Users
Delete user data (GDPR Article 17)
Request account erasure (right to be forgotten). Anonymizes PII, revokes all sessions and API keys, and disables the account immediately (not a grace period - the effect is immediate and irreversible). Accepts JWT Bearer token (OrgBearerAuth or ProjectBearerAuth - both are the same JWT token format). API keys are not supported for this endpoint. Requires re-proving your current password (skipped only for OAuth-only accounts with no password set) and, if 2FA is enabled, a fresh TOTP code - the same step-up re-authentication already required by the less-destructive `PATCH /api/users/password` and `POST /api/users/2fa/disable`.
/api/users/me/eraseSDK setup
Create a client and set credentials (JWT and/or API key) before calling the API. Match the authentication type shown above.
import { Configuration, UsersApi } from 'mudbase-sdk';
const configuration = new Configuration({
basePath: 'https://cloud.mudbase.dev',
accessToken: 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfbW9yZ2FuX2RlIiwiZW1haWwiOiJtb3JnYW4uY2hlbkBub3J0aHdpbmQuZGV2IiwiZXhwIjoxODI1MTI5NjAwfQ.doc_preview_sig',
});
const users = new UsersApi(configuration);import { Configuration, UsersApi } from 'mudbase-sdk';
const configuration = new Configuration({
basePath: 'https://cloud.mudbase.dev',
accessToken: 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfbW9yZ2FuX2RlIiwiZW1haWwiOiJtb3JnYW4uY2hlbkBub3J0aHdpbmQuZGV2IiwiZXhwIjoxODI1MTI5NjAwfQ.doc_preview_sig',
});
const users = new UsersApi(configuration);Example request
Call this endpoint using the client from SDK setup. Use View HTTP for a raw cURL example.
const { data: result } = await users.eraseUserData(
{
confirm: "array reboot",
currentPassword: "Str0ng_Sample_Pass!w0rd",
totpToken: "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfZGVtbyJ9.sig_sample"
}
);const { data: result } = await users.eraseUserData(
{
confirm: "array reboot",
currentPassword: "Str0ng_Sample_Pass!w0rd",
totpToken: "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiJ1c3JfZGVtbyJ9.sig_sample"
}
);Playground
liveTest this endpoint with your own credentials. Your requests will be sent to the live API.
No Request Yet
Send a request to see the full inspector
Authentication
Authorization: Bearer YOUR_TOKEN header (user-facing apps, RBAC). View authentication guide →Request Body
{
"confirm": "DELETE",
"currentPassword": "CurrentPassword123!",
"totpToken": "123456"
}{
"confirm": "DELETE",
"currentPassword": "CurrentPassword123!",
"totpToken": "123456"
}Responses
{
"success": true,
"message": "User data anonymized and account disabled",
"data": {
"alreadyErased": false,
"subjectId": "685acbe0e129932fbb7a0fc2",
"anonymized": true,
"sessionsRevoked": true
}
}{
"success": true,
"message": "User data anonymized and account disabled",
"data": {
"alreadyErased": false,
"subjectId": "685acbe0e129932fbb7a0fc2",
"anonymized": true,
"sessionsRevoked": true
}
}{
"error": "program back up"
}{
"error": "program back up"
}{
"error": "program back up",
"soleOwnedOrgs": [
"bus program"
]
}{
"error": "program back up",
"soleOwnedOrgs": [
"bus program"
]
}Errors
| Code | Meaning |
|---|---|
400 | Missing/invalid confirm, currentPassword, or totpToken |
401 | — |
409 | Sole owner of one or more organizations - transfer or delete them first |