How-To GuidesCredential Management
Revoke Credentials
How to revoke API credentials
How to Revoke Credentials
This guide shows you how to revoke API credentials that are no longer needed or may have been compromised.
Before You Start
Ensure you have:
- The client ID of the credential to revoke
- Admin access (credentials.write scope)
- Certainty that no systems depend on this credential
Revoke a Credential
1. Find the Client ID
List credentials to find the one you want to revoke:
arctic credentials list2. Revoke the Credential
arctic credentials revoke CLIENT_ID3. Verify Revocation
Confirm the credential no longer appears:
arctic credentials listImmediate Effect
Revocation takes effect immediately:
- Existing access tokens issued to this credential become invalid
- New token requests with this credential will fail
- There is no grace period (unlike rotation)
When to Revoke
Consider revoking credentials when:
- Credential compromised: Someone gained unauthorized access
- Employee departure: Remove access for former team members
- Scope change: Replace with credentials having different permissions
- Cleanup: Remove unused credentials
Cannot Revoke Current Credential
You cannot revoke the credential you are currently using:
Error: cannot revoke the credential currently in useTo revoke your current credential:
- Create new credentials:
arctic credentials create - Update your config to use the new credentials
- Revoke the old credential
Troubleshooting
Credential Not Found
If the client ID is not found:
- Verify the client ID:
arctic credentials list - The credential may have already been revoked
Cannot Revoke
If revocation fails:
- Check you have
credentials.writescope - Verify you are not revoking your current credential
- Check agent logs for errors