Revocation
Sometimes the answer is "stop — now." A credential leaked, a grant was a mistake, a session is doing something it shouldn't. OAP's authority is designed to be pulled in flight: revoke it and the change lands on the agent's next action, not whenever it happens to restart.
Revocation is checked at the choke point, live
Because every consequential thing an agent does is a tool call through a gated pipeline, there's a single place to enforce a withdrawal. Revocation re-checks immediately before the call runs — so a credential or grant you pull mid-turn stops the very next tool call, rather than being caught only when a token is next minted or a pod next starts. There's no window where authority you've already removed keeps working.
What you can pull
- A credential — a leaked or rotated secret. Once revoked, tools that authenticate with it fail closed, and repeated auth failures end the session rather than retrying a dead credential.
- A grant — an approval or a slot you granted, including a participant's standing in a session. Revoke it and that subject can no longer drive or approve.
- A session — halt a run outright, or place it on a hold so it's frozen for inspection rather than torn down.