curl -X DELETE "https://qcg-api.scanova.io/console/token/401f7ac837da42b97f613d789819ff93537bee6a/" \
-H "Authorization: Bearer <your_oauth_access_token>"
Management API — Tokens & Usage
Remove an API token
DELETE /console/token//
DELETE
/
console
/
token
/
{key}
/
curl -X DELETE "https://qcg-api.scanova.io/console/token/401f7ac837da42b97f613d789819ff93537bee6a/" \
-H "Authorization: Bearer <your_oauth_access_token>"
Permanently revokes a Management API key. Like creating a token, this lives on the regular Scanova API host (
qcg-api.scanova.io) and is authenticated with your normal dashboard OAuth access token — not the key you’re deleting.
Request
DELETE https://qcg-api.scanova.io/console/token/{key}/
Authorization: Bearer <your_oauth_access_token>
string
required
The full key value returned when the token was created (not a numeric ID).
curl -X DELETE "https://qcg-api.scanova.io/console/token/401f7ac837da42b97f613d789819ff93537bee6a/" \
-H "Authorization: Bearer <your_oauth_access_token>"
Behavior
- A successful removal returns
204 No Contentwith an empty body. - Once deleted, the key stops authenticating on the data host immediately — any in-flight or subsequent requests using it get
401. - You can only delete a key you own (or, for a shared user, a key that shared user created).
Deletion also re-checks plan quota using an
environment value, defaulting to sandbox if you don’t pass one — the same rule described on the create token page. This rarely matters in practice since plans that grant Management API access typically grant it across all environments, but pass ?environment=live explicitly if you hit an unexpected 401 deleting a live-environment key.There’s no “disable” or “pause” state — removal is immediate and permanent. If you just need to stop a key from being used temporarily, don’t delete it; create a new key and stop using the old one, or coordinate with the integration consuming it before deleting.
Related
- Management API overview — the two-host auth architecture this endpoint is part of.
- Create an API token — generate a replacement key, and see the listing/quota rules this endpoint shares.
- Usage statistics — check a key’s usage before deciding whether to remove it.
Authorizations
Send your Management API key as the raw value of the Authorization header — no "Bearer " or "Token " prefix, and no other characters. Example: Authorization: 401f7ac837da42b97f613d789819ff93537bee6a. A header containing more than one space-separated part is rejected outright. Requests also require the request's Host header to be the management API host (e.g. management.scanova.io) — the same key sent to the regular API host will not authenticate.
Path Parameters
Response
204
Token removed
Was this page helpful?
⌘I