curl --request POST \
--url https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/admin/user-deletion \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"user_id": "user-123"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({user_id: 'user-123'})
};
fetch('https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/admin/user-deletion', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/admin/user-deletion"
payload = { "user_id": "user-123" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"dry_run": false,
"user_id": "user-123",
"conversations_anonymized": 12,
"agents_transferred": 1,
"shares_deleted": 2,
"ratings_deleted": 3,
"access_requests_deleted": 0,
"agent_bindings_deleted": 4,
"tasks_archive_deleted": 5,
"memories_deleted": 6,
"storage_files_deleted": 2,
"storage_vector_stores_deleted": 1,
"insights_deleted": 7,
"errors": []
}{
"error": "<string>",
"message": "<string>",
"code": "<string>",
"status": 123
}{
"error": "<string>",
"message": "<string>",
"code": "<string>",
"status": 123
}{
"error": "Platform admin access required",
"code": "FORBIDDEN",
"status": 403
}{
"error": "<string>",
"message": "<string>",
"code": "<string>",
"status": 123
}{
"error": "<string>",
"message": "<string>",
"code": "<string>",
"status": 123
}Delete a user's data (GDPR erasure)
Erases a user’s data across the platform: anonymizes their
conversations, transfers ownership of their agents to the calling
admin, deletes their shares, ratings, access requests, access
bindings, tasks and artifacts, then asks the Tools Memories, Knowledges
and AI Insights workspaces to delete their data. Each step is best
effort: failures are reported in errors and do not stop the run.
Requires a platform administrator session (platformRole superadmin
or root); other callers get 403. Rate limited to 10 calls per hour
per admin. With dry_run: true, nothing is deleted and the counts
preview what would be affected (cross-workspace counts stay at 0).
curl --request POST \
--url https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/admin/user-deletion \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"user_id": "user-123"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({user_id: 'user-123'})
};
fetch('https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/admin/user-deletion', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://{host}/v2/workspaces/slug:agent-factory/webhooks/v1/admin/user-deletion"
payload = { "user_id": "user-123" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"dry_run": false,
"user_id": "user-123",
"conversations_anonymized": 12,
"agents_transferred": 1,
"shares_deleted": 2,
"ratings_deleted": 3,
"access_requests_deleted": 0,
"agent_bindings_deleted": 4,
"tasks_archive_deleted": 5,
"memories_deleted": 6,
"storage_files_deleted": 2,
"storage_vector_stores_deleted": 1,
"insights_deleted": 7,
"errors": []
}{
"error": "<string>",
"message": "<string>",
"code": "<string>",
"status": 123
}{
"error": "<string>",
"message": "<string>",
"code": "<string>",
"status": 123
}{
"error": "Platform admin access required",
"code": "FORBIDDEN",
"status": 403
}{
"error": "<string>",
"message": "<string>",
"code": "<string>",
"status": 123
}{
"error": "<string>",
"message": "<string>",
"code": "<string>",
"status": 123
}Authorizations
User-bound credential carrying an identity: either a session JWT
or a user access token (at:*) generated from the user settings UI.
Send as Authorization: Bearer <token>.
Org API keys (iak_*) are not accepted here - they carry
no user identity. Use the x-prismeai-api-key header instead
(see OrgApiKeyAuth).
Body
Response
Deletion (or dry-run preview) report.
Was this page helpful?