Back-channel logout from the identity provider
POST
/auth/backchannel-logout
const url = 'https://example.com/auth/backchannel-logout';const options = { method: 'POST', headers: {'Content-Type': 'application/x-www-form-urlencoded'}, body: new URLSearchParams({logout_token: 'example'})};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/auth/backchannel-logout \ --header 'Content-Type: application/x-www-form-urlencoded' \ --data logout_token=exampleOpenID Connect Back-Channel Logout 1.0: the identity provider posts a signed logout_token when a user logs out there, and the sessions it names end at once.
Authorizations
Section titled “Authorizations”- None
Request Bodyrequired
Section titled “Request Bodyrequired”Media typeapplication/x-www-form-urlencoded
object
logout_token
required
A logout token signed by the identity provider (a JWT).
string
Example generated
logout_token=exampleResponses
Section titled “Responses”The sessions ended.
No or an invalid logout token.
Media typeapplication/json
An OAuth 2.0 error (RFC 6749 §5.2).
object
error
required
string
error_description
required
string
Example
{ "error": "invalid_request"}