Users

Delete user data (GDPR Article 17)

Request account erasure (right to be forgotten). Anonymizes PII, revokes all sessions and API keys, and disables the account immediately (not a grace period - the effect is immediate and irreversible). Accepts JWT Bearer token (OrgBearerAuth or ProjectBearerAuth - both are the same JWT token format). API keys are not supported for this endpoint. Requires re-proving your current password (skipped only for OAuth-only accounts with no password set) and, if 2FA is enabled, a fresh TOTP code - the same step-up re-authentication already required by the less-destructive `PATCH /api/users/password` and `POST /api/users/2fa/disable`.

AuthBearer (JWT)
GroupUsers
Rate limitSee Rate Limits
POST/api/users/me/erase

SDK setup

Create a client and set credentials (JWT and/or API key) before calling the API. Match the authentication type shown above.

import { Configuration, UsersApi } from 'mudbase-sdk';

const configuration = new Configuration({
  basePath: 'https://cloud.mudbase.dev',
  accessToken: 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfbW9yZ2FuX2RlIiwiZW1haWwiOiJtb3JnYW4uY2hlbkBub3J0aHdpbmQuZGV2IiwiZXhwIjoxODI1MTI5NjAwfQ.doc_preview_sig',
});

const users = new UsersApi(configuration);
import { Configuration, UsersApi } from 'mudbase-sdk';

const configuration = new Configuration({
  basePath: 'https://cloud.mudbase.dev',
  accessToken: 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfbW9yZ2FuX2RlIiwiZW1haWwiOiJtb3JnYW4uY2hlbkBub3J0aHdpbmQuZGV2IiwiZXhwIjoxODI1MTI5NjAwfQ.doc_preview_sig',
});

const users = new UsersApi(configuration);

Example request

Call this endpoint using the client from SDK setup. Use View HTTP for a raw cURL example.

const { data: result } = await users.eraseUserData(
  {
    confirm: "array reboot",
    currentPassword: "Str0ng_Sample_Pass!w0rd",
    totpToken: "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfZGVtbyJ9.sig_sample"
  }
);
const { data: result } = await users.eraseUserData(
  {
    confirm: "array reboot",
    currentPassword: "Str0ng_Sample_Pass!w0rd",
    totpToken: "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfZGVtbyJ9.sig_sample"
  }
);

Playground

live

Test this endpoint with your own credentials. Your requests will be sent to the live API.

Use the auth endpoints to obtain a JWT.

No Request Yet

Send a request to see the full inspector

Authentication

Requires JWT
Note
Include your JWT in the Authorization: Bearer YOUR_TOKEN header (user-facing apps, RBAC). View authentication guide →

Request Body

json
{
  "confirm": "DELETE",
  "currentPassword": "CurrentPassword123!",
  "totpToken": "123456"
}
{
  "confirm": "DELETE",
  "currentPassword": "CurrentPassword123!",
  "totpToken": "123456"
}

Responses

200Account erased
json
{
  "success": true,
  "message": "User data anonymized and account disabled",
  "data": {
    "alreadyErased": false,
    "subjectId": "685acbe0e129932fbb7a0fc2",
    "anonymized": true,
    "sessionsRevoked": true
  }
}
{
  "success": true,
  "message": "User data anonymized and account disabled",
  "data": {
    "alreadyErased": false,
    "subjectId": "685acbe0e129932fbb7a0fc2",
    "anonymized": true,
    "sessionsRevoked": true
  }
}
400Missing/invalid confirm, currentPassword, or totpToken
json
{
  "error": "program back up"
}
{
  "error": "program back up"
}
401
409Sole owner of one or more organizations - transfer or delete them first
json
{
  "error": "program back up",
  "soleOwnedOrgs": [
    "bus program"
  ]
}
{
  "error": "program back up",
  "soleOwnedOrgs": [
    "bus program"
  ]
}

Errors

CodeMeaning
400Missing/invalid confirm, currentPassword, or totpToken
401
409Sole owner of one or more organizations - transfer or delete them first
Edit this page on GitHub