Remove a tenant's issuer from its trust set (platform)

Takes the declaration out of the effective trust set, keeping the row and everything
configured on it. Tokens from that issuer are refused on the very next request.

This is the operator's fastest lever when a customer's authorization server is compromised: one call, immediate, and reversible without retyping the declaration. The bindings that name the issuer are left in place, so re-enabling restores exactly the access that was suspended rather than a re-derived approximation of it.

Idempotent, for the same reason as its counterpart.

Not entitlement-gated. The operator is the party that sells the edition, so

refusing them on it would be the platform refusing itself. The tenant's own verdict is
readable at ../workload-identity/entitlement (SR-10.6).

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Path Params
uuid
required
uuid
required
Headers
string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
Credentials
Bearer
JWT
URL
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json