# Remove\_token for HMAC-Signed token

**URL:** <https://janus.discourse.group/t/remove-token-for-hmac-signed-token/1739>\
**Category:** General\
**Created:** [November 4, 2025, 9:08am UTC](https://janus.discourse.group/t/remove-token-for-hmac-signed-token/1739 "2025-11-04T09:08:01Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![programmer](https://avatars.discourse-cdn.com/v4/letter/p/779978/32.png) [@programmer](https://janus.discourse.group/u/programmer)\
**Post date:** [November 4, 2025, 9:08am UTC](https://janus.discourse.group/t/remove-token-for-hmac-signed-token/1739/1 "2025-11-04T09:08:01Z")

</div>

I know we have remove\_token for [Stored token based authentication mechanism](https://janus.conf.meetecho.com/docs/auth.html#token).

So will it work for [HMAC-Signed token authentication](https://janus.conf.meetecho.com/docs/auth.html#signed) as well?

If not how can I revoke hmac token I created?

---

<div class="post-metadata">

**Author:** ![lorenzo](https://yyz2.discourse-cdn.com/free1/user_avatar/janus.discourse.group/lorenzo/32/425_2.png) [@lorenzo](https://janus.discourse.group/u/lorenzo)\
**Post date:** [November 4, 2025, 3:14pm UTC](https://janus.discourse.group/t/remove-token-for-hmac-signed-token/1739/2 "2025-11-04T15:14:35Z")

</div>

The documentation you linked to already explains this:

> Please note that tokens of this sort cannot be revoked after being signed and passed to the client. Instead of signing tokens with late expirys, it is recommended to use tokens with shorter durations and generate and transition to a new token within the expiry time of every last token when the lease time is unknown and security is critical.
