> ## Documentation Index
> Fetch the complete documentation index at: https://docs.dev.symbiosis.markets/llms.txt
> Use this file to discover all available pages before exploring further.

# Revoke one of the session user's API keys.



## OpenAPI

````yaml /openapi.yaml delete /auth/api-keys/{api_key_id}
openapi: 3.1.0
info:
  title: Symbiosis API
  description: >-
    The Symbiosis REST API.


    ## Authentication


    Endpoints accept one of two credentials:


    - **Session token** — `Authorization: Bearer <token>`, from `POST
    /auth/login`.

    - **API key (HMAC)** — three headers on every request:
      - `APIKEY`: the API key id, from `POST /auth/api-keys`.
      - `X-Hmac-Timestamp`: current Unix time in milliseconds.
      - `X-Hmac-Signature`: Base64-encoded HMAC-SHA256 of
        `timestamp_ms "\n" METHOD "\n" PATH_AND_QUERY "\n" BODY`, keyed with the API key
        secret. `PATH_AND_QUERY` is the full request target including the query string.

    ## Wire formats


    Token amounts (`U256`) serialize in responses as 0x-prefixed hex strings;
    requests accept decimal strings, 0x-prefixed hex strings, or JSON numbers.
    Asset ids and addresses are 0x-prefixed hex strings. Prices are integers
    scaled by 1e6.
  version: 0.1.0
servers:
  - url: https://api.symbiosis.markets
security: []
tags:
  - name: auth
    description: Accounts, sessions, API keys, and websocket tickets.
  - name: custody
    description: Deposit addresses, balances, and withdrawals.
  - name: rfq
    description: Quote requests, quotes, and matching.
paths:
  /auth/api-keys/{api_key_id}:
    delete:
      tags:
        - auth
      summary: Revoke one of the session user's API keys.
      operationId: revoke_api_key
      responses:
        '204':
          description: no content
        '401':
          description: Invalid or missing session token.
      security:
        - SessionBearer: []
components:
  securitySchemes:
    SessionBearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Session token from `POST /auth/login`.

````