Remove an external identity's ability to authenticate as this actor

Deletes the binding. From the very next request, a token from that issuer naming
that subject authenticates nothing — indistinguishably from every other cause, so a
client cannot learn from the refusal that the binding ever existed.

Everything else is kept. The actor still exists with its roles, capability grants and exchange context, and any credentials it holds directly are untouched; only this one external identity stops resolving to it.

A hard delete, not a soft one. A binding exists or it is gone, so revoking access has exactly one shape and an operator under pressure has exactly one thing to do. The audit trail is what preserves the fact that it existed.

🔴 Ungated, and that is a deliberate asymmetry with the create. A tenant

must be able to reduce its own exposure whatever its billing state has done.
Gating this behind an entitlement would trap a downgraded customer with a live
binding they cannot remove — a workload that keeps authenticating precisely because
the tenant stopped paying for the feature that would let them stop it.

Nothing removes a binding on a timer. There is no sweep, no grace window

and no automatic suspension anywhere in this feature: a schedule that cut a
customer's production authentication N days after a billing event would do it at a
moment no operator chose and with no human in the loop.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
uuid
required
uuid
required
uuid
required
Responses
204

Removed. No body — there is no post-state to describe.

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/problem+json