> ## Documentation Index
> Fetch the complete documentation index at: https://docs-staging-quickstart-revamp.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

> Learn how to revoke your tenant's application signing key using the Auth0 Dashboard or Management API.

# Revoke Signing Keys

You can revoke your tenant's application or API signing key using the <Tooltip tip="Auth0 Dashboard: Auth0's main product to configure your services." cta="View Glossary" href="/docs/glossary?term=Auth0+Dashboard">Auth0 Dashboard</Tooltip> or the <Tooltip tip="Auth0 Dashboard: Auth0's main product to configure your services." cta="View Glossary" href="/docs/glossary?term=Management+API">Management API</Tooltip>. The signing key is used to sign <Tooltip tip="Management API: A product to allow customers to perform administrative tasks." cta="View Glossary" href="/docs/glossary?term=ID+tokens">ID tokens</Tooltip>, <Tooltip tip="ID Token: Credential meant for the client itself, rather than for accessing a resource." cta="View Glossary" href="/docs/glossary?term=access+tokens">access tokens</Tooltip>, <Tooltip tip="Access Token: Authorization credential, in the form of an opaque string or JWT, used to access an API." cta="View Glossary" href="/docs/glossary?term=SAML">SAML</Tooltip> assertions, and <Tooltip tip="Security Assertion Markup Language (SAML): Standardized protocol allowing two parties to exchange authentication information without a password." cta="View Glossary" href="/docs/glossary?term=WS-Fed">WS-Fed</Tooltip> assertions sent to your application or API. To learn more, read [Signing Keys](/docs/get-started/tenant-settings/signing-keys).

## Prerequisites

* Before you can revoke a previously-used signing key, you must first have rotated the key. To learn more, read [Rotate Signing Keys](/docs/get-started/tenant-settings/signing-keys/rotate-signing-keys), or see the **Rotate and revoke signing key** section below.
* Make sure you have updated your application or API with the new key before you revoke the previous key.

<Warning>
  You cannot reuse a signing key after revocation, so be sure that you want to revoke it.
</Warning>

## Use the Dashboard

### Revoke previously used signing key

1. Go to [Dashboard > Settings > Signing Keys](https://manage.auth0.com/#/tenant/signing_keys).
2. In the **List of Valid Keys** section, locate the **Previously Used** key, select the more options (**...**) menu, and select **Revoke Key**.
   The **List of Valid Keys** section lists the current signing key being used by your tenant, plus the next signing key that will be assigned should you choose to rotate your signing keys. If you have previously rotated signing keys, this section also lists the previously-used keys.
   The **List of Revoked Keys** section lists the last three revoked keys for your tenant.
3. Select **Revoke** to confirm.

### Rotate and revoke signing key

1. Go to [Dashboard > Settings > Signing Keys](https://manage.auth0.com/#/tenant/signing_keys).
2. In the **Rotation Settings** section, locate the **Rotate & Revoke Signing Key** section, and select **Rotate & Revoke Key**.
3. Select **Rotate & Revoke** to confirm.

## Use the Management API

<Warning>
  You can only revoke the previously used signing key.
</Warning>

1. To get a list of the signing keys, make a `GET` call to the [Get all Application Signing Keys](https://auth0.com/docs/api/management/v2#!/Keys/get_signing_keys) endpoint.
2. Make a `PUT` call to the [Revoke an Application Signing Key by its Key ID](https://auth0.com/docs/api/management/v2#!/Keys/put_signing_keys) endpoint. Be sure to replace the `{yourKeyId}` and `{yourMgmtApiAccessToken}` placeholder values with your signing key's ID and Management API access token, respectively.

   <CodeGroup>
     ```bash cURL lines
     curl --request PUT \
        --url 'https://{yourDomain}/api/v2/keys/signing/%7ByourKeyId%7D/revoke' \
        --header 'authorization: Bearer {yourMgmtApiAccessToken}'
     ```

     ```csharp C# lines
     var client = new RestClient("https://{yourDomain}/api/v2/keys/signing/%7ByourKeyId%7D/revoke");
     var request = new RestRequest(Method.PUT);
     request.AddHeader("authorization", "Bearer {yourMgmtApiAccessToken}");
     IRestResponse response = client.Execute(request);
     ```

     ```go Go lines
     package main

     import (
        "fmt"
        "net/http"
        "io/ioutil"
     )

     func main() {

        url := "https://{yourDomain}/api/v2/keys/signing/%7ByourKeyId%7D/revoke"

        req, _ := http.NewRequest("PUT", url, nil)

        req.Header.Add("authorization", "Bearer {yourMgmtApiAccessToken}")

        res, _ := http.DefaultClient.Do(req)

        defer res.Body.Close()
        body, _ := ioutil.ReadAll(res.Body)

        fmt.Println(res)
        fmt.Println(string(body))

     }
     ```

     ```java Java lines
     HttpResponse response = Unirest.put("https://{yourDomain}/api/v2/keys/signing/%7ByourKeyId%7D/revoke")
        .header("authorization", "Bearer {yourMgmtApiAccessToken}")
        .asString();
     ```

     ```javascript Node.JS lines
     var axios = require("axios").default;

     var options = {
     method: 'PUT',
     url: 'https://{yourDomain}/api/v2/keys/signing/%7ByourKeyId%7D/revoke',
     headers: {authorization: 'Bearer {yourMgmtApiAccessToken}'}
     };

     axios.request(options).then(function (response) {
     console.log(response.data);
     }).catch(function (error) {
     console.error(error);
     });
     ```

     ```obj-c Obj-C lines
     #import <Foundation/Foundation.h>

     NSDictionary *headers = @{ @"authorization": @"Bearer {yourMgmtApiAccessToken}" };

     NSMutableURLRequest *request = [NSMutableURLRequest requestWithURL:[NSURL URLWithString:@"https://{yourDomain}/api/v2/keys/signing/%7ByourKeyId%7D/revoke"]
                                                           cachePolicy:NSURLRequestUseProtocolCachePolicy
                                                        timeoutInterval:10.0];
     [request setHTTPMethod:@"PUT"];
     [request setAllHTTPHeaderFields:headers];

     NSURLSession *session = [NSURLSession sharedSession];
     NSURLSessionDataTask *dataTask = [session dataTaskWithRequest:request
                                               completionHandler:^(NSData *data, NSURLResponse *response, NSError *error) {
                                                     if (error) {
                                                        NSLog(@"%@", error);
                                                     } else {
                                                        NSHTTPURLResponse *httpResponse = (NSHTTPURLResponse *) response;
                                                        NSLog(@"%@", httpResponse);
                                                     }
                                               }];
     [dataTask resume];
     ```

     ```php PHP lines
     $curl = curl_init();

     curl_setopt_array($curl, [
     CURLOPT_URL => "https://{yourDomain}/api/v2/keys/signing/%7ByourKeyId%7D/revoke",
     CURLOPT_RETURNTRANSFER => true,
     CURLOPT_ENCODING => "",
     CURLOPT_MAXREDIRS => 10,
     CURLOPT_TIMEOUT => 30,
     CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
     CURLOPT_CUSTOMREQUEST => "PUT",
     CURLOPT_HTTPHEADER => [
        "authorization: Bearer {yourMgmtApiAccessToken}"
     ],
     ]);

     $response = curl_exec($curl);
     $err = curl_error($curl);

     curl_close($curl);

     if ($err) {
     echo "cURL Error #:" . $err;
     } else {
     echo $response;
     }
     ```

     ```python Python lines
     import http.client

     conn = http.client.HTTPSConnection("")

     headers = { 'authorization': "Bearer {yourMgmtApiAccessToken}" }

     conn.request("PUT", "/{yourDomain}/api/v2/keys/signing/%7ByourKeyId%7D/revoke", headers=headers)

     res = conn.getresponse()
     data = res.read()

     print(data.decode("utf-8"))
     ```

     ```ruby Ruby lines
     require 'uri'
     require 'net/http'
     require 'openssl'

     url = URI("https://{yourDomain}/api/v2/keys/signing/%7ByourKeyId%7D/revoke")

     http = Net::HTTP.new(url.host, url.port)
     http.use_ssl = true
     http.verify_mode = OpenSSL::SSL::VERIFY_NONE

     request = Net::HTTP::Put.new(url)
     request["authorization"] = 'Bearer {yourMgmtApiAccessToken}'

     response = http.request(request)
     puts response.read_body
     ```

     ```swift Swift lines
     import Foundation

     let headers = ["authorization": "Bearer {yourMgmtApiAccessToken}"]

     let request = NSMutableURLRequest(url: NSURL(string: "https://{yourDomain}/api/v2/keys/signing/%7ByourKeyId%7D/revoke")! as URL,
                                            cachePolicy: .useProtocolCachePolicy,
                                         timeoutInterval: 10.0)
     request.httpMethod = "PUT"
     request.allHTTPHeaderFields = headers

     let session = URLSession.shared
     let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
     if (error != nil) {
        print(error)
     } else {
        let httpResponse = response as? HTTPURLResponse
        print(httpResponse)
     }
     })

     dataTask.resume()
     ```
   </CodeGroup>

<table class="table">
  <thead>
    <tr>
      <th>Value</th>
      <th>Description</th>
    </tr>
  </thead>

  <tbody>
    <tr>
      <td><code>YOUR\_KEY\_ID</code></td>
      <td>ID of the signing key to be revoked.  To learn how to find your signing key ID, see <a href="/docs/secure/tokens/json-web-tokens/locate-json-web-key-sets">Locate JSON Web Key Sets</a>.</td>
    </tr>

    <tr>
      <td><code>MGMT\_API\_ACCESS\_TOKEN</code></td>
      <td><a href="https://auth0.com/docs/api/management/v2/tokens">Access Token for the Management API</a> with the scope <code>update:signing\_keys</code>.</td>
    </tr>
  </tbody>
</table>

## Learn more

* [Rotate Signing Keys](/docs/get-started/tenant-settings/signing-keys/rotate-signing-keys)
* [View Signing Certificates](/docs/get-started/tenant-settings/signing-keys/view-signing-certificates)
* [Change Application Signing Algorithms](/docs/get-started/applications/change-application-signing-algorithms)
