- Tokens
- Delete Secret Phrase
Tokens
Delete Secret Phrase
Remove secret phrases to invalidate associated bearer tokens
curl --request POST \
--url https://sandbox.masonhub.co/dragonfly-cosmetics-demo/api/v1/delete_secrets \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{
"secret_phrase": "<string>"
}'Remove secret phrases from your account, permanently invalidating all bearer tokens generated with that phrase. This is useful for token rotation and security management.
Deleting a secret phrase invalidates all tokens generated with that phrase. This action cannot be undone.
The secret phrase must match exactly as it was entered during token creation, including capitalization, spacing, and punctuation.
Request Body
The exact secret phrase used to generate the token(s) you want to invalidate. Must match character-for-character with the original phrase.
curl -X POST "https://app.masonhub.co/{account}/api/v1/delete_secrets" \
-H "Content-Type: application/json" \
-d '{
"secret_phrase": "Enter secret phrase exactly as entered during creation process"
}'
{
"success": true,
"message": "Secret phrase deleted successfully. All associated tokens have been invalidated."
}
When to Delete Secret Phrases
Token Rotation Workflow
Safely rotate tokens to maintain security:
Generate New Token
Create a new bearer token with a different secret phrase using Generate New Bearer Token
Update Applications
Deploy the new token to all applications and services
Test Thoroughly
Verify all integrations work correctly with the new token
Monitor for Issues
Watch for authentication errors after deployment
Delete Old Phrase
Once confirmed working, delete the old secret phrase to invalidate the previous token
Important Considerations
Before Deleting:
- Ensure you have a new working token in place
- Update all applications using the old token
- Test that the new token works correctly
- Document which systems were updated
Immediate Effects
When you delete a secret phrase:
- All tokens generated with that phrase are immediately invalidated
- Any API requests using those tokens will return 401 Unauthorized
- The deletion cannot be reversed
- You’ll need to generate a new token to regain access
Best Practices
Graceful Rotation
Plan token rotation during maintenance windows to minimize disruption
Document Changes
Keep records of when tokens were rotated and which systems were updated
Test First
Always test the new token thoroughly before deleting the old secret phrase
Monitor Access
Watch for authentication failures after deletion to catch missed updates
Emergency Token Revocation
If a token is compromised:
Act Immediately
Delete the secret phrase as soon as you detect a security issue
Generate New Token
Create a new token with a completely different secret phrase
Review Access Logs
Check API access logs for suspicious activity
Update Security
Review and strengthen your token storage and handling practices
Notify Stakeholders
Inform relevant team members about the security incident
Troubleshooting
For security-related issues or to report compromised tokens, contact support@masonhub.co immediately.
curl -X POST "https://app.masonhub.co/{account}/api/v1/delete_secrets" \
-H "Content-Type: application/json" \
-d '{
"secret_phrase": "Enter secret phrase exactly as entered during creation process"
}'
curl --request POST \
--url https://sandbox.masonhub.co/dragonfly-cosmetics-demo/api/v1/delete_secrets \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{
"secret_phrase": "<string>"
}'{
"success": true,
"message": "Secret phrase deleted successfully. All associated tokens have been invalidated."
}