Skip to content

Session Revocation — Zendesk

Session Revocation — Zendesk

Challenge bulk-deletes all active sessions for a Zendesk user.

Credentials

  1. In Zendesk Admin Center, enable API token access and create an API token.
  2. Use an admin account email plus API token for Basic authentication.
  3. In Challenge under Integrations → Session Revocation → Zendesk, enter:
    • Subdomain (e.g. company for company.zendesk.com)
    • Admin email
    • API token

API calls Challenge makes

StepMethodEndpoint
LookupGET/api/v2/users/search.json?query=email:{email}
RevokeDELETE/api/v2/users/{user_id}/sessions

Authentication: Basic auth with {email}/token:{api_token}.

Username format

Use the agent or end-user email address.

Expected outcomes

  • 204 on revoke → all sessions deleted
  • Empty search results → user not found

Troubleshooting

SymptomCheck
http_401Wrong subdomain, email, or API token
http_403Admin role cannot manage sessions
Multiple users in searchUse unique email; ambiguous matches fail safely