Revoke a single CLI session owned by the caller
Revoke a single CLI session owned by the caller. Cookie auth required. revoked: false is returned when the family does not exist, does not belong to the caller, or has already been revoked — the route layer does not distinguish these cases at the HTTP shape so an attacker who somehow guessed a family_id cannot probe ownership through the response.
POST
/api/auth/cli/sessions/revokeAuthorization
cookieAuth better-auth.session_token<token>
Cookie session from Better Auth. Requires X-Org-Id header for org-scoped routes.
In: cookie
Request Body
application/json
curl -X POST "https://your-instance/api/auth/cli/sessions/revoke" \ -H "Content-Type: application/json" \ -d '{ "familyId": "string" }'{
"revoked": true
}{
"error": "string",
"error_description": "string"
}