Set or revoke a contact's vendor token
Rotate or revoke the vendor token Peeve holds for one contact.
Credential: API token · Role: owner or admin (grant)
Note
{id}is Peeve’s contact id — a UUID — not yourexternal_user_id. It is theidfield on a contact. If you only have your own id, resolve it first withGET /v1/contacts?external_user_id=…and readdata[0].id. Passing an external id returns400 invalid_id.
The vendor token is that end user’s credential for your API — what the server SDK’s identify({ token }) supplies, and what Peeve presents when it acts on that user’s account.
This is the narrow operation: one contact, one credential. The alternative is re-pushing the whole user through POST /v1/users, which needs the external id and rewrites every identity field as a side effect.
It sits on grant — the same capability the contact page requires to issue or revoke a contact’s access, and the same one POST /v1/users requires. Writing an end user’s credential is one act, so it answers to one gate whichever door it comes through.
Warning
The token is never returned — not on success, not in an error, not in the audit line. The response carries only the resulting status.
Authorizations
An API token (pv_ut_…) as Authorization: Bearer pv_ut_…. X-Peeve-Key is accepted too. Never a query parameter — URLs end up in proxy logs and Referer headers.
The token carries its owner's live workspace role, re-read on every call.
Path Parameters
Peeve's id for the contact — the id field on a contact object, a UUID. The code calls it the end-user id.
This is not your own external_user_id. Passing one returns 400 invalid_id. To go from your id to this one, look the contact up first: GET /v1/contacts?external_user_id=user_8412 and read data[0].id.
Body
The token to store, encrypted at rest. null revokes.