Z Zise Developers 简体中文

Force a member to sign out (not a ban; they may sign in again immediately)

POST /v1/members/{id}/sessions/revoke scope: members:write
Merchant account Requires x-idempotency-key

Revokes the member's sessions on all devices. This is not a ban; they may sign in again immediately. To block sign-in, use POST /v1/members/{id}/suspend; the two actions are independent.

⚠ This endpoint accepts only external_member_id, not mem_<uuid>. Unlike /v1/members/{id} and x-on-behalf-of, which accept both, supplying our identifier returns member_not_found. The error looks like a missing member but actually means the wrong identifier type was used. The response id is also the external identifier you supplied, not the mem_ form.

Nonexistent members and members belonging to another merchant receive the same response.

Path Parameters

FieldTypeRequiredDescription
id string Required Accepts only external_member_id. Supplying mem_<uuid> returns 404.
FieldTypeRequiredDescription
x-idempotency-key string Required UUID v4

Response

200Forced sign-out completed.
{
  "id": "u-10086",
  "revoked": true
}
404member_not_found: nonexistent member, belonging to another merchant, or an ID in mem_ form was supplied. All three return the same response.
409idempotency_key_reused · idempotency_in_progress
Request
curl -X POST 'https://api.zinfra.vip/v1/members/{id}/sessions/revoke' \
  -H 'x-auth-token: Bearer $TOKEN' \
  -H 'x-idempotency-key: $IDEMPOTENCY_KEY'
const res = await fetch("https://api.zinfra.vip/v1/members/{id}/sessions/revoke", {
  method: "POST",
  headers: {
    "x-auth-token": "Bearer $TOKEN",
    "x-idempotency-key": "$IDEMPOTENCY_KEY",
  },
});
// Keep monetary amounts as strings, never numbers.
const data = await res.json();
import requests

res = requests.post(
    "https://api.zinfra.vip/v1/members/{id}/sessions/revoke",
    headers={
        "x-auth-token": "Bearer $TOKEN",
        "x-idempotency-key": "$IDEMPOTENCY_KEY",
    },
)
# Use Decimal(str(...)) for amounts, not float.
data = res.json()
req, _ := http.NewRequest("POST", "https://api.zinfra.vip/v1/members/{id}/sessions/revoke",
    nil)
req.Header.Set("x-auth-token", "Bearer $TOKEN")
req.Header.Set("x-idempotency-key", "$IDEMPOTENCY_KEY")
res, err := http.DefaultClient.Do(req)
// Decode amount fields as string, not float64.
HttpRequest req = HttpRequest.newBuilder()
    .uri(URI.create("https://api.zinfra.vip/v1/members/{id}/sessions/revoke"))
    .header("x-auth-token", "Bearer $TOKEN")
    .header("x-idempotency-key", "$IDEMPOTENCY_KEY")
    .method("POST", HttpRequest.BodyPublishers.noBody())
    .build();
// Use String / BigDecimal for amounts, not double.
$ch = curl_init('https://api.zinfra.vip/v1/members/{id}/sessions/revoke');
curl_setopt_array($ch, [
  CURLOPT_CUSTOMREQUEST => 'POST',
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_HTTPHEADER => [
    'x-auth-token: Bearer $TOKEN',
    'x-idempotency-key: $IDEMPOTENCY_KEY',
  ],
]);
$res = curl_exec($ch);
// Use bcmath / strings for amounts, not floatval.
200
{
  "id": "u-10086",
  "revoked": true
}