Skip to content

Delete somebody’s account

POST
/staff/people/{id}/delete
curl --request POST \
--url https://api.sloose.com/staff/people/c1d2e3f4/delete \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "reason": "example" }'

Backoffice route: a staff session, or ADMIN_TOKEN. What POST /auth/account/delete does for the person themselves, for somebody who asked by email: every session, sign-in, factor and membership they hold goes, their own connections are revoked (asked of Zoho, whose refusal is named in warnings), and what they did for an org stays as the org’s record under “a deleted person”. The address is freed and is sent one message saying it is done. A banned person can be deleted — that is the one thing they cannot do for themselves — and the ban goes with the account, since the address is freed and nothing is left for it to stop; a staff member cannot: take the role away first. Once deleted, the person is not found by any tool here. Refused while they are the only owner of an open org. Written down as user.delete, with the reason.

id
required

The person

string
Example
c1d2e3f4

The person

Media typeapplication/json
object
reason
required

Why — the request that asked for it, usually. Required; it goes on the record.

string
>= 1 characters <= 500 characters
Examplegenerated
{
"reason": "example"
}

Deleted.

Media typeapplication/json
object
sessionsEnded
required

Browsers signed out, as sessions/revoke counts them: a CRM tab’s own session is its browser’s.

integer
warnings
required

What could not be done at Zoho — a connection whose grant Zoho would not revoke. The account is deleted regardless.

Array<string>
mailed
required

The message saying it is done was accepted for delivery. False when it was not — the account is deleted regardless, and nothing can send it again.

boolean
Examplegenerated
{
"sessionsEnded": 1,
"warnings": [
"example"
],
"mailed": true
}

The request — its body or its query — did not match the schema. issues carries the Zod issue list.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

A bearer that is neither the token nor a live session (code: AUTH_REQUIRED).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

A customer’s session, an API token, or no bearer at all — not staff, and not the ADMIN_TOKEN (code: ADMIN_REQUIRED).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

No such person, or it is not visible to this session.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

That person is staff (code: STAFF_CANNOT_BE_DELETED), or the only owner of an open org (code: SOLE_OWNER, naming each in orgs).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

Report a problem with this page