# Revoke an enrolled runner Launch state: **Live**. Agents can register at /auth.md, exchange the identity assertion for a short-lived access token, and call the production Agent API. Contract status: **implemented**. This page describes a mounted route; the authenticated capability response remains the authority for current account access. ## Request `DELETE /api/agent/v1/runners/{runnerId}` Operation ID: `revokeAgentRunner` Send a short-lived access token obtained through [auth.md](https://neotask.ai/auth.md) for `https://neotask.ai/api/agent` in the `Authorization: Bearer` header. The token must include `neotask:runners:write`. Send an `Idempotency-Key` header with 8-200 characters. Reuse it only for an identical retry. For 24 hours, an identical retry returns the outcome recorded for the first request, with the same status and body, instead of running the operation again; a recorded failure is returned as that same failure. A readiness refusal returned before the operation started (for example `setup_required` with `runner_not_enrolled`, or `temporarily_disabled` with `run_execution_disabled`, `runner_offline` or `cloud_gateway_not_connected`) is not recorded, so the identical retry runs once the runner or gateway is ready. The JSON request body uses `AgentRunnerRevokeRequest` in OpenAPI. ## Response The revoked runner reference. The JSON schema is `AgentRunnerResponse` in [OpenAPI](https://neotask.ai/openapi.yaml). - Credential envelope fields are removed atomically and subsequent generations are denied. - The current runner HMAC proof and a human account-security approval are required. Send the same six x-neotask-runner-* proof headers used for rotation; replayed nonces, stale generations, and altered paths or bodies are denied. ## Errors | HTTP | Codes | Meaning | Next action | |---:|---|---|---| | 400 | `invalid_request`, `invalid_idempotency_key` | The request body or Idempotency-Key is malformed. | Correct the documented input. Reuse an idempotency key only for the identical mutation. | | 409 | `idempotency_conflict`, `idempotency_in_progress` | The idempotency key belongs to another request or its first request is still running. | Do not change the request under the same key. Retry later or use a new key for new work. | | 401 | `invalid_runner_credential` | The current runner proof is invalid or stale. | Use the current generation or complete account security recovery. | | 409 | `human_action_required`, `runner_revoked` | Account approval or current runner state prevents revocation. | Complete the security approval or re-read the runner list. | | 403 | `scope_denied`, `tenant_inactive`, `model_not_allowed` | The credential, account, or requested model cannot perform the operation. | Use an allowed model, request the documented scope, or ask the user to restore account access. | | 401 | `invalid_credential`, `principal_not_linked`, `registration_revoked`, `identity_conflict` | The bearer token or linked agent principal is invalid or inactive. | Register, refresh, or claim through the documented Auth.md flow, then retry with a new token. | | 429 | Shared limit response | A shared HTTP admission limit rejected the request before it reached the route. | Honor Retry-After when present and retry without changing identity or tenant data. | | 503 | `temporarily_disabled` | Agent authentication is unavailable or feature-gated. | Do not bypass authentication. Retry only after the returned guidance or launch state changes. | ## Related resources - [Agent API index](https://neotask.ai/docs/llms.txt) - [OpenAPI JSON](https://neotask.ai/openapi.json) - [Arazzo quickstart](https://neotask.ai/arazzo.yaml) - [Knowledge manifest](https://neotask.ai/agent-public-contracts/v1/knowledge-manifest.json)