Skip to main content
POST
/
api
/
v1
/
logout
Log out
curl --request POST \
  --url https://staging.zerolatencylabs.com/api/v1/logout \
  --header 'Content-Type: application/json' \
  --header 'X-DEVICE-KEY: <api-key>' \
  --data '
{
  "payload": "AQABAAAAAAB4m2tQz9KvX1Yk2mN3oQ4rS5tU6vW7xZ8aB9cD0eF1gH2iJ3kL5mN7oP9qR1sT3uV5wX7yZ9a=",
  "public_key": "AAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwdHh8=",
  "signature": "AAcOFRwjKjE4P0ZNVFtiaXB3foWMk5qhqK+2vcTL0tng5+71/AMKERgfJi00O0JJUFdeZWxzeoGIj5adpKuyuQ=="
}
'
{
  "device_key_deleted": false,
  "session_revoked": true
}

Authorizations

X-DEVICE-KEY
string
header
required

Base64-encoded device-key secret issued by POST /api/v1/login.

Body

application/json

Signed write request. The JSON body is a Base64SignedPayload; its base64 payload decodes to the binary layout [Header(8) || RequestId(16) || Body || Auth] the client signs — see spec/signing.md for the byte layout, signature types, and signing procedure. The decoded Body is:

  • RevokeSession when Header.request_type = revoke_session (14).

JSON envelope for a signed request: the base64-encoded canonical payload plus the base64 signature and public_key of the signing credential. Session-key (Ed25519) endpoints accept exactly these fields; master-key (Secp256k1 / Passkey) endpoints sign the same payload and may carry additional signature material. Endpoints also accept the equivalent application/octet-stream binary frame.

payload
string
required

Base64-encoded bytes of the canonical request payload.

Example:

"AQABAAAAAAB4m2tQz9KvX1Yk2mN3oQ4rS5tU6vW7xZ8aB9cD0eF1gH2iJ3kL5mN7oP9qR1sT3uV5wX7yZ9a="

public_key
string
required

Base64-encoded public key of the signing credential.

Example:

"AAECAwQFBgcICQoLDA0ODxAREhMUFRYXGBkaGxwdHh8="

signature
string
required

Base64-encoded signature over the payload.

Example:

"AAcOFRwjKjE4P0ZNVFtiaXB3foWMk5qhqK+2vcTL0tng5+71/AMKERgfJi00O0JJUFdeZWxzeoGIj5adpKuyuQ=="

Response

Logout processed; see session_revoked / device_key_deleted

device_key_deleted
boolean
required

Whether a device key was deleted (false if none was presented or it was already gone).

Example:

false

session_revoked
boolean
required

Whether the exchange revoked the session key.

Example:

true