> ## Documentation Index
> Fetch the complete documentation index at: https://phone-harness.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Revoke an API key

> Revoke a key belonging to this account using its key_hash from the key list, not the raw key. Revoking a key does not end sessions. The response is idempotent and does not prove the identifier existed.



## OpenAPI

````yaml /openapi.json post /me/keys/revoke
openapi: 3.1.0
info:
  title: Phone Harness API
  version: '2026-09-14'
  description: >-
    Public account and disposable Android session API. Open beta. Create
    responses are asynchronous; session duration includes provisioning, while
    billing begins at readiness. This specification documents the current
    supported client contract, not internal management interfaces. All example
    IDs, links, timestamps, limits, prices and digests are illustrative, not
    live credentials, measurements, or account entitlements.
  contact:
    name: Phone Harness support
    email: support@phone-harness.com
servers:
  - url: https://api.phone-harness.com
    description: Production beta
security:
  - ApiKey: []
tags:
  - name: Sessions
  - name: Phone
  - name: ADB
  - name: Account
  - name: History
  - name: Service
paths:
  /me/keys/revoke:
    post:
      tags:
        - Account
      summary: Revoke an API key
      description: >-
        Revoke a key belonging to this account using its key_hash from the key
        list, not the raw key. Revoking a key does not end sessions. The
        response is idempotent and does not prove the identifier existed.
      operationId: revoke-api-key
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                key_hash:
                  type: string
                  description: Identifier from GET /me/keys.
                  pattern: ^[a-f0-9]{64}$
              required:
                - key_hash
      responses:
        '200':
          description: Revocation request processed.
          content:
            application/json:
              schema:
                type: object
                properties:
                  revoked:
                    type: boolean
                    const: true
                required:
                  - revoked
        '400':
          description: Invalid request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Bad or missing bearer credential.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: Account access denied or rental access unavailable.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Unexpected service error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    Error:
      type: object
      properties:
        error:
          type: string
          description: Human-readable public error.
        code:
          type: string
          description: Present only for errors with a stable code.
        state:
          type: string
        unsupported:
          type: boolean
        outcome:
          type: string
          enum:
            - unknown
            - installed
        id:
          type: string
          description: Session ID if a create receipt exists.
        request_key:
          type: string
        cleanup_complete:
          type: boolean
        balance_cents:
          type: integer
        session:
          type: string
        session_limit:
          type: integer
        active_session_count:
          type: integer
        available_session_slots:
          type: integer
      required:
        - error
  securitySchemes:
    ApiKey:
      type: http
      scheme: bearer
      description: >-
        Phone Harness account API key (pck_…). The dashboard may use a Clerk
        session JWT with the same header. Never put an account key in a URL.

````