Delete somebody’s account
const url = 'https://api.sloose.com/staff/people/c1d2e3f4/delete';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"reason":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.sloose.com/staff/people/c1d2e3f4/delete \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "reason": "example" }'Backoffice route: a staff session, or ADMIN_TOKEN. What POST /auth/account/delete does for the person themselves, for somebody who asked by email: every session, sign-in, factor and membership they hold goes, their own connections are revoked (asked of Zoho, whose refusal is named in warnings), and what they did for an org stays as the org’s record under “a deleted person”. The address is freed and is sent one message saying it is done. A banned person can be deleted — that is the one thing they cannot do for themselves — and the ban goes with the account, since the address is freed and nothing is left for it to stop; a staff member cannot: take the role away first. Once deleted, the person is not found by any tool here. Refused while they are the only owner of an open org. Written down as user.delete, with the reason.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”The person
Example
c1d2e3f4The person
Request Bodyrequired
Section titled “Request Bodyrequired”object
Why — the request that asked for it, usually. Required; it goes on the record.
Examplegenerated
{ "reason": "example"}Responses
Section titled “Responses”Deleted.
object
Browsers signed out, as sessions/revoke counts them: a CRM tab’s own session is its browser’s.
What could not be done at Zoho — a connection whose grant Zoho would not revoke. The account is deleted regardless.
The message saying it is done was accepted for delivery. False when it was not — the account is deleted regardless, and nothing can send it again.
Examplegenerated
{ "sessionsEnded": 1, "warnings": [ "example" ], "mailed": true}The request — its body or its query — did not match the schema. issues carries the Zod issue list.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}A bearer that is neither the token nor a live session (code: AUTH_REQUIRED).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}A customer’s session, an API token, or no bearer at all — not staff, and not the ADMIN_TOKEN (code: ADMIN_REQUIRED).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}No such person, or it is not visible to this session.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}That person is staff (code: STAFF_CANNOT_BE_DELETED), or the only owner of an open org (code: SOLE_OWNER, naming each in orgs).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}