Skip to content

Delete your account

POST
/auth/account/delete
curl --request POST \
--url https://api.sloose.com/auth/account/delete \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "confirm": "example" }'

Deletes the person behind the session, everywhere, at once: every session and sign-in link, the Zoho sign-ins linked to the account (so none can find it again), passkeys and second factor, every org membership, the apps granted access over MCP (their tokens stop working), requests to join, invitations to the address that were never accepted, and their own connections, whose credentials go with the rest and are each sent to Zoho to be revoked (Zoho may refuse or be down; that is named in warnings, and the account is deleted regardless). What they did for an org stays as the org’s record, as “a deleted person”, with every copy of the address in it replaced; the address is freed, so signing up with it again is a new person. One message goes to the address saying it is done. Refused while the person is the only owner of an open org (close it, or make someone else an owner, first) or the last staff member, and — when a second factor is enrolled — unless this session passed one recently. confirm must be the account’s own email. Session only.

Media typeapplication/json
object
confirm
required

The account’s own email, typed.

string
Examplegenerated
{
"confirm": "example"
}

Deleted. The bearer that asked no longer works.

Media typeapplication/json
object
ok
required
boolean
warnings
required

What could not be done at Zoho on the way out — a connection whose grant Zoho would not revoke. The account is deleted regardless.

Array<string>
mailed
required

The message saying it is done was accepted for delivery. False when it was not — the account is deleted regardless, and nothing can send it again.

boolean
Example
{
"ok": true
}

confirm is not the account’s email (code: CONFIRMATION_MISMATCH), or the body is not { confirm } (code: INVALID_BODY).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

No bearer, or one that is expired, revoked or no longer resolves to a member.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

An API token was used (code: SESSION_REQUIRED), the person is banned (code: BANNED), the session is a staff member’s view of an org (code: STAFF_VIEW), or a second factor is enrolled and this session has not passed one recently (code: SECOND_FACTOR_REQUIRED).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

The person is the only owner of an open org (code: SOLE_OWNER, naming each in orgs), or the last staff member (code: LAST_STAFF) — asked inside the deletion’s own transaction as well as before it — or the account changed as it was being deleted (code: ACCOUNT_CHANGED).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

Report a problem with this page