The clear cache API evicts users from the user cache. You can completely clear the cache or evict specific users.
POST /_security/realm/<realms>/_clear_cache
POST /_security/realm/<realms>/_clear_cache?usernames=<usernames>
User credentials are cached in memory on each node to avoid connecting to a remote authentication service or hitting the disk for every incoming request. There are realm settings that you can use to configure the user cache. For more information, see Controlling the User Cache.
To evict roles from the role cache, see the Clear Roles Cache API.
realms
(required)
usernames
For example, to evict all users cached by the file
realm:
POST /_security/realm/default_file/_clear_cache
To evict selected users, specify the usernames
parameter:
POST /_security/realm/default_file/_clear_cache?usernames=rdeniro,alpacino
To clear the caches for multiple realms, specify the realms as a comma-delimited list:
POST /_security/realm/default_file,ldap1/_clear_cache