Revoke one own refresh session
Stops future refresh for this family only. Already issued access JWTs remain valid until their configured expiry; this is not immediate access-token invalidation. Only the authenticated active membership's family in this tenant can be changed.
bearerAuthAuthorizationBearer <token>Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.
familyId*stringOwn refresh-family identifier
uuidRefresh family revoked and audited atomically
curl -X DELETE 'https://api.monetaryai.uz/api/v1/me/sessions/497f6eca-6276-4993-bfeb-53cbbbba6f08'Revoke all own active refresh sessions DELETE
Revokes this active membership's currently visible live refresh families in this tenant. Concurrent or later new logins are not prevented. Already issued access JWTs retain their configured expiry. Other memberships and tenants are untouched; repeated requests do not duplicate audit events.
Get the current authenticated user GET
Returns identity, membership, tenant, and role claims after signature and host-to-tenant validation.