Pass your access token in the The
Authorization header on every protected request:/auth/* routes, GET /health, and GET /drive/callback are public and do not require this header.Auth Flow
Logging Out
CallPOST /auth/logout to revoke the current session. Pass your refresh token in the request body so the API can identify the session to revoke. This endpoint is idempotent — it always returns 204 No Content regardless of whether the token was already revoked or the session never existed.
string
The refresh token for the session you want to end. If omitted, the endpoint still returns
204 without taking any action.