1. Docs
  2. API Reference
  3. Erase an identity (GDPR/CCPA right to be forgotten)

Erase an identity (GDPR/CCPA right to be forgotten)

POST/portal/v1/accounts/{accountSlug}/identities/{id}/erase

Irreversible GDPR/CCPA erasure ("right to be forgotten") for one identity. In a single transaction it overwrites every direct identifier (email becomes a non-routable .invalid tombstone, name/avatar/external id/metadata cleared), destroys all credentials and MFA factors/recovery codes/trusted devices, severs federation, revokes every session and pending invite, deactivates all EnvironmentMemberships, drops all role assignments, and anonymizes historical audit rows that reference the identity. Idempotent — erasing an already-erased identity is a no-op — and returns 204.

Authentication

Bearer TokenAuthorization

JWT access token. Never send alongside X-API-Key: a request carrying both is refused.

Requires capability identities.manageIdentities

Manage end-user identities across the account. Granted through an administrator role in the Admin Workspace; a valid token without it is refused with 403.

Path Parameters

idstring Required

Responses

Irreversibly wipes the identity's personal data — email, name, IdP subject, credentials, MFA secrets — revokes all sessions and pending invites, and removes access in every Environment. Historical audit rows referencing the identity are anonymized in place (label snapshots + email-bearing metadata removed) while keeping the event and id. A pseudonymous tombstone row remains so audit history keeps its references. Distinct from deactivation (`is_active = false`), which retains the data and is reversible. Idempotent; writes an Account-tier audit row carrying only the identity id.

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

application/json

  • errorApiErrorBodyDto*

Errors

When the request can't be completed, the response body includes a stable error code you can branch on.

403account.capability_requiredForbidden
When it happens

The signed-in user's administrator roles do not grant the capability this endpoint requires.

Remediation

Ask an account administrator to grant a role carrying the capability named in the Authentication section, then retry.

Request
curl -X POST "https://auth.canopy-io.com/portal/v1/accounts/{accountSlug}/identities/value/erase" \
  -H "Authorization: Bearer $CANOPY_TOKEN"
Response
HTTP/1.1 204 Irreversibly wipes the identity's personal data — email, name, IdP subject, credentials, MFA secrets — revokes all sessions and pending invites, and removes access in every Environment. Historical audit rows referencing the identity are anonymized in place (label snapshots + email-bearing metadata removed) while keeping the event and id. A pseudonymous tombstone row remains so audit history keeps its references. Distinct from deactivation (`is_active = false`), which retains the data and is reversible. Idempotent; writes an Account-tier audit row carrying only the identity id.

(empty body)
Related endpoints
GETList identities in Account
POSTCreate an Account identity
POSTBulk-create Account identities
GETGet directory counts for the Account
GETGet an Account identity
PATCHUpdate an Account identity profile
PATCHSet Account-wide is_active flag
POSTAdmin-trigger a password reset email
POSTRe-send email verification
POSTRevoke all active sessions for an identity
GETList audit events for an Account identity
POSTAdd an identity to an Environment (create EnvironmentMembership)
POSTBulk-attach EnvironmentMemberships for the Add-from-directory picker
DELETERemove an identity from an Environment (revoke EnvironmentMembership)
Was this page helpful?

Tell us how we can improve this guide.