Item

itemAccessTokenInvalidate

POST
/item/access_token/invalidate

By default, the access_token associated with an Item does not expire and should be stored in a persistent, secure manner.

You can use the /item/access_token/invalidate endpoint to rotate the access_token associated with an Item. The endpoint returns a new access_token and immediately invalidates the previous access_token.

Authorization

PLAID-CLIENT-ID PLAID-SECRET Plaid-Version
PLAID-CLIENT-ID<token>

In: header

PLAID-SECRET<token>

In: header

Plaid-Version<token>

In: header

Request Body

application/json

ItemAccessTokenInvalidateRequest defines the request schema for /item/access_token/invalidate

client_id?string

Your Plaid API client_id. The client_id is required and may be provided either in the PLAID-CLIENT-ID header or as part of a request body.

secret?string

Your Plaid API secret. The secret is required and may be provided either in the PLAID-SECRET header or as part of a request body.

access_token*string

The access token associated with the Item data is being requested for.

Response Body

application/json

curl -X POST "https://example.com/item/access_token/invalidate" \  -H "Content-Type: application/json" \  -d '{    "access_token": "string"  }'
{  "new_access_token": "access-sandbox-8ab976e6-64bc-4b38-98f7-731e7a349970",  "request_id": "m8MDnv9okwxFNBV"}