Skip to main content

Command Palette

Search for a command to run...

Deactivating a user should shut off their API tokens too

Updated
•1 min read•View as Markdown
A
Practical lessons on auth, authorization, and access control.

When someone leaves, an admin marks their account deactivated and the login page starts rejecting them. Their personal API tokens often keep working anyway. The token middleware looks up the token hash, finds a match, and loads that user's permissions without ever checking the account status.

Refresh tokens have the same gap. The access token may expire in a few minutes, but if the refresh endpoint only checks that the refresh token is valid, the old session keeps getting new access tokens for weeks.

After you resolve a token to a user, check on every request that the user is still active and still a member of the workspace the request is for. When an account is deactivated, revoke its refresh tokens and personal API keys in the same transaction, so nothing issued before that point still works.

To test it, create a token as a regular user, deactivate that user from the admin screen, and call any read endpoint with the token. If you get a 200, deactivation only blocked the login form.