Erase an identity (GDPR/CCPA right to be forgotten)
/portal/v1/accounts/{accountSlug}/identities/{id}/eraseIrreversible GDPR/CCPA erasure ("right to be forgotten") for one identity. In a single transaction it overwrites every direct identifier (email becomes a non-routable .invalid tombstone, name/avatar/external id/metadata cleared), destroys all credentials and MFA factors/recovery codes/trusted devices, severs federation, revokes every session and pending invite, deactivates all EnvironmentMemberships, drops all role assignments, and anonymizes historical audit rows that reference the identity. Idempotent — erasing an already-erased identity is a no-op — and returns 204.
Authentication
AuthorizationJWT access token. Never send alongside X-API-Key: a request carrying both is refused.
identities.manageIdentitiesManage end-user identities across the account. Granted through an administrator role in the Admin Workspace; a valid token without it is refused with 403.
Path Parameters
idstring Required Responses
Irreversibly wipes the identity's personal data — email, name, IdP subject, credentials, MFA secrets — revokes all sessions and pending invites, and removes access in every Environment. Historical audit rows referencing the identity are anonymized in place (label snapshots + email-bearing metadata removed) while keeping the event and id. A pseudonymous tombstone row remains so audit history keeps its references. Distinct from deactivation (`is_active = false`), which retains the data and is reversible. Idempotent; writes an Account-tier audit row carrying only the identity id.
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
application/json
error *ApiErrorBodyDto
Errors
When the request can't be completed, the response body includes a stable error code you can branch on.
account.capability_requiredForbiddenThe signed-in user's administrator roles do not grant the capability this endpoint requires.
Ask an account administrator to grant a role carrying the capability named in the Authentication section, then retry.
curl -X POST "https://auth.canopy-io.com/portal/v1/accounts/{accountSlug}/identities/value/erase" \ -H "Authorization: Bearer $CANOPY_TOKEN"
HTTP/1.1 204 Irreversibly wipes the identity's personal data — email, name, IdP subject, credentials, MFA secrets — revokes all sessions and pending invites, and removes access in every Environment. Historical audit rows referencing the identity are anonymized in place (label snapshots + email-bearing metadata removed) while keeping the event and id. A pseudonymous tombstone row remains so audit history keeps its references. Distinct from deactivation (`is_active = false`), which retains the data and is reversible. Idempotent; writes an Account-tier audit row carrying only the identity id. (empty body)
Tell us how we can improve this guide.