import { createClient } from "@mailsai/sdk";
const client = createClient(); // reads MAILS_API_KEY
const result = await client.connected_apps.revoke(
"oag_01JZX8K3M9Q4P7VN2YB6RTDC0E",
);
console.log(result);from mailsai import create_client
client = create_client() # reads MAILS_API_KEY
result = client.revoke_connected_app(
"oag_01JZX8K3M9Q4P7VN2YB6RTDC0E",
)
print(result)curl -X DELETE 'https://api.mails.ai/v1/oauth/grants/oag_01JZX8K3M9Q4P7VN2YB6RTDC0E' \
-H "Authorization: Bearer $MAILS_API_KEY"mails connected-apps revoke oag_01JABC --yes{
"name": "mails_connected_apps_revoke",
"arguments": {
"app_id": "oag_01JZX8K3M9Q4P7VN2YB6RTDC0E"
}
}{
"id": "oag_01JZX8K3M9Q4P7VN2YB6RTDC0E",
"client_id": "<client_id>",
"client_name": "<client_name>",
"first_party": false,
"scope": "<scope>",
"scopes": ["send"],
"created_at": "2026-10-04T12:00:00.000Z",
"approved_at": "2026-10-04T12:00:00.000Z",
"last_used_at": "2026-10-04T12:00:00.000Z",
"created_api_keys": 0,
"created_webhooks": 0,
"signing_secrets_known": 0,
"revoked_at": "2026-10-04T12:00:00.000Z"
}200 The revoked app, with what it left behind.
401 Missing or invalid API key.
403 The API key lacks the required scope
(insufficient_scope), or the token belongs to an
app connected by sign-in and this operation is
closed to connected apps
(connected_app_not_allowed).
404 Resource not found in this workspace, or the agent
a send names is archived (agent_archived).
500 Internal server error.Revoke a connected app
import { createClient } from "@mailsai/sdk";
const client = createClient(); // reads MAILS_API_KEY
const result = await client.connected_apps.revoke(
"oag_01JZX8K3M9Q4P7VN2YB6RTDC0E",
);
console.log(result);from mailsai import create_client
client = create_client() # reads MAILS_API_KEY
result = client.revoke_connected_app(
"oag_01JZX8K3M9Q4P7VN2YB6RTDC0E",
)
print(result)curl -X DELETE 'https://api.mails.ai/v1/oauth/grants/oag_01JZX8K3M9Q4P7VN2YB6RTDC0E' \
-H "Authorization: Bearer $MAILS_API_KEY"mails connected-apps revoke oag_01JABC --yes{
"name": "mails_connected_apps_revoke",
"arguments": {
"app_id": "oag_01JZX8K3M9Q4P7VN2YB6RTDC0E"
}
}{
"id": "oag_01JZX8K3M9Q4P7VN2YB6RTDC0E",
"client_id": "<client_id>",
"client_name": "<client_name>",
"first_party": false,
"scope": "<scope>",
"scopes": ["send"],
"created_at": "2026-10-04T12:00:00.000Z",
"approved_at": "2026-10-04T12:00:00.000Z",
"last_used_at": "2026-10-04T12:00:00.000Z",
"created_api_keys": 0,
"created_webhooks": 0,
"signing_secrets_known": 0,
"revoked_at": "2026-10-04T12:00:00.000Z"
}200 The revoked app, with what it left behind.
401 Missing or invalid API key.
403 The API key lacks the required scope
(insufficient_scope), or the token belongs to an
app connected by sign-in and this operation is
closed to connected apps
(connected_app_not_allowed).
404 Resource not found in this workspace, or the agent
a send names is archived (agent_archived).
500 Internal server error.Path Parameters
The connected app's id (oag_…), from List connected apps.
The API keys and webhook endpoints it created, and the webhook signing secrets it was shown, stay; the response counts them, so revoke and rotate those yourself. (Only when one of its refresh tokens is used twice, a sign of theft, does mails.ai remove them as well, and rotate those secrets again.) Idempotent: revoking an app already revoked returns its existing revoked_at. Closed to apps connected by sign-in (403 connected_app_not_allowed), and to a key tied to one agent (403): use an API key with manage that is not tied to an agent, or the mails CLI.
Response
The sign-in's id (oag_…): the id in the path.
The app's OAuth client id: the id it registered with, or the address of its client-ID document.
The name the app gave itself, at most 80 characters, or null when it gave none; mails CLI for the mails CLI.
true for the mails CLI, false for an app somebody connected by signing in.
What the person had approved: full_access, send or read.
What its tokens could do until the revoke, in the API key scopes: full_access = send + read + manage, send = send + read, read = read. Never more than the role of the person who approved it gave an app: a Member's apps never hold manage, and a Billing member's hold read only.
When the app was first approved.
When it was last approved before this revoke.
When one of its tokens was last used, recorded at most once a minute. Null when none was used.
API keys it created that still work after the revoke.
Webhook endpoints it created, still in place after the revoke.
Other webhook endpoints still signing with a secret it was shown.
When the sign-in was ended and its tokens stopped working. For one that was already revoked, the time it ended then.
Was this page helpful?