Withdraw a deployment-wide trusted issuer

Withdraws the declaration. Tokens from that issuer stop verifying for every tenant
from the next request onward.

🔴 Refused with a 409 while any binding still depends on it — in any tenant. Never a cascade. A cascade would delete, in one unremarkable-looking DELETE, the entire authentication path of every workload bound to this issuer across every customer on the deployment, at a moment the operator was tidying a registry rather than one they had chosen to cut those workloads off. The refusal names the count, so "you cannot do this" becomes "here is how much there is to do first"; the count is published as an extension member so a console need not parse the sentence.

The count spans every tenant, deliberately. A dependency check that only looked at one tenant would let a withdrawal that orphans forty other customers' workloads answer that nothing depends on this issuer. It is a count and not a list: the number is what the refusal needs, while the rows would tell a platform operator which customers run which workloads.

To stop trusting an issuer immediately without removing anything, use disable — it takes effect on the next request and is reversible.

Never entitlement-gated. No Edition widens or narrows this plane. These are

the deployment operator's own declarations rather than a tenant's, so there is no
Edition to consult (FR-181.16).

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
uuid
required
Responses
204

Withdrawn. The declaration is gone and its issuer URL is declarable again.

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/problem+json