Withdraws the declaration. Tokens from that issuer stop authenticating on the very
next request — there is no grace window and no scheduled sweep, because a timer that
withdrew trust at a moment no operator chose would cut a customer's production
authentication without anyone deciding to.
🔴 Refused with 409 while actor bindings still name this issuer. The
bindings are what actually grant workloads access, and withdrawing the issuer under
them would leave rows pointing at a trust relationship that no longer exists —
invisible until a workload fails to authenticate. Remove the bindings first; the
refusal reports how many there are.
An operator withdrawing a customer's issuer is stopping that customer's workloads from authenticating. The audit row is filed under the customer, so their own trail shows who did it and when.
Not entitlement-gated. The operator is the party that sells the edition, so
refusing them on it would be the platform refusing itself. The tenant's own verdict is
readable at ../workload-identity/entitlement (SR-10.6).
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
204Withdrawn. Nothing is returned.