# Revoking offline token as the client

**URL:** <https://forum.keycloak.org/t/revoking-offline-token-as-the-client/9161>\
**Category:** Getting advice\
**Created:** [May 20, 2021, 3:19pm UTC](https://forum.keycloak.org/t/revoking-offline-token-as-the-client/9161 "2021-05-20T15:19:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![DrDizzle](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/drdizzle/32/242_2.png) [@DrDizzle](https://forum.keycloak.org/u/DrDizzle)\
**Post date:** [May 20, 2021, 3:19pm UTC](https://forum.keycloak.org/t/revoking-offline-token-as-the-client/9161/1 "2021-05-20T15:19:46Z")

</div>

#### Scenario
I know that active offline tokens can be revoked by either the user - trough the Account API, or the Admin - through the Admin REST API. What I would like to do, is to enable the client to revoke it's own active offline tokens. Assuming I have checked "Revoke Refresh Token", a particular offline token could be revoked when getting a new one. The problem is that I'm still getting an active new one. Also, a timeout-based approach won't really work in this scenario.
#### Question
Is there an existing way to achieve this, or will I have to create a custom endpoint?

---

<div class="post-metadata">

**Author:** ![DrDizzle](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/drdizzle/32/242_2.png) [@DrDizzle](https://forum.keycloak.org/u/DrDizzle)\
**Post date:** [May 21, 2021, 8:33am UTC](https://forum.keycloak.org/t/revoking-offline-token-as-the-client/9161/2 "2021-05-21T08:33:56Z")

</div>

Nevermind.  
Keycloak has a regular [OAuth 2.0 Token Revocation](https://datatracker.ietf.org/doc/html/rfc7009) Endpoint.  
[https://www.keycloak.org/docs/latest/securing\_apps/#\_token\_revocation\_endpoint](https://www.keycloak.org/docs/latest/securing_apps/#_token_revocation_endpoint)

A good nights sleep does wonders sometimes…
