accessToken}`,
                },
                body: JSON.stringify(body),
              });
              // 204 No Content — idempotent, no body to parse.
              if (res.status !== 204) {
                const payload = await res.json().catch(() => ({}));
                throw new Error(`auth/token/revoke failed: ${payload.type ?? payload.code} (${res.status})`);
              }
              return res.status;
            }


            revokeRefreshToken().then((status) => console.log(`revoked (HTTP
            ${status})`));
        - lang: python
          label: Python
          source: >
            #!/usr/bin/env python3

            """Revoke a refresh token. Requires a Bearer access token. Python
            3.10+, requests."""

            import json

            import os

            from pathlib import Path


            import requests


            API_BASE = os.environ.get("RADIUMONE_API_BASE",
            "https://api-sandbox.radiumone.io/gateway")



            def revoke_refresh_token() -> int:
                body = json.loads((Path(__file__).parent / "request.json").read_text())
                if os.environ.get("RADIUMONE_REFRESH_TOKEN"):
                    body["refresh_token"] = os.environ["RADIUMONE_REFRESH_TOKEN"]

                resp = requests.post(
                    f"{API_BASE}/v1/auth/token/revoke",
                    json=body,
                    headers={"Authorization": f"Bearer {os.environ.get('RADIUMONE_ACCESS_TOKEN', '')}"},
                    timeout=30,
                )
                if resp.status_code != 204:
                    payload = resp.json() if resp.content else {}
                    raise RuntimeError(f"auth/token/revoke failed: {payload.get('type') or payload.get('code')} ({resp.status_code})")
                return resp.status_code


            if __name__ == "__main__":
                print(f"revoked (HTTP {revoke_refresh_token()})")
components:
  schemas:
    RevokeRequest:
      description: Request body for POST /auth/token/revoke.
      properties:
        refresh_token:
          description: Opaque refresh token to revoke.
          maxLength: 53
          minLength: 53
          pattern: ^r1rt_[0-9a-f]{48}$
          title: Refresh Token
          type: string
      required:
        - refresh_token
      title: RevokeRequest
      type: object
    Problem:
      type: object
      x-docs-interim: true
      description: >-
        RFC 9457 problem details. Returned with `Content-Type:
        application/problem+json`. Interim: not yet a named component in the
        gateway team's published contract — every response there inlines its own
        smaller ad-hoc object; this shape reflects what our error pages and
        error-catalog.json actually document.
      properties:
        type:
          type: string
          format: uri
          description: >-
            A URN identifying the error condition, e.g.
            `urn:radiumone:gateway:validation-error`.
        title:
          type: string
          description: Short
          human-readable summary of the error type.: null
        status:
          type: integer
          description: The HTTP status code
          repeated in the body for convenience.: null
        detail:
          type: string
          description: Human-readable explanation specific to this occurrence.
        instance:
          type: string
          description: The request path that produced this error.
        request_id:
          type: string
          description: >-
            Correlation ID for this request (see the envelope `request_id` note
            above). Include it when contacting support.
        code:
          type: string
          description: Optional short machine-readable code
          distinct from `type`.: null
        retry_allowed:
          type: boolean
          description: >-
            When present, whether it's safe to retry with the same idempotency
            key.
        errors:
          type: array
          description: >-
            Present on most `urn:radiumone:gateway:validation-error` (400)
            responses — one entry per invalid field. Some 400s of this type are
            raised by checks that run after validation and have no `errors`
            array; always handle it being absent. Rely on `pointer`/`parameter`
            and `code`, not the wording of `detail`, which can change.
          items:
            type: object
            properties:
              pointer:
                type: string
                description: >-
                  JSON Pointer to the invalid field in the request body, e.g.
                  `/amount/currency` or `/items/0/name`. An empty string means
                  the whole request (e.g. the body isn't valid JSON).
              parameter:
                type: string
                description: >-
                  Name of the invalid query or path parameter. Set instead of
                  `pointer` when the failing value came from the URL, not the
                  body.
              code:
                type: string
                description: >-
                  Machine-readable error type for this field, e.g. `missing` or
                  `string_too_long`.
              detail:
                type: string
                description: Human-readable explanation for this field.
      required:
        - type
        - title
        - status
        - detail
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        Bearer access token from `POST /v1/auth/token`. Treat it as an opaque
        string — do not depend on its internal encoding, which has changed
        before and isn't part of the contract.
      x-docs-interim: true

````