ti fs delete-file-system-token
Permanently revokes a file system token. The token stops authenticating after the change propagates and no longer appears in list results. An owner token can revoke either token kind in the same file system; a scoped token cannot use this command.
Syntax
ti fs delete-file-system-token
--token-id <string>
[--file-system-id <string>]
[--fs-token <string>]
[--dry-run]
[--help]
[--version]
Options
--file-system-id <string>: Specify the file system that owns the token. Required when using TiDB Cloud API credentials; optional when an owner token supplies the ID.--token-id <string>: Specify the immutable token ID returned by the list command. This option is required.--fs-token <string>: Authorize the request with a file system owner token. If omitted, the command uses theTI_FS_TOKENenvironment variable. If neither is provided, the command requires TiDB Cloud API credentials and--file-system-id. It does not automatically use a locally stored owner token.--dry-run: Validate credentials, identifiers, and known local mount conflicts without revoking the token.--help: Display help information.--version: Display version information.
For options shared by all commands, see Global options.
Examples
Revoke an old token after validating its replacement:
# Revocation is permanent; use disable first when you need a reversible rollout. ti fs delete-file-system-token \ --file-system-id "<file-system-id>" \ --token-id "<old-token-id>"Revoke a token by using an owner token:
# The owner token identifies the file system; use the immutable ID of the token being revoked. TI_FS_TOKEN="<owner-fs-token>" ti fs delete-file-system-token \ --token-id "<old-token-id>"