We use impersonation feature in Zitadel and we need to be able to revoke issued tokens. We have a service user (used by our backed) with a proper role (impersonator) that communicates with Zitadel. But when calling /oauth/v2/revoke I always get “invalid client - token was not issued for this client”. Even though the same client (service user - client ID/Secret) is used for these requests. Moreover /oauth/v2/introspect endpoint works fine. Both “revoke” and “introspect” have the same payload (token, client ID, client Secret). Could anyone help with that?
Continue the conversation
Join the Discord to ask follow-up questions and connect with the community
Z
ZITADEL
ZITADEL - Identity infrastructure, simplified for you.