# How to Revoke IPATool Credentials: CLI and Go Implementation Guide

> Revoke IPATool credentials easily using the CLI command ipatool auth revoke. Learn how to remove stored Apple ID credentials from your system keychain with this Go implementation guide.

- Repository: [Majd/ipatool](https://github.com/majd/ipatool)
- Tags: how-to-guide
- Published: 2026-09-01

---

**Run `ipatool auth revoke` to remove stored Apple ID credentials from your system keychain.**

IPATool stores authentication data in the operating system keychain through its internal **appstore** package. When you need to securely log out or delete saved credentials, the tool provides a dedicated revocation mechanism that removes the account entry directly from the keychain. This guide explains how to revoke IPATool credentials using both the command-line interface and programmatic Go code, based on the source implementation in `majd/ipatool`.

## Understanding IPATool Credential Storage

IPATool persists Apple ID credentials using the OS-native keychain rather than plaintext files. The `appstore` package manages this storage through a dedicated keychain interface, saving the account data under the key `"account"`. Because authentication relies entirely on this keychain entry, removing it effectively logs the tool out of your Apple ID without requiring additional cleanup of secondary tokens or configuration files.

## How to Revoke IPATool Credentials from the Command Line

The simplest method to revoke credentials is using the built-in `auth revoke` sub-command. This command triggers the removal of the stored account information from your system keychain.

```bash

# Revoke the stored Apple ID credentials

ipatool auth revoke

```

When executed successfully, the command removes the `"account"` entry from the keychain. If the removal fails (for example, if no credentials were previously stored), the CLI returns an error indicating the failure.

## Revoking Credentials Programmatically in Go

You can also revoke credentials programmatically by calling the `Revoke` method on an `appstore` instance. This approach is useful when building custom tooling or automation around IPATool's core functionality.

```go
import (
    "github.com/majd/ipatool/v2/pkg/appstore"
)

// Assuming you have an appstore instance named `store`
if err := store.Revoke(); err != nil {
    // handle error – revocation failed
    log.Fatalf("failed to revoke credentials: %v", err)
}
fmt.Println("credentials revoked")

```

The `Revoke` method handles the keychain interaction internally, returning an error only if the underlying keychain operation fails.

## Implementation Details

The revocation flow involves three distinct layers in the codebase: CLI command registration, business logic implementation, and low-level keychain operations.

### CLI Command Registration

The `revoke` sub-command is defined in [`cmd/auth.go`](https://github.com/majd/ipatool/blob/main/cmd/auth.go) within the `revokeCmd` function (lines 53-58). This function binds the `ipatool auth revoke` command to the appstore's `Revoke` method, handling flag parsing and error output before delegating to the core logic.

### Core Revocation Logic

The actual credential removal is implemented in [`pkg/appstore/appstore_revoke.go`](https://github.com/majd/ipatool/blob/main/pkg/appstore/appstore_revoke.go) (lines 7-13). The `Revoke` method executes `t.keychain.Remove("account")`, which targets the specific keychain entry where the Apple ID credentials are stored. This implementation ensures that only the account data is removed, leaving other tool configurations intact.

### Keychain Interaction

The `Remove` operation utilized by the `Revoke` method is defined in [`pkg/keychain/keyring.go`](https://github.com/majd/ipatool/blob/main/pkg/keychain/keyring.go). This abstraction layer provides the interface between IPATool and the operating system's native keychain services (such as macOS Keychain or Windows Credential Manager), ensuring secure deletion of sensitive authentication data.

## Summary

- **Command-line method**: Execute `ipatool auth revoke` to delete stored credentials instantly.
- **Programmatic method**: Call `store.Revoke()` on an `appstore` instance within Go applications.
- **Storage mechanism**: Credentials are removed from the OS keychain via `keychain.Remove("account")`.
- **Source locations**: CLI entry point is in [`cmd/auth.go`](https://github.com/majd/ipatool/blob/main/cmd/auth.go); core logic resides in [`pkg/appstore/appstore_revoke.go`](https://github.com/majd/ipatool/blob/main/pkg/appstore/appstore_revoke.go).
- **Security**: No residual tokens or files remain after revocation; only the keychain entry is deleted.

## Frequently Asked Questions

### What happens when I revoke IPATool credentials?

Revoking credentials deletes the `"account"` entry from your system keychain. This removes the stored Apple ID and password, effectively logging IPATool out. No local configuration files or cached data persist; the tool will require re-authentication on the next use.

### Where does IPATool store Apple ID credentials?

IPATool stores credentials exclusively in the operating system keychain through its `pkg/keychain` implementation. Unlike tools that use plaintext files or environment variables, IPATool relies on the OS-native secure storage mechanism accessible via the [`keyring.go`](https://github.com/majd/ipatool/blob/main/keyring.go) abstraction layer.

### Can I revoke credentials programmatically?

Yes. Import `github.com/majd/ipatool/v2/pkg/appstore` and call the `Revoke()` method on your `appstore` instance. This method mirrors the CLI behavior by invoking the keychain removal logic directly from your Go code.

### What if the revoke command fails?

If `ipatool auth revoke` returns an error, it typically indicates that either no credentials were present in the keychain or the keychain access was denied. Verify that you have the necessary permissions to modify system keychain entries and that credentials were previously stored using `ipatool auth login`.