Skip to main content

DELETE /api/session

End a session. Idempotent.

Closes the session named by the Authorization header, if there is one, and answers 204.

It is idempotent and unauthenticated by contract, not by accident. A caller presenting no credential at all, a dead one, or the same one twice, all get 204. A double logout is not an error, and this route never consults the session guard. No cookie is cleared, because this surface sets none.

Authentication​

No session required. This operation is reachable without an Authorization header. See Authenticating.

Request​

No request body.

Responses​

204​

The session is gone, or was already gone, or was never named. These are not distinguished, deliberately.