Removes the binding. That external identity stops authenticating as this actor on
the very next request — no grace window, because the reason an operator removes a
binding is usually that it should already have stopped.
This is the narrowest revocation this feature has: it withdraws ONE workload without touching the issuer, the other bindings, or anything the customer's other workloads depend on. Disabling the issuer is the wider lever and is a different call.
Rebinding is a delete and a create rather than a mutation, because a binding either exists or is gone and there is no intermediate state worth recording.
Not entitlement-gated. The operator is the party that sells the edition, so
refusing them on it would be the platform refusing itself. The tenant's own verdict is
readable at ../workload-identity/entitlement (SR-10.6).
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
204Removed. Nothing is returned.