The Square OAuth API uses the OAuth 2 protocol to get permission from the owner of the seller account to manage specific types of resources in that account.
Step 1: Revoke the exposed secret.
POST /oauth2/revoke: Revokes an access token generated with the OAuth flow.
If an account has more than one OAuth access token for your application, this endpoint revokes all of them, regardless of which token you specify. When an OAuth access token is revoked, all of the active subscriptions associated with that OAuth token are canceled immediately.
Replace APPLICATION_SECRET with the application secret on the OAuth page in the developer dashboard.
Authorization: Client APPLICATION_SECRET
Step 2: Clean the git history.
Updated 12 days ago