Withdraw a tenant's trusted issuer (platform)

Withdraws the declaration. Tokens from that issuer stop authenticating on the very
next request — there is no grace window and no scheduled sweep, because a timer that
withdrew trust at a moment no operator chose would cut a customer's production
authentication without anyone deciding to.

🔴 Refused with 409 while actor bindings still name this issuer. The

bindings are what actually grant workloads access, and withdrawing the issuer under
them would leave rows pointing at a trust relationship that no longer exists —
invisible until a workload fails to authenticate. Remove the bindings first; the
refusal reports how many there are.

An operator withdrawing a customer's issuer is stopping that customer's workloads from authenticating. The audit row is filed under the customer, so their own trail shows who did it and when.

Not entitlement-gated. The operator is the party that sells the edition, so

refusing them on it would be the platform refusing itself. The tenant's own verdict is
readable at ../workload-identity/entitlement (SR-10.6).

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
uuid
required
uuid
required
Responses
204

Withdrawn. Nothing is returned.

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/problem+json