Skip to main content
DELETE
Permanently revokes a Management API key. Like creating a token, this lives on the regular Scanova API host (qcg-api.scanova.io) and is authenticated with your normal dashboard OAuth access token — not the key you’re deleting.

Request

string
required
The full key value returned when the token was created (not a numeric ID).

Behavior

  • A successful removal returns 204 No Content with an empty body.
  • Once deleted, the key stops authenticating on the data host immediately — any in-flight or subsequent requests using it get 401.
  • You can only delete a key you own (or, for a shared user, a key that shared user created).
Deletion also re-checks plan quota using an environment value, defaulting to sandbox if you don’t pass one — the same rule described on the create token page. This rarely matters in practice since plans that grant Management API access typically grant it across all environments, but pass ?environment=live explicitly if you hit an unexpected 401 deleting a live-environment key.
There’s no “disable” or “pause” state — removal is immediate and permanent. If you just need to stop a key from being used temporarily, don’t delete it; create a new key and stop using the old one, or coordinate with the integration consuming it before deleting.

Authorizations

Authorization
string
header
required

Send your Management API key as the raw value of the Authorization header — no "Bearer " or "Token " prefix, and no other characters. Example: Authorization: 401f7ac837da42b97f613d789819ff93537bee6a. A header containing more than one space-separated part is rejected outright. Requests also require the request's Host header to be the management API host (e.g. management.scanova.io) — the same key sent to the regular API host will not authenticate.

Path Parameters

key
string
required

Response

204

Token removed