> ## Documentation Index
> Fetch the complete documentation index at: https://docs.prisme.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Delete a user's data (GDPR erasure)

> Erases a user's data across the platform: anonymizes their
conversations, transfers ownership of their agents to the calling
admin, deletes their shares, ratings, access requests, access
bindings, tasks and artifacts, then asks the Tools Memories, Knowledges
and AI Insights workspaces to delete their data. Each step is best
effort: failures are reported in `errors` and do not stop the run.

Requires a platform administrator session (`platformRole` `superadmin`
or `root`); other callers get `403`. Rate limited to 10 calls per hour
per admin. With `dry_run: true`, nothing is deleted and the counts
preview what would be affected (cross-workspace counts stay at `0`).




## OpenAPI

````yaml /api-reference/agent-factory/swagger.yml post /v1/admin/user-deletion
openapi: 3.0.3
info:
  version: 1.0.0
  title: Agent Factory API
  description: |
    Public REST API for the Agent Factory workspace - agents, conversations,
    messages, tools, artifacts, sharing, ratings, and discovery.
    Powered by Prisme.ai's runtime; all endpoints are exposed under each
    workspace's webhook namespace.
  contact:
    name: Prisme.ai
    url: https://prisme.ai
servers:
  - url: https://{host}/v2/workspaces/slug:agent-factory/webhooks
    description: Prisme.ai workspace webhooks
    variables:
      host:
        default: api.studio.prisme.ai
        description: API host (override for self-hosted or sandbox)
security:
  - BearerAuth: []
  - OrgApiKeyAuth: []
tags:
  - name: Agents
    description: Agent CRUD, discovery, AGENTS.md import/export.
  - name: Access
    description: Agent access bindings, sharing, and access requests.
  - name: ApiKeys
    description: Agent-scoped API key management (mint, revoke, rotate).
  - name: Publishing
    description: Publish or discard draft changes on an agent.
  - name: Ratings
    description: User ratings on published agents.
  - name: Profiles
    description: >-
      Agent profiles/presets catalog (simple, workflow, agent_light, agent_full,
      orchestrator).
  - name: Activity
    description: Activity feed for agents (events, errors, lifecycle changes).
  - name: Analytics
    description: Agent usage analytics (series + summary).
  - name: Conversations
    description: Conversations on an agent (CRUD, archive, star).
  - name: Messages
    description: Send messages to an agent (synchronous send + SSE stream).
  - name: Tasks
    description: Async task lifecycle (list, fetch, cancel, resolve, subscribe).
  - name: Artifacts
    description: Generated artifacts (files, code, content) attached to a task.
  - name: Shares
    description: Conversation, message, and artifact share-link snapshots.
  - name: A2A
    description: Agent-to-agent JSON-RPC 2.0 gateway (well-known agent.json + RPC).
  - name: Tools
    description: Per-agent tool catalogue (system tools, MCP servers, function tools).
  - name: Retention
    description: Per-agent and org-wide conversation retention policies.
  - name: Traces
    description: >-
      Execution traces of agent turns (editor debugging,
      `agent-factory:traces:read`).
  - name: Evaluations
    description: Agent evaluation runs and results.
  - name: Admin
    description: |
      GDPR operations called by the AI Insights admin screens. They require
      elevated permissions: the caller must be a platform administrator
      (`platformRole` `superadmin` or `root`). The export route also lets a
      user export their own data. Each route is rate limited to 10 calls per
      hour per caller.
paths:
  /v1/admin/user-deletion:
    post:
      tags:
        - Admin
      summary: Delete a user's data (GDPR erasure)
      description: |
        Erases a user's data across the platform: anonymizes their
        conversations, transfers ownership of their agents to the calling
        admin, deletes their shares, ratings, access requests, access
        bindings, tasks and artifacts, then asks the Tools Memories, Knowledges
        and AI Insights workspaces to delete their data. Each step is best
        effort: failures are reported in `errors` and do not stop the run.

        Requires a platform administrator session (`platformRole` `superadmin`
        or `root`); other callers get `403`. Rate limited to 10 calls per hour
        per admin. With `dry_run: true`, nothing is deleted and the counts
        preview what would be affected (cross-workspace counts stay at `0`).
      operationId: adminDeleteUserData
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AdminUserRequest'
            example:
              user_id: user-123
      responses:
        '200':
          description: Deletion (or dry-run preview) report.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AdminUserDeletionResult'
        '400':
          description: Missing or invalid `user_id`.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AdminError'
        '401':
          description: Authentication required.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AdminError'
        '403':
          description: The caller is not a platform administrator.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AdminError'
              example:
                error: Platform admin access required
                code: FORBIDDEN
                status: 403
        '405':
          description: Method not allowed (only POST is accepted).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AdminError'
        '429':
          description: Rate limit exceeded (10 per hour per admin).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AdminError'
      security:
        - BearerAuth: []
components:
  schemas:
    AdminUserRequest:
      type: object
      additionalProperties: false
      required:
        - user_id
      properties:
        user_id:
          type: string
          maxLength: 128
          description: Identifier of the user whose data is erased.
        dry_run:
          type: boolean
          default: false
          description: When `true`, only count what would be affected; nothing is deleted.
    AdminUserDeletionResult:
      type: object
      properties:
        dry_run:
          type: boolean
        user_id:
          type: string
        conversations_anonymized:
          type: integer
        agents_transferred:
          type: integer
        shares_deleted:
          type: integer
        ratings_deleted:
          type: integer
        access_requests_deleted:
          type: integer
        agent_bindings_deleted:
          type: integer
        tasks_archive_deleted:
          type: integer
        memories_deleted:
          type: integer
        storage_files_deleted:
          type: integer
        storage_vector_stores_deleted:
          type: integer
        insights_deleted:
          type: integer
        errors:
          type: array
          items:
            $ref: '#/components/schemas/AdminStepError'
      example:
        dry_run: false
        user_id: user-123
        conversations_anonymized: 12
        agents_transferred: 1
        shares_deleted: 2
        ratings_deleted: 3
        access_requests_deleted: 0
        agent_bindings_deleted: 4
        tasks_archive_deleted: 5
        memories_deleted: 6
        storage_files_deleted: 2
        storage_vector_stores_deleted: 1
        insights_deleted: 7
        errors: []
    AdminError:
      type: object
      description: |
        Error body of the Admin routes. Authentication failures return
        `error` + `message`; permission, validation, method and rate-limit
        failures return `error` (message text) + `code` + `status`.
      required:
        - error
      properties:
        error:
          type: string
          description: Error code (authentication failures) or human-readable message.
        message:
          type: string
          description: Human-readable message (authentication failures).
        code:
          type: string
          description: Stable error code (FORBIDDEN, VALIDATION_ERROR, METHOD_NOT_ALLOWED).
        status:
          type: integer
          description: HTTP status, repeated in the body.
    AdminStepError:
      type: object
      properties:
        step:
          type: string
          description: Step that failed (e.g. conversations, shares, storage, ai_insights).
        error:
          type: string
          description: Error message of the failed step.
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: |
        User-bound credential carrying an identity: either a session JWT
        or a user access token (`at:*`) generated from the user settings UI.
        Send as `Authorization: Bearer <token>`.
        Org API keys (`iak_*`) are **not** accepted here - they carry
        no user identity. Use the `x-prismeai-api-key` header instead
        (see `OrgApiKeyAuth`).
    OrgApiKeyAuth:
      type: apiKey
      in: header
      name: x-prismeai-api-key
      description: |
        Organization API key (`iak_{orgSlug}_{uuid}`). Unlike
        `Authorization: Bearer`, this credential is **not** tied to a user
        identity - it is bound to the org and its effective access is
        defined by the scopes / permission rules attached to it (it can
        be restricted to a single project, or kept broader).
        For Agent Factory, these keys can be generated directly from
        the Agent Factory UI (in addition to the AI Governance settings).
        Send as `x-prismeai-api-key: iak_...`.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.