Takes the declaration out of the effective trust set, keeping the row and everything
configured on it. Tokens from that issuer are refused on the very next request.
This is the operator's fastest lever when a customer's authorization server is compromised: one call, immediate, and reversible without retyping the declaration. The bindings that name the issuer are left in place, so re-enabling restores exactly the access that was suspended rather than a re-derived approximation of it.
Idempotent, for the same reason as its counterpart.
Not entitlement-gated. The operator is the party that sells the edition, so
refusing them on it would be the platform refusing itself. The tenant's own verdict is
readable at ../workload-identity/entitlement (SR-10.6).
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||