Revoke a Verification
Terminally cancels an in-flight attempt and expires its hosted link. The attempt moves to
revoked and cannot be resumed — open a new attempt via re-verify if the subject should
be verified later. Fails with 422 when the attempt is already terminal.
Authorizations
Per-request DPoP proof JWT (RFC 9449). MUST accompany the Authorization: DPoP <access_token> header on every protected operation. The proof is signed by the merchant's private DPoP key and carries htm, htu, iat, jti, and ath claims.
Headers
Unique key identifying this operation. Sending the same key twice returns the original response instead of creating a duplicate. Keys are retained for 24 hours.
255Path Parameters
Verification attempt ID.
^vrf_[a-zA-Z0-9]+$Response
Attempt revoked.
One verification attempt. hosted_link is secret-once: present only on the response
that minted it (create / resend / regenerate / re-verify) and never on a read.