# Revoke Session

`DELETE /api/sdk/session`

End an agent's embedded phone session. Call this from **your backend** when one of your users logs out or you need to cut off access.

Requires a Bearer API token and the **call-center** permission (same as [Mint SDK Token](/api-docs/sdk/token)).

After this, that agent cannot keep using the previous browser session. Unused tokens for that agent also stop working. A call that is already connected is not hung up. You can still create a new token for the same agent later.

## Request Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| agent_id | integer | Yes | Numeric id of a call-center agent that belongs to your account. Get ids from [List Agents](/api-docs/call-center/agents). |

## Request Example

```bash
curl -X DELETE https://api.awajdigital.com/api/sdk/session \
  -H "Authorization: Bearer your_api_token_here" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{
    "agent_id": 42
  }'
```

```javascript
// Call this from your server, not from the embed page.
const response = await fetch('https://api.awajdigital.com/api/sdk/session', {
  method: 'DELETE',
  headers: {
    'Authorization': 'Bearer your_api_token_here',
    'Accept': 'application/json',
    'Content-Type': 'application/json'
  },
  body: JSON.stringify({
    agent_id: 42
  })
});

const data = await response.json();
console.log(data);
```

```javascript
// Node.js with axios
const axios = require('axios');

async function revokeSdkSession(agentId) {
  try {
    const response = await axios.delete('https://api.awajdigital.com/api/sdk/session', {
      data: { agent_id: agentId },
      headers: {
        'Authorization': 'Bearer your_api_token_here',
        'Accept': 'application/json',
        'Content-Type': 'application/json'
      }
    });

    console.log(response.data);
  } catch (error) {
    console.error('Error:', error.response?.data || error.message);
  }
}

revokeSdkSession(42);
```

```python
# Python with requests
import requests

def revoke_sdk_session(agent_id):
    url = 'https://api.awajdigital.com/api/sdk/session'
    headers = {
        'Authorization': 'Bearer your_api_token_here',
        'Accept': 'application/json',
        'Content-Type': 'application/json'
    }
    data = {
        'agent_id': agent_id
    }

    try:
        response = requests.delete(url, json=data, headers=headers)
        print(response.json())
    except requests.exceptions.RequestException as e:
        print(f'Error: {e}')

revoke_sdk_session(42)
```

```php
<?php
// PHP with cURL
$url = 'https://api.awajdigital.com/api/sdk/session';
$token = 'your_api_token_here';

$data = [
    'agent_id' => 42
];

$ch = curl_init($url);
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, 'DELETE');
curl_setopt($ch, CURLOPT_POSTFIELDS, json_encode($data));
curl_setopt($ch, CURLOPT_HTTPHEADER, [
    'Authorization: Bearer ' . $token,
    'Accept: application/json',
    'Content-Type: application/json'
]);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);

$response = curl_exec($ch);
curl_close($ch);

$result = json_decode($response, true);
print_r($result);
?>
```

## Success Response Example

```json
{
  "revoked": true
}
```

A later [Mint SDK Token](/api-docs/sdk/token) for the same agent still works — this ends the current session; it does not disable the agent.

## Error Responses

| Status | Code | Description |
| --- | --- | --- |
| 401 | — | Missing or invalid access token |
| 403 | — | Account does not have the call-center permission |
| 404 | `agent_not_found` | Agent does not exist or belongs to another account |
| 422 | — | Validation failed (`agent_id` missing or not a positive integer) |
| 429 | — | Too many requests |

```json
{
  "error": "agent not found",
  "code": "agent_not_found"
}
```