# Bug: deauth callback requests broken?

**URL:** <https://forum.beeminder.com/t/bug-deauth-callback-requests-broken/12777>\
**Category:** Bugabee\
**Created:** [May 21, 2026, 5:52pm UTC](https://forum.beeminder.com/t/bug-deauth-callback-requests-broken/12777 "2026-05-21T17:52:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![narthur](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.beeminder.com/narthur/32/5113_2.png) [@narthur](https://forum.beeminder.com/u/narthur)\
**Post date:** [May 21, 2026, 5:52pm UTC](https://forum.beeminder.com/t/bug-deauth-callback-requests-broken/12777/1 "2026-05-21T17:52:03Z")

</div>

Working on debugging an issue with TaskRatchet, and couldn’t figure out why taskratchet wasn’t honoring events sent to its deauth webhook. Used webhook.site to listen to the request sent from beeminder, and got this:

```bash
curl -X 'POST' 'https://webhook.site/d8e138e5-ee42-4d09-88e8-7852fa1d53fe' \
  -H 'content-type: application/x-www-form-urlencoded' \
  -H 'content-length: 13' \
  -H 'host: webhook.site' \
  -H 'user-agent: Ruby' \
  -H 'accept: */*' \
  -H 'accept-encoding: gzip;q=1.0,deflate;q=0.6,identity;q=0.3' \
  -d $'access_token='

```

It’s sending an empty access token, meaning taskratchet can’t link the event back to the user who revoked the app.

Can we get this fixed?

Thanks!

---

<div class="post-metadata">

**Author:** ![narthur](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.beeminder.com/narthur/32/5113_2.png) [@narthur](https://forum.beeminder.com/u/narthur)\
**Post date:** [June 2, 2026, 12:05am UTC](https://forum.beeminder.com/t/bug-deauth-callback-requests-broken/12777/2 "2026-06-02T00:05:07Z")

</div>

Worked on this with @bee, and should be fixed now! Events sent to deauth webhooks now include username and access\_token\_hash.
