curl --request POST \
--url https://api.orbit.devotel.io/api/v1/agents/agent-authorization-mandate/revoke \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"mandate": {
"id": "<string>",
"agentId": "<string>",
"principalId": "<string>",
"allowedActions": [
"<string>"
],
"allowedTools": [
"<string>"
],
"allowedDataCategories": [
"<string>"
],
"maxInvocations": 123,
"invocationCount": 123,
"consentDigest": "<string>",
"expiresAt": 123,
"createdAt": 123,
"updatedAt": 123,
"revokedAt": 123,
"parentMandateId": "<string>",
"parentDigest": "<string>"
}
}
'import requests
url = "https://api.orbit.devotel.io/api/v1/agents/agent-authorization-mandate/revoke"
payload = { "mandate": {
"id": "<string>",
"agentId": "<string>",
"principalId": "<string>",
"allowedActions": ["<string>"],
"allowedTools": ["<string>"],
"allowedDataCategories": ["<string>"],
"maxInvocations": 123,
"invocationCount": 123,
"consentDigest": "<string>",
"expiresAt": 123,
"createdAt": 123,
"updatedAt": 123,
"revokedAt": 123,
"parentMandateId": "<string>",
"parentDigest": "<string>"
} }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
mandate: {
id: '<string>',
agentId: '<string>',
principalId: '<string>',
allowedActions: ['<string>'],
allowedTools: ['<string>'],
allowedDataCategories: ['<string>'],
maxInvocations: 123,
invocationCount: 123,
consentDigest: '<string>',
expiresAt: 123,
createdAt: 123,
updatedAt: 123,
revokedAt: 123,
parentMandateId: '<string>',
parentDigest: '<string>'
}
})
};
fetch('https://api.orbit.devotel.io/api/v1/agents/agent-authorization-mandate/revoke', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.orbit.devotel.io/api/v1/agents/agent-authorization-mandate/revoke",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'mandate' => [
'id' => '<string>',
'agentId' => '<string>',
'principalId' => '<string>',
'allowedActions' => [
'<string>'
],
'allowedTools' => [
'<string>'
],
'allowedDataCategories' => [
'<string>'
],
'maxInvocations' => 123,
'invocationCount' => 123,
'consentDigest' => '<string>',
'expiresAt' => 123,
'createdAt' => 123,
'updatedAt' => 123,
'revokedAt' => 123,
'parentMandateId' => '<string>',
'parentDigest' => '<string>'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.orbit.devotel.io/api/v1/agents/agent-authorization-mandate/revoke"
payload := strings.NewReader("{\n \"mandate\": {\n \"id\": \"<string>\",\n \"agentId\": \"<string>\",\n \"principalId\": \"<string>\",\n \"allowedActions\": [\n \"<string>\"\n ],\n \"allowedTools\": [\n \"<string>\"\n ],\n \"allowedDataCategories\": [\n \"<string>\"\n ],\n \"maxInvocations\": 123,\n \"invocationCount\": 123,\n \"consentDigest\": \"<string>\",\n \"expiresAt\": 123,\n \"createdAt\": 123,\n \"updatedAt\": 123,\n \"revokedAt\": 123,\n \"parentMandateId\": \"<string>\",\n \"parentDigest\": \"<string>\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.orbit.devotel.io/api/v1/agents/agent-authorization-mandate/revoke")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"mandate\": {\n \"id\": \"<string>\",\n \"agentId\": \"<string>\",\n \"principalId\": \"<string>\",\n \"allowedActions\": [\n \"<string>\"\n ],\n \"allowedTools\": [\n \"<string>\"\n ],\n \"allowedDataCategories\": [\n \"<string>\"\n ],\n \"maxInvocations\": 123,\n \"invocationCount\": 123,\n \"consentDigest\": \"<string>\",\n \"expiresAt\": 123,\n \"createdAt\": 123,\n \"updatedAt\": 123,\n \"revokedAt\": 123,\n \"parentMandateId\": \"<string>\",\n \"parentDigest\": \"<string>\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.orbit.devotel.io/api/v1/agents/agent-authorization-mandate/revoke")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"mandate\": {\n \"id\": \"<string>\",\n \"agentId\": \"<string>\",\n \"principalId\": \"<string>\",\n \"allowedActions\": [\n \"<string>\"\n ],\n \"allowedTools\": [\n \"<string>\"\n ],\n \"allowedDataCategories\": [\n \"<string>\"\n ],\n \"maxInvocations\": 123,\n \"invocationCount\": 123,\n \"consentDigest\": \"<string>\",\n \"expiresAt\": 123,\n \"createdAt\": 123,\n \"updatedAt\": 123,\n \"revokedAt\": 123,\n \"parentMandateId\": \"<string>\",\n \"parentDigest\": \"<string>\"\n }\n}"
response = http.request(request)
puts response.read_body{
"data": {
"id": "<string>",
"agentId": "<string>",
"principalId": "<string>",
"allowedActions": [
"<string>"
],
"allowedTools": [
"<string>"
],
"allowedDataCategories": [
"<string>"
],
"maxInvocations": 123,
"invocationCount": 123,
"status": "active",
"consentDigest": "<string>",
"expiresAt": 123,
"createdAt": 123,
"updatedAt": 123,
"revokedAt": 123,
"parentMandateId": "<string>",
"parentDigest": "<string>"
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}Revoke an agent authorization mandate
Withdraw consent, moving the mandate to the terminal revoked status so no further action is authorized under it (and, via the chain endpoints, none under any mandate delegated from it). Returns the revoked mandate snapshot. Re-revoking an already-revoked mandate is a VALIDATION_ERROR. Requires the agents:write scope and an owner, admin, or developer role. Audit-logged.
curl --request POST \
--url https://api.orbit.devotel.io/api/v1/agents/agent-authorization-mandate/revoke \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"mandate": {
"id": "<string>",
"agentId": "<string>",
"principalId": "<string>",
"allowedActions": [
"<string>"
],
"allowedTools": [
"<string>"
],
"allowedDataCategories": [
"<string>"
],
"maxInvocations": 123,
"invocationCount": 123,
"consentDigest": "<string>",
"expiresAt": 123,
"createdAt": 123,
"updatedAt": 123,
"revokedAt": 123,
"parentMandateId": "<string>",
"parentDigest": "<string>"
}
}
'import requests
url = "https://api.orbit.devotel.io/api/v1/agents/agent-authorization-mandate/revoke"
payload = { "mandate": {
"id": "<string>",
"agentId": "<string>",
"principalId": "<string>",
"allowedActions": ["<string>"],
"allowedTools": ["<string>"],
"allowedDataCategories": ["<string>"],
"maxInvocations": 123,
"invocationCount": 123,
"consentDigest": "<string>",
"expiresAt": 123,
"createdAt": 123,
"updatedAt": 123,
"revokedAt": 123,
"parentMandateId": "<string>",
"parentDigest": "<string>"
} }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
mandate: {
id: '<string>',
agentId: '<string>',
principalId: '<string>',
allowedActions: ['<string>'],
allowedTools: ['<string>'],
allowedDataCategories: ['<string>'],
maxInvocations: 123,
invocationCount: 123,
consentDigest: '<string>',
expiresAt: 123,
createdAt: 123,
updatedAt: 123,
revokedAt: 123,
parentMandateId: '<string>',
parentDigest: '<string>'
}
})
};
fetch('https://api.orbit.devotel.io/api/v1/agents/agent-authorization-mandate/revoke', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.orbit.devotel.io/api/v1/agents/agent-authorization-mandate/revoke",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'mandate' => [
'id' => '<string>',
'agentId' => '<string>',
'principalId' => '<string>',
'allowedActions' => [
'<string>'
],
'allowedTools' => [
'<string>'
],
'allowedDataCategories' => [
'<string>'
],
'maxInvocations' => 123,
'invocationCount' => 123,
'consentDigest' => '<string>',
'expiresAt' => 123,
'createdAt' => 123,
'updatedAt' => 123,
'revokedAt' => 123,
'parentMandateId' => '<string>',
'parentDigest' => '<string>'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.orbit.devotel.io/api/v1/agents/agent-authorization-mandate/revoke"
payload := strings.NewReader("{\n \"mandate\": {\n \"id\": \"<string>\",\n \"agentId\": \"<string>\",\n \"principalId\": \"<string>\",\n \"allowedActions\": [\n \"<string>\"\n ],\n \"allowedTools\": [\n \"<string>\"\n ],\n \"allowedDataCategories\": [\n \"<string>\"\n ],\n \"maxInvocations\": 123,\n \"invocationCount\": 123,\n \"consentDigest\": \"<string>\",\n \"expiresAt\": 123,\n \"createdAt\": 123,\n \"updatedAt\": 123,\n \"revokedAt\": 123,\n \"parentMandateId\": \"<string>\",\n \"parentDigest\": \"<string>\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.orbit.devotel.io/api/v1/agents/agent-authorization-mandate/revoke")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"mandate\": {\n \"id\": \"<string>\",\n \"agentId\": \"<string>\",\n \"principalId\": \"<string>\",\n \"allowedActions\": [\n \"<string>\"\n ],\n \"allowedTools\": [\n \"<string>\"\n ],\n \"allowedDataCategories\": [\n \"<string>\"\n ],\n \"maxInvocations\": 123,\n \"invocationCount\": 123,\n \"consentDigest\": \"<string>\",\n \"expiresAt\": 123,\n \"createdAt\": 123,\n \"updatedAt\": 123,\n \"revokedAt\": 123,\n \"parentMandateId\": \"<string>\",\n \"parentDigest\": \"<string>\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.orbit.devotel.io/api/v1/agents/agent-authorization-mandate/revoke")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"mandate\": {\n \"id\": \"<string>\",\n \"agentId\": \"<string>\",\n \"principalId\": \"<string>\",\n \"allowedActions\": [\n \"<string>\"\n ],\n \"allowedTools\": [\n \"<string>\"\n ],\n \"allowedDataCategories\": [\n \"<string>\"\n ],\n \"maxInvocations\": 123,\n \"invocationCount\": 123,\n \"consentDigest\": \"<string>\",\n \"expiresAt\": 123,\n \"createdAt\": 123,\n \"updatedAt\": 123,\n \"revokedAt\": 123,\n \"parentMandateId\": \"<string>\",\n \"parentDigest\": \"<string>\"\n }\n}"
response = http.request(request)
puts response.read_body{
"data": {
"id": "<string>",
"agentId": "<string>",
"principalId": "<string>",
"allowedActions": [
"<string>"
],
"allowedTools": [
"<string>"
],
"allowedDataCategories": [
"<string>"
],
"maxInvocations": 123,
"invocationCount": 123,
"status": "active",
"consentDigest": "<string>",
"expiresAt": 123,
"createdAt": 123,
"updatedAt": 123,
"revokedAt": 123,
"parentMandateId": "<string>",
"parentDigest": "<string>"
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>",
"status": 123,
"details": {}
},
"meta": {
"request_id": "<string>",
"timestamp": "2023-11-07T05:31:56Z",
"docs_url": "<string>"
}
}Authorizations
Dashboard JWT token from Clerk
Body
A scoped, revocable, action-capped authorization an AI agent acts under — a serializable snapshot the caller stores and round-trips in each request body. The scope fields (principal, agent, allowlists, invocation cap, expiry, ancestry) are immutable after issue and bound by consentDigest; only status, invocationCount, updatedAt, and revokedAt advance over the mandate's life. A delegated (child) mandate additionally carries a parentMandateId + parentDigest pointer to the parent it was attenuated from.
Show child attributes
Show child attributes
Response
The revoked mandate snapshot.
A scoped, revocable, action-capped authorization an AI agent acts under — a serializable snapshot the caller stores and round-trips in each request body. The scope fields (principal, agent, allowlists, invocation cap, expiry, ancestry) are immutable after issue and bound by consentDigest; only status, invocationCount, updatedAt, and revokedAt advance over the mandate's life. A delegated (child) mandate additionally carries a parentMandateId + parentDigest pointer to the parent it was attenuated from.
Show child attributes
Show child attributes
Show child attributes
Show child attributes