curl --request DELETE \
--url https://app.thinnest.ai/api/v1/customers/{id}/keys/{keyId} \
--header 'Authorization: Bearer <token>'const options = {method: 'DELETE', headers: {Authorization: 'Bearer <token>'}};
fetch('https://app.thinnest.ai/api/v1/customers/{id}/keys/{keyId}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/customers/{id}/keys/{keyId}"
headers = {"Authorization": "Bearer <token>"}
response = requests.delete(url, headers=headers)
print(response.text){
"id": "0c7e4a92-3d1b-4f6a-8e25-91b7c3d4f5a6",
"name": "Sunrise front-desk dashboard",
"prefix": "ta_live_Xk3pQ9",
"scope": "read",
"createdAt": "2026-10-03T08:22:10.511Z",
"lastUsedAt": "2026-10-06T09:58:47.090Z",
"revokedAt": "2026-10-06T10:20:03.615Z"
}{
"error": "Manage customers without the Thinnest-Workspace header: they belong to your own workspace."
}{
"error": "Send a valid API key as `Authorization: Bearer <key>`."
}{
"error": "This API key is read-only: it can read everything but change nothing."
}{
"error": "Key not found, or already revoked."
}{
"error": "This workspace resells the console under white label: its workspaces are clients, managed in White label → Clients, not API customers."
}{
"error": "Over 240 requests a minute. Slow down and retry."
}Revoke Customer Key
Revokes one of a customer’s keys, immediately: its next request answers 401. Answers with the key as it now is. A key already revoked is 404. Needs a full key.
curl --request DELETE \
--url https://app.thinnest.ai/api/v1/customers/{id}/keys/{keyId} \
--header 'Authorization: Bearer <token>'const options = {method: 'DELETE', headers: {Authorization: 'Bearer <token>'}};
fetch('https://app.thinnest.ai/api/v1/customers/{id}/keys/{keyId}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/customers/{id}/keys/{keyId}"
headers = {"Authorization": "Bearer <token>"}
response = requests.delete(url, headers=headers)
print(response.text){
"id": "0c7e4a92-3d1b-4f6a-8e25-91b7c3d4f5a6",
"name": "Sunrise front-desk dashboard",
"prefix": "ta_live_Xk3pQ9",
"scope": "read",
"createdAt": "2026-10-03T08:22:10.511Z",
"lastUsedAt": "2026-10-06T09:58:47.090Z",
"revokedAt": "2026-10-06T10:20:03.615Z"
}{
"error": "Manage customers without the Thinnest-Workspace header: they belong to your own workspace."
}{
"error": "Send a valid API key as `Authorization: Bearer <key>`."
}{
"error": "This API key is read-only: it can read everything but change nothing."
}{
"error": "Key not found, or already revoked."
}{
"error": "This workspace resells the console under white label: its workspaces are clients, managed in White label → Clients, not API customers."
}{
"error": "Over 240 requests a minute. Slow down and retry."
}Authorizations
Your API key (ta_live_…) from Settings → API keys, sent as Authorization: Bearer <key>. Keep it on a server: it can message every customer you have. A key is full, build or read-only; a request its level does not allow is refused with 403.
Path Parameters
The customer's id (org_…), as Create Customer answered.
The key's id, from List Customer Keys.
Response
The key, now revoked.
An API key that works in one customer only. Never carries the secret.
The key's id, for revoking it.
"0c7e4a92-3d1b-4f6a-8e25-91b7c3d4f5a6"
What you called it.
"Sunrise front-desk dashboard"
The key's first characters, so you can tell keys apart.
"ta_live_Xk3pQ9"
Its access level: full everything; build everything except messaging customers, sending codes and placing calls; read reads only.
full, build, read "read"
"2026-10-03T08:22:10.511Z"
When it last made a request; null if never.
"2026-10-06T09:58:47.090Z"
When it was revoked; null while it works.
null