Skip to content
getgeolens.com

Logout

POST
/auth/logout/
curl --request POST \
--url https://example.com/auth/logout/ \
--header 'Content-Type: application/json' \
--data '{ "refresh_token": "example" }'

Revoke all refresh tokens and bump token_version for the current user.

SEC-S15 (Phase 1062-01): revoke_all_tokens bumps User.token_version so the access JWT used for this logout call (and any other outstanding access JWTs) are rejected on the next authenticated request — closing the “logout doesn’t invalidate the access JWT” gap.

fix(#821): logout deliberately does NOT bump key_epoch — API keys exist to outlive browser sessions (CI, MCP servers, tile URLs), so session hygiene must not revoke them. Security events (password change, role change) do.

fix(#1446): the refresh COOKIE can authenticate this call when the access token has aged out. Requiring a live bearer token meant a user returning after their 15-minute access token expired got a 401 here while their multi-day refresh cookie stayed valid — the UI reported a clean logout and the session survived it. CSRF is enforced on that path exactly as it is for /auth/refresh, since the cookie is then the credential.

X-CSRF-Token
Any of:
string

Double-submit CSRF token, enforced only when the refresh cookie is what authenticates the call. Echo the value of the geolens_csrf cookie issued alongside the refresh cookie. Callers presenting a refresh token in the request body do not send it.

Media type application/json
Any of:
RefreshRequest
object
refresh_token
required
Refresh Token
string
<= 512 characters
Example generated
{
"refresh_token": "example"
}

Successful Response

Bad request — invalid query parameters or payload

Media type application/problem+json
ProblemDetail
object
type
Type
string
default: about:blank
title
required
Title
string
status
required
Status
integer
detail
required
Any of:
string
Example
{
"detail": "Dataset not found",
"status": 404,
"title": "Not Found",
"type": "about:blank"
}

Unauthorized — missing or invalid credentials

Media type application/problem+json
ProblemDetail
object
type
Type
string
default: about:blank
title
required
Title
string
status
required
Status
integer
detail
required
Any of:
string
Example
{
"detail": "Dataset not found",
"status": 404,
"title": "Not Found",
"type": "about:blank"
}

Forbidden — caller lacks access to this resource

Media type application/problem+json
ProblemDetail
object
type
Type
string
default: about:blank
title
required
Title
string
status
required
Status
integer
detail
required
Any of:
string
Example
{
"detail": "Dataset not found",
"status": 404,
"title": "Not Found",
"type": "about:blank"
}

Not found

Media type application/problem+json
ProblemDetail
object
type
Type
string
default: about:blank
title
required
Title
string
status
required
Status
integer
detail
required
Any of:
string
Example
{
"detail": "Dataset not found",
"status": 404,
"title": "Not Found",
"type": "about:blank"
}

Validation error

Media type application/problem+json
ProblemDetail
object
type
Type
string
default: about:blank
title
required
Title
string
status
required
Status
integer
detail
required
Any of:
string
Example
{
"detail": "Dataset not found",
"status": 404,
"title": "Not Found",
"type": "about:blank"
}

Too many requests — retry after the advertised interval

Media type application/problem+json
ProblemDetail
object
type
Type
string
default: about:blank
title
required
Title
string
status
required
Status
integer
detail
required
Any of:
string
Example
{
"detail": "Dataset not found",
"status": 404,
"title": "Not Found",
"type": "about:blank"
}
Retry-After
integer

Seconds until the request may be retried

Internal server error

Media type application/problem+json
ProblemDetail
object
type
Type
string
default: about:blank
title
required
Title
string
status
required
Status
integer
detail
required
Any of:
string
Example
{
"detail": "Dataset not found",
"status": 404,
"title": "Not Found",
"type": "about:blank"
}

Service unavailable — the database could not serve the request

Media type application/problem+json
ProblemDetail
object
type
Type
string
default: about:blank
title
required
Title
string
status
required
Status
integer
detail
required
Any of:
string
Example
{
"detail": "Dataset not found",
"status": 404,
"title": "Not Found",
"type": "about:blank"
}