curl --request POST \
--url https://mcp.echozero.app/api/auth/sign-out \
--header 'Content-Type: application/json' \
--header 'x-signature: <x-signature>' \
--header 'x-timestamp: <x-timestamp>' \
--data '
{
"refreshToken": "550e8400-e29b-41d4-a716-446655440000"
}
'{
"success": true,
"data": {
"success": true
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}Auth
Revoke a refresh token
Marks the session associated with the provided refresh token inactive. Safe to call multiple times — always returns { success: true } once the backend has processed the request.
POST
/
api
/
auth
/
sign-out
curl --request POST \
--url https://mcp.echozero.app/api/auth/sign-out \
--header 'Content-Type: application/json' \
--header 'x-signature: <x-signature>' \
--header 'x-timestamp: <x-timestamp>' \
--data '
{
"refreshToken": "550e8400-e29b-41d4-a716-446655440000"
}
'{
"success": true,
"data": {
"success": true
}
}{
"success": false,
"error": {
"code": "NOT_FOUND",
"message": "Resource not found"
}
}Headers
Required for API-key authenticated requests. HMAC-SHA256(secretKey, timestamp + METHOD + path + body) as lowercase hex. Omit only for JWT/OAuth session tokens or public routes.
Required with x-signature. Epoch milliseconds; rejected if drift exceeds 5 minutes. Omit only for JWT/OAuth session tokens or public routes.
Body
application/json
OpenAPI schema McpSignOutBodyDto.
Refresh token of the session to be revoked.
Example:
"550e8400-e29b-41d4-a716-446655440000"