Cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Revoke endpoint revokes access independently of an Authorization header being present or not.

Hello,

I recently noticed the TITLE, I don't know if I'm doing something wrong.

I've tried several scenarios where I request access is revoked and I send literally random strings in the Authorization header, even tried without Authorization header (only header "Content-type": "application/x-www-form-urlencoded" and, as a parameter, the token to be revoked) and it still revokes access.

 

Any insights or ideas are welcome.

 

Thanks

 

@Gordon-C 

Best Answer
0 Votes
1 REPLY 1

Hi @kazy28 

 

I moved your question to the Web API section of the forums.   

 

Would you please provide an example of what syntax you're sending, along with the headers.   It'll be easier to provide advice.

Gordon Crenshaw
Senior Technical Solutions Consultant
Fitbit Partner Engineering & Web API Support | Google
Best Answer
0 Votes