Elastic Stack (ELK Stack) Fleet uninstall tokens API

Fleet uninstall tokens APIs enable you to manage Fleet uninstall tokens, including retrieving metadata and decrypted tokens for agent uninstallation.

Operations 3

GET /api/fleet/uninstall_tokens Get metadata for latest uninstall tokens #
POST /api/fleet/uninstall_tokens/{agentPolicyId}/rotate Rotate an uninstall token #
GET /api/fleet/uninstall_tokens/{uninstallTokenId} Get a decrypted uninstall token #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/elk-stack-fleet-uninstall-tokens-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

elk-stack-fleet-uninstall-tokens-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  contact:
    name: Kibana Team
  description: The Kibana REST APIs enable you to manage resources such as connectors, data views, and saved objects.
  title: Kibana Fleet uninstall tokens API
  version: ''
  x-doc-license:
    name: Attribution-NonCommercial-NoDerivatives 4.0 International
    url: https://creativecommons.org/licenses/by-nc-nd/4.0/
  x-feedbackLink:
    label: Feedback
    url: https://github.com/elastic/docs-content/issues/new?assignees=&labels=feedback%2Ccommunity&projects=&template=api-feedback.yaml&title=%5BFeedback%5D%3A+
servers:
- url: https://{kibana_url}
  variables:
    kibana_url:
      default: localhost:5601
security:
- apiKeyAuth: []
- basicAuth: []
tags:
- name: Fleet uninstall tokens
  description: Fleet uninstall tokens APIs enable you to manage Fleet uninstall tokens, including retrieving metadata and decrypted tokens for agent uninstallation.
  x-displayName: Fleet uninstall tokens
paths:
  /api/fleet/uninstall_tokens:
    get:
      description: '**Spaces method and path for this operation:**


        get /s/{space_id}/api/fleet/uninstall_tokens


        Refer to Spaces for more information.


        List the metadata for the latest uninstall tokens per agent policy.


        [Required authorization] Route required privileges: fleet-agents-all.'
      operationId: get-fleet-uninstall-tokens
      parameters:
      - description: Partial match filtering for policy IDs
        in: query
        name: policyId
        required: false
        schema:
          maxLength: 50
          type: string
      - description: Partial match filtering for uninstall token values
        in: query
        name: search
        required: false
        schema:
          maxLength: 50
          type: string
      - description: The number of items to return
        in: query
        name: perPage
        required: false
        schema:
          minimum: 5
          type: number
      - description: Page number
        in: query
        name: page
        required: false
        schema:
          minimum: 1
          type: number
      responses:
        '200':
          content:
            application/json:
              examples:
                getUninstallTokensExample:
                  description: List of uninstall token metadata for agent policies
                  value:
                    items:
                    - created_at: '2024-01-01T00:00:00.000Z'
                      id: token-id-1
                      namespaces:
                      - default
                      policy_id: policy-id-1
                      policy_name: Default policy
                    - created_at: '2024-01-02T00:00:00.000Z'
                      id: token-id-2
                      namespaces:
                      - production
                      policy_id: policy-id-2
                      policy_name: Production policy
                    page: 1
                    perPage: 20
                    total: 2
              schema:
                additionalProperties: false
                type: object
                properties:
                  items:
                    items:
                      additionalProperties: false
                      type: object
                      properties:
                        created_at:
                          type: string
                        id:
                          type: string
                        namespaces:
                          items:
                            type: string
                          maxItems: 100
                          type: array
                        policy_id:
                          type: string
                        policy_name:
                          type:
                          - string
                          - 'null'
                      required:
                      - id
                      - policy_id
                      - created_at
                    maxItems: 10000
                    type: array
                  page:
                    type: number
                  perPage:
                    type: number
                  total:
                    type: number
                required:
                - items
                - total
                - page
                - perPage
          description: Successful response
        '400':
          content:
            application/json:
              examples:
                conflictingQueryParamsExample:
                  description: Both policyId and search query parameters were provided
                  value:
                    error: Bad Request
                    message: Query parameters `policyId` and `search` cannot be used at the same time.
                    statusCode: 400
              schema:
                additionalProperties: false
                description: Generic Error
                type: object
                properties:
                  attributes: {}
                  error:
                    type: string
                  errorType:
                    type: string
                  message:
                    type: string
                  statusCode:
                    type: number
                required:
                - message
                - attributes
          description: Bad Request
      summary: Get metadata for latest uninstall tokens
      tags:
      - Fleet uninstall tokens
      x-metaTags:
      - content: Kibana
        name: product_name
  /api/fleet/uninstall_tokens/{agentPolicyId}/rotate:
    post:
      description: '**Spaces method and path for this operation:**


        post /s/{space_id}/api/fleet/uninstall_tokens/{agentPolicyId}/rotate


        Refer to Spaces for more information.


        Rotate the uninstall token for an agent policy. Only applicable to policies with tamper protection enabled.


        [Required authorization] Route required privileges: fleet-agents-all.'
      operationId: post-fleet-uninstall-tokens-agentpolicyid-rotate
      parameters:
      - description: A required header to protect against CSRF attacks
        in: header
        name: kbn-xsrf
        required: true
        schema:
          example: 'true'
          type: string
      - description: The ID of the agent policy whose uninstall token should be rotated
        in: path
        name: agentPolicyId
        required: true
        schema:
          maxLength: 255
          type: string
      responses:
        '200':
          content:
            application/json:
              examples:
                rotateUninstallTokenExample:
                  description: Uninstall token rotated successfully for the given agent policy
                  value:
                    message: Uninstall token rotated successfully.
              schema:
                additionalProperties: false
                type: object
                properties:
                  message:
                    type: string
                required:
                - message
          description: Successful response
        '400':
          content:
            application/json:
              examples:
                genericErrorResponseExample:
                  description: Example of a generic error response
                  value:
                    error: Bad Request
                    message: An error message describing what went wrong
                    statusCode: 400
                notProtectedExample:
                  description: Agent policy does not have tamper protection enabled
                  value:
                    error: Bad Request
                    message: Agent policy [policy-id-1] does not have tamper protection enabled. Uninstall tokens can only be rotated for protected policies.
                    statusCode: 400
              schema:
                additionalProperties: false
                description: Generic Error
                type: object
                properties:
                  attributes: {}
                  error:
                    type: string
                  errorType:
                    type: string
                  message:
                    type: string
                  statusCode:
                    type: number
                required:
                - message
                - attributes
          description: Bad Request
        '404':
          content:
            application/json:
              examples:
                notFoundExample:
                  description: No agent policy was found with the given ID
                  value:
                    error: Not Found
                    message: Agent policy not found with id policy-id-1
                    statusCode: 404
              schema:
                additionalProperties: false
                description: Generic Error
                type: object
                properties:
                  attributes: {}
                  error:
                    type: string
                  errorType:
                    type: string
                  message:
                    type: string
                  statusCode:
                    type: number
                required:
                - message
                - attributes
          description: Not Found
      summary: Rotate an uninstall token
      tags:
      - Fleet uninstall tokens
      x-metaTags:
      - content: Kibana
        name: product_name
  /api/fleet/uninstall_tokens/{uninstallTokenId}:
    get:
      description: '**Spaces method and path for this operation:**


        get /s/{space_id}/api/fleet/uninstall_tokens/{uninstallTokenId}


        Refer to Spaces for more information.


        Get one decrypted uninstall token by its ID.


        [Required authorization] Route required privileges: fleet-agents-all.'
      operationId: get-fleet-uninstall-tokens-uninstalltokenid
      parameters:
      - description: The ID of the uninstall token
        in: path
        name: uninstallTokenId
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              examples:
                getUninstallTokenExample:
                  description: Decrypted uninstall token for an agent policy
                  value:
                    item:
                      created_at: '2024-01-01T00:00:00.000Z'
                      id: token-id-1
                      namespaces:
                      - default
                      policy_id: policy-id-1
                      policy_name: Default policy
                      token: CKHJsJcBqNwIRcRBNDaE
              schema:
                additionalProperties: false
                type: object
                properties:
                  item:
                    additionalProperties: false
                    type: object
                    properties:
                      created_at:
                        type: string
                      id:
                        type: string
                      namespaces:
                        items:
                          type: string
                        maxItems: 100
                        type: array
                      policy_id:
                        type: string
                      policy_name:
                        type:
                        - string
                        - 'null'
                      token:
                        type: string
                    required:
                    - id
                    - policy_id
                    - created_at
                    - token
                required:
                - item
          description: Successful response
        '400':
          content:
            application/json:
              examples:
                genericErrorResponseExample:
                  description: Example of a generic error response
                  value:
                    error: Bad Request
                    message: An error message describing what went wrong
                    statusCode: 400
              schema:
                additionalProperties: false
                description: Generic Error
                type: object
                properties:
                  attributes: {}
                  error:
                    type: string
                  errorType:
                    type: string
                  message:
                    type: string
                  statusCode:
                    type: number
                required:
                - message
                - attributes
          description: Bad Request
        '404':
          content:
            application/json:
              examples:
                notFoundExample:
                  description: No uninstall token was found with the given ID
                  value:
                    error: Not Found
                    message: Uninstall Token not found with ID token-id-1
                    statusCode: 404
          description: Not Found
      summary: Get a decrypted uninstall token
      tags:
      - Fleet uninstall tokens
      x-metaTags:
      - content: Kibana
        name: product_name
components:
  securitySchemes:
    apiKeyAuth:
      description: 'These APIs use key-based authentication. You must create an API key and use the encoded value in the request header. For example: `Authorization: ApiKey base64AccessApiKey`

        '
      in: header
      name: Authorization
      type: apiKey
    basicAuth:
      scheme: basic
      type: http
x-topics:
- title: Kibana spaces
  content: "Spaces enable you to organize your dashboards and other saved objects into meaningful categories.\nYou can use the default space or create your own spaces.\n\nTo run APIs in non-default spaces, you must add `s/{space_id}/` to the path.\nFor example:\n\n```bash\ncurl -X GET \"http://${KIBANA_URL}/s/marketing/api/data_views\" \\\n  -H \"Authorization: ApiKey ${API_KEY}\"\n```\n\nIf you use the Kibana console to send API requests, it automatically adds the appropriate space identifier.\n\nTo learn more, check out [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces).\n"