Request to the Logout Endpoint

The application sends a GET request to the logout endpoint to revoke the valid id token and its associated access and refresh tokens. This endpoint has the following format:



where <accountID> represents your NetSuite account ID.

Request Parameters for the Logout Token Request

Request Parameter



The value of the id_token_hint parameter is the value of the id token that the application revokes.


The client authentication method used in the header of the request follows the HTTP Basic authentication scheme. For more information, see RFC 7617. The format is client_id:client_secret. The string value is Base64 encoded. The following code provides an example.

The client authentication in the request to the logout endpoint is optional.



If you use public clients you can choose from the following options:

  • The HTTP authorization request header does not contain the Authorization and the client_id parameter is included in the body of the request, or

  • The HTTP authorization request header contains only the client_id in the Authorization.

Related Topics

General Notices