> ## Documentation Index
> Fetch the complete documentation index at: https://conductorone-leet-slack-mcp-docs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Revoke

> Revoke allows admin to revoke any secret (not just their own).



## OpenAPI

````yaml https://spec.speakeasy.com/conductor-one/conductorone/my-source-with-code-samples delete /api/v1/secrets-admin/{vault_id}
openapi: 3.1.0
info:
  description: The C1 API is a HTTP API for managing C1 resources.
  title: C1 API
  version: 0.1.0-alpha
servers:
  - description: The C1 API server for the current tenant.
    url: https://{tenantDomain}.conductor.one
    variables:
      tenantDomain:
        default: example
        description: The domain of the tenant to use for this request.
security:
  - bearerAuth: []
    oauth: []
paths:
  /api/v1/secrets-admin/{vault_id}:
    delete:
      tags:
        - Secrets Admin
      summary: Revoke
      description: Revoke allows admin to revoke any secret (not just their own).
      operationId: c1.api.secrets.v1.PaperSecretAdminService.Revoke
      parameters:
        - in: path
          name: vault_id
          required: true
          schema:
            description: The vaultId field.
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: >-
                #/components/schemas/c1.api.secrets.v1.PaperSecretAdminServiceRevokeRequestInput
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/c1.api.secrets.v1.PaperSecretAdminServiceRevokeResponse
          description: Successful response
      x-codeSamples:
        - lang: go
          label: Revoke
          source: "package main\n\nimport(\n\t\"context\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/shared\"\n\tconductoronesdkgo \"github.com/conductorone/conductorone-sdk-go\"\n\t\"github.com/conductorone/conductorone-sdk-go/pkg/models/operations\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := conductoronesdkgo.New(\n        conductoronesdkgo.WithSecurity(shared.Security{\n            BearerAuth: \"<YOUR_BEARER_TOKEN_HERE>\",\n            Oauth: \"<YOUR_OAUTH_HERE>\",\n        }),\n    )\n\n    res, err := s.PaperSecretAdmin.Revoke(ctx, operations.C1APISecretsV1PaperSecretAdminServiceRevokeRequest{\n        VaultID: \"<id>\",\n    })\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.PaperSecretAdminServiceRevokeResponse != nil {\n        // handle response\n    }\n}"
        - lang: typescript
          label: Typescript (SDK)
          source: >-
            import { ConductoroneSDKTypescript } from
            "conductorone-sdk-typescript";


            const conductoroneSDKTypescript = new ConductoroneSDKTypescript({
              security: {
                bearerAuth: "<YOUR_BEARER_TOKEN_HERE>",
                oauth: "<YOUR_OAUTH_HERE>",
              },
            });


            async function run() {
              const result = await conductoroneSDKTypescript.paperSecretAdmin.revoke({
                vaultId: "<id>",
              });

              console.log(result);
            }


            run();
components:
  schemas:
    c1.api.secrets.v1.PaperSecretAdminServiceRevokeRequestInput:
      description: The PaperSecretAdminServiceRevokeRequest message.
      title: Paper Secret Admin Service Revoke Request
      type: object
      x-speakeasy-name-override: PaperSecretAdminServiceRevokeRequest
    c1.api.secrets.v1.PaperSecretAdminServiceRevokeResponse:
      description: The PaperSecretAdminServiceRevokeResponse message.
      properties:
        secret:
          oneOf:
            - $ref: '#/components/schemas/c1.api.secrets.v1.PaperSecret'
            - type: 'null'
      title: Paper Secret Admin Service Revoke Response
      type: object
      x-speakeasy-name-override: PaperSecretAdminServiceRevokeResponse
    c1.api.secrets.v1.PaperSecret:
      description: >-
        PaperSecret is the API view of a secret (combines Vault + PaperVault
        fields).
         The vault_id is the primary identifier (Vault.id).
      properties:
        ageSuite:
          description: Exact Age suite used by the stored ciphertext.
          enum:
            - AGE_SUITE_UNSPECIFIED
            - AGE_SUITE_X25519
            - AGE_SUITE_MLKEM768X25519
          type: string
          x-speakeasy-unknown-values: allow
        allowedEmails:
          description: The allowedEmails field.
          items:
            type: string
          type:
            - array
            - 'null'
        allowedUserIds:
          description: Access control
          items:
            type: string
          type:
            - array
            - 'null'
        contentDeleted:
          description: The contentDeleted field.
          type: boolean
        contentExpiresAt:
          format: date-time
          type:
            - string
            - 'null'
        contentReady:
          description: Whether content has been set (text uploaded or file uploaded)
          type: boolean
        contentType:
          description: The contentType field.
          type: string
        createdAt:
          format: date-time
          readOnly: true
          type:
            - string
            - 'null'
        creatorUserId:
          description: Creator
          type: string
        currentViews:
          description: The currentViews field.
          format: uint32
          type: integer
        deletedAt:
          format: date-time
          readOnly: true
          type:
            - string
            - 'null'
        displayName:
          description: From Vault
          type: string
        fileSize:
          description: File metadata
          format: int64
          type: string
        filename:
          description: 'For FILE secrets: original filename (sanitized)'
          type: string
        inputFormat:
          description: The inputFormat field.
          enum:
            - SECRET_INPUT_FORMAT_UNSPECIFIED
            - SECRET_INPUT_FORMAT_PLAINTEXT
            - SECRET_INPUT_FORMAT_JSON
            - SECRET_INPUT_FORMAT_YAML
            - SECRET_INPUT_FORMAT_KEY_VALUE
          type: string
          x-speakeasy-unknown-values: allow
        maxViews:
          description: View tracking
          format: uint32
          type: integer
        secretType:
          description: The secretType field.
          enum:
            - SECRET_TYPE_UNSPECIFIED
            - SECRET_TYPE_TEXT
            - SECRET_TYPE_FILE
          type: string
          x-speakeasy-unknown-values: allow
        shareCode:
          description: Human-friendly share code (XXXX-XXXX-XXXX) for shareable URLs
          type: string
        shareUrl:
          description: URL to share with recipients (populated when content_ready is true)
          type: string
        sharingMode:
          description: From PaperVault
          enum:
            - PAPER_VAULT_SHARING_MODE_UNSPECIFIED
            - PAPER_VAULT_SHARING_MODE_INTERNAL
            - PAPER_VAULT_SHARING_MODE_EXTERNAL
          type: string
          x-speakeasy-unknown-values: allow
        status:
          description: Computed status
          enum:
            - SECRET_STATUS_UNSPECIFIED
            - SECRET_STATUS_ACTIVE
            - SECRET_STATUS_EXPIRED
            - SECRET_STATUS_BURNED
            - SECRET_STATUS_REVOKED
            - SECRET_STATUS_DATA_DELETED
          type: string
          x-speakeasy-unknown-values: allow
        updatedAt:
          format: date-time
          readOnly: true
          type:
            - string
            - 'null'
        vaultId:
          description: Vault.id - primary identifier for the secret
          type: string
      title: Paper Secret
      type: object
      x-speakeasy-name-override: PaperSecret
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    oauth:
      description: >-
        This API uses OAuth2 with the Client Credential flow.

        Client Credentials must be sent in the BODY, not the headers.

        For an example of how to implement this, refer to the
        [c1TokenSource.Token()](https://github.com/ConductorOne/conductorone-sdk-go/blob/3375fe7c0126d17e7ec4e711693dee7b791023aa/token_source.go#L101-L187)
        function.
      flows:
        clientCredentials:
          scopes: {}
          tokenUrl: /auth/v1/token
      type: oauth2

````