Compliance

Erase my personal data (GDPR Art. 17)

Anonymizes the subject's PII, revokes sessions/tokens, and anonymizes (never hard-deletes) financial/legal-retention records. Idempotent and self-scoped. Requires re-proving your current password (skipped only for OAuth-only accounts with no password set) and, if 2FA is enabled, a fresh TOTP code - the same step-up re-authentication already required by the less-destructive `PATCH /api/users/password` and `POST /api/users/2fa/disable`.

AuthBearer (JWT)
GroupCompliance
Rate limitSee Rate Limits
POST/api/gdpr/erase

SDK setup

Create a client and set credentials (JWT and/or API key) before calling the API. Match the authentication type shown above.

import { Configuration, ComplianceApi } from 'mudbase-sdk';

const configuration = new Configuration({
  basePath: 'https://cloud.mudbase.dev',
  accessToken: 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfbW9yZ2FuX2RlIiwiZW1haWwiOiJtb3JnYW4uY2hlbkBub3J0aHdpbmQuZGV2IiwiZXhwIjoxODI1MTI5NjAwfQ.doc_preview_sig',
});

const compliance = new ComplianceApi(configuration);
import { Configuration, ComplianceApi } from 'mudbase-sdk';

const configuration = new Configuration({
  basePath: 'https://cloud.mudbase.dev',
  accessToken: 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfbW9yZ2FuX2RlIiwiZW1haWwiOiJtb3JnYW4uY2hlbkBub3J0aHdpbmQuZGV2IiwiZXhwIjoxODI1MTI5NjAwfQ.doc_preview_sig',
});

const compliance = new ComplianceApi(configuration);

Example request

Call this endpoint using the client from SDK setup. Use View HTTP for a raw cURL example.

const { data: result } = await compliance.request(
  {
    confirm: "interface transmit",
    currentPassword: "Str0ng_Sample_Pass!w0rd",
    totpToken: "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfZGVtbyJ9.sig_sample"
  }
);
const { data: result } = await compliance.request(
  {
    confirm: "interface transmit",
    currentPassword: "Str0ng_Sample_Pass!w0rd",
    totpToken: "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfZGVtbyJ9.sig_sample"
  }
);

Playground

live

Test this endpoint with your own credentials. Your requests will be sent to the live API.

Use the auth endpoints to obtain a JWT.

No Request Yet

Send a request to see the full inspector

Authentication

Requires JWT
Note
Include your JWT in the Authorization: Bearer YOUR_TOKEN header (user-facing apps, RBAC). View authentication guide →

Request Body

json
{
  "confirm": "DELETE",
  "currentPassword": "CurrentPassword123!",
  "totpToken": "123456"
}
{
  "confirm": "DELETE",
  "currentPassword": "CurrentPassword123!",
  "totpToken": "123456"
}

Responses

200Data anonymized (or already anonymized — idempotent)
json
{
  "success": true,
  "message": "Stylish Keyboard designed to make you stand out with lively looks",
  "data": {}
}
{
  "success": true,
  "message": "Stylish Keyboard designed to make you stand out with lively looks",
  "data": {}
}
400Confirmation field missing/not equal to "DELETE", or currentPassword/totpToken missing or invalid
401Authentication required
409Sole owner of one or more organizations - transfer or delete them first
json
{
  "error": "program back up",
  "soleOwnedOrgs": [
    "bus program"
  ]
}
{
  "error": "program back up",
  "soleOwnedOrgs": [
    "bus program"
  ]
}
429Rate limit exceeded

Errors

CodeMeaning
400Confirmation field missing/not equal to "DELETE", or currentPassword/totpToken missing or invalid
401Authentication required
409Sole owner of one or more organizations - transfer or delete them first
429Rate limit exceeded
Edit this page on GitHub