delimit_secret_revoke
Revoke a secret to block all future access. Use after a credential leak or when rotating away from an old secret name.
Instructions
Revoke a secret to prevent any future access.
When to use: after a credential leak or when rotating away from an old secret name. When NOT to use: to delete metadata only — revocation also blocks delimit_secret_get from succeeding.
Sibling contrast: delimit_secret_store creates; this disables.
Side effects: writes a revocation record via ai.secrets_broker.revoke_secret. Subsequent get calls will be denied; the access log is preserved.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | No | Secret name to revoke. Required. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||