Delete your account
const url = 'https://api.sloose.com/auth/account/delete';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"confirm":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.sloose.com/auth/account/delete \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "confirm": "example" }'Deletes the person behind the session, everywhere, at once: every session and sign-in link, the Zoho sign-ins linked to the account (so none can find it again), passkeys and second factor, every org membership, the apps granted access over MCP (their tokens stop working), requests to join, invitations to the address that were never accepted, and their own connections, whose credentials go with the rest and are each sent to Zoho to be revoked (Zoho may refuse or be down; that is named in warnings, and the account is deleted regardless). What they did for an org stays as the org’s record, as “a deleted person”, with every copy of the address in it replaced; the address is freed, so signing up with it again is a new person. One message goes to the address saying it is done. Refused while the person is the only owner of an open org (close it, or make someone else an owner, first) or the last staff member, and — when a second factor is enrolled — unless this session passed one recently. confirm must be the account’s own email. Session only.
Authorizations
Section titled “Authorizations”Request Bodyrequired
Section titled “Request Bodyrequired”object
The account’s own email, typed.
Examplegenerated
{ "confirm": "example"}Responses
Section titled “Responses”Deleted. The bearer that asked no longer works.
object
What could not be done at Zoho on the way out — a connection whose grant Zoho would not revoke. The account is deleted regardless.
The message saying it is done was accepted for delivery. False when it was not — the account is deleted regardless, and nothing can send it again.
Example
{ "ok": true}confirm is not the account’s email (code: CONFIRMATION_MISMATCH), or the body is not { confirm } (code: INVALID_BODY).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}No bearer, or one that is expired, revoked or no longer resolves to a member.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}An API token was used (code: SESSION_REQUIRED), the person is banned (code: BANNED), the session is a staff member’s view of an org (code: STAFF_VIEW), or a second factor is enrolled and this session has not passed one recently (code: SECOND_FACTOR_REQUIRED).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}The person is the only owner of an open org (code: SOLE_OWNER, naming each in orgs), or the last staff member (code: LAST_STAFF) — asked inside the deletion’s own transaction as well as before it — or the account changed as it was being deleted (code: ACCOUNT_CHANGED).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}