Marks the certificate revoked with revocationReason and the time, so verification reports it as revoked from then on. Returns 404 when the organization has no such certificate. Requires an org admin or owner.
PATCH
/certificates/{certificateId}
curl \
--request PATCH 'http://api.example.com/certificates/{certificateId}' \
--header "Authorization: Bearer $ACCESS_TOKEN" \
--header "Content-Type: application/json" \
--header "organization: string" \
--data '{
"revocationReason": "string"
}'
Request examples
# Headers
organization: string
# Payload
{
"revocationReason": "string"
}
Response examples (200)
{
"data": {
"createdAt": "2026-01-15T14:30:00.000Z",
"updatedAt": "2026-01-15T14:30:00.000Z",
"id": "507f1f77bcf86cd799439011",
"certificateId": "HC-2026-05-15-A1B2-1F3",
"organization": "65a1b2c3d4e5f6a7b8c9d0e3",
"case": "65a1b2c3d4e5f6a7b8c9d0e2",
"sourceIds": [
"65a1b2c3d4e5f6a7b8c9d0f4"
],
"status": "verified",
"generatedBySide": "org",
"certificate": {
"generatedAt": "2026-05-15T12:00:00.000Z",
"dataSummary": {}
},
"revokedAt": "2026-05-04T09:42:00Z",
"revocationReason": "string",
"createdBy": "65a1b2c3d4e5f6a7b8c9d0e4"
},
"statusCode": 200,
"timestamp": "2026-01-15T10:15:00.000Z"
}