Questions · Updated 2026-09-28
How do I revoke an AI assistant connection?
Revoke an AI assistant's connection with DELETE /oauth/grants/{id}, using the connection id from GET /oauth/grants. The operation summary says tokens and the backing key die immediately. Both calls are a signed-in person's; an API key is refused with human_action_required.
Revoke an AI assistant's connection by calling DELETE /oauth/grants/{id} as a signed-in person, with the connection id from GET /oauth/grants. The summary of that delete is "Revoke one assistant connection. Tokens and the backing key die immediately." The assistant's next request fails to authenticate, and nothing the assistant can call reopens the connection: an API key on either route is refused with human_action_required.
Find the connection
GET /oauth/grants lists them. Its summary is "Every assistant connection on this account, newest first." Each row carries id, client_id, client_name, scopes, created_at and last_used_at. One row is one connection a person approved: an assistant such as Claude, ChatGPT, Cursor or another MCP client connected over OAuth 2.1 to https://api.agentisend.com/mcp, backed by a key that holds the scopes approved at that moment. last_used_at says whether the connection is still in use; scopes says what it may do.
curl -sS -X GET https://api.agentisend.com/oauth/grants \
-H "Authorization: Bearer $AGENTISEND_API_KEY"200
{
"data": [],
"has_more": true,
"next_cursor": "string",
"object": "string"
}Revoke it
DELETE /oauth/grants/{id} returns the id and deleted: true. Every access token and refresh token on the connection is revoked, any unused authorization code is spent, and the key behind them is revoked, all in the same call. Calling it again on the same id answers not_found with "No connection with that id on this account." A new connection needs a person to approve it again; the assistant cannot grant itself one.
Over MCP the same two calls are the tools list_oauth_grants and revoke_oauth_grant. Their descriptions say the same thing the routes do: "A key is refused with human_action_required."
A connection made with a pasted key
An assistant that was configured with a pasted as_… token rather than through OAuth does not appear in GET /oauth/grants, because there is no grant, only the key. Revoke that key with DELETE /api-keys/{id}, whose summary is "Revoke an API key immediately." The catalogue says a deleted key cannot be restored. Revoking a key that backs an OAuth connection also ends that connection, so DELETE /api-keys/{id} is a second way in when you know the key and not the grant.
What an API key gets
An API key calling GET /oauth/grants or DELETE /oauth/grants/{id} is refused with human_action_required. The message is "This is a person’s decision, so an API key cannot make it." Both routes answer a signed-in session and nothing else. So an assistant cannot drop another assistant's connection, and cannot hide its own by dropping it.
Revoking access is one stop. The other is the kill switch, POST /limits/kill-all, which pauses sending from every key on the account and takes effect on the next request; the connections stay listed, and their sends answer kill_switch_active until a person resumes them. How do I pause an AI agent that is sending email? covers that stop.