1. Tokens
  2. Delete Secret Phrase
POST
/delete_secrets
curl --request POST \
     --url https://sandbox.masonhub.co/dragonfly-cosmetics-demo/api/v1/delete_secrets \
     --header 'Authorization: Bearer <token>' \
     --header 'Content-Type: application/json' \
     --data '{
  "secret_phrase": "<string>"
}'

Remove secret phrases from your account, permanently invalidating all bearer tokens generated with that phrase. This is useful for token rotation and security management.

Deleting a secret phrase invalidates all tokens generated with that phrase. This action cannot be undone.

The secret phrase must match exactly as it was entered during token creation, including capitalization, spacing, and punctuation.

​
Request Body

secret_phrase
required
string

The exact secret phrase used to generate the token(s) you want to invalidate. Must match character-for-character with the original phrase.

curl -X POST "https://app.masonhub.co/{account}/api/v1/delete_secrets" \
  -H "Content-Type: application/json" \
  -d '{
    "secret_phrase": "Enter secret phrase exactly as entered during creation process"
  }'
{
  "success": true,
  "message": "Secret phrase deleted successfully. All associated tokens have been invalidated."
}

​
When to Delete Secret Phrases

​
Token Rotation Workflow

Safely rotate tokens to maintain security:

1

Generate New Token

Create a new bearer token with a different secret phrase using Generate New Bearer Token

2

Update Applications

Deploy the new token to all applications and services

3

Test Thoroughly

Verify all integrations work correctly with the new token

4

Monitor for Issues

Watch for authentication errors after deployment

5

Delete Old Phrase

Once confirmed working, delete the old secret phrase to invalidate the previous token

​
Important Considerations

Before Deleting:

  • Ensure you have a new working token in place
  • Update all applications using the old token
  • Test that the new token works correctly
  • Document which systems were updated

​
Immediate Effects

When you delete a secret phrase:

  • All tokens generated with that phrase are immediately invalidated
  • Any API requests using those tokens will return 401 Unauthorized
  • The deletion cannot be reversed
  • You’ll need to generate a new token to regain access

​
Best Practices

​
Emergency Token Revocation

If a token is compromised:

1

Act Immediately

Delete the secret phrase as soon as you detect a security issue

2

Generate New Token

Create a new token with a completely different secret phrase

3

Review Access Logs

Check API access logs for suspicious activity

4

Update Security

Review and strengthen your token storage and handling practices

5

Notify Stakeholders

Inform relevant team members about the security incident

​
Troubleshooting

For security-related issues or to report compromised tokens, contact support@masonhub.co immediately.