API Reference
Remove User
Soft-delete a user with optional email anonymization. The handler revokes sessions, marks the row as removed, and (when
anonymize is true) replaces the email with a deterministic placeholder so the audit trail stays intact while PII is wiped.DELETE/api/v1/users/{user_id}
Authentication
Accepts a JWT bearer token (Authorization: Bearer eyJ…) or an API key (X-API-Key: ms_live_…). API-key callers should send X-Project-ID unless the key is project-locked. Cross-tenant operators must send X-Tenant-ID.
Path parameters
| Field | Type | Required | Description |
|---|---|---|---|
user_id | integer | required | User to remove. Cannot be the organisation owner. |
Query parameters
| Field | Type | Required | Description |
|---|---|---|---|
organization_id | integer | optional | Organisation context. |
actor_id | integer | optional | Actor performing the removal. |
Request body
| Field | Type | Required | Description |
|---|---|---|---|
reason | string | required | Stored on the audit row. |
anonymize | boolean | optional | Default false. When true, email becomes removed-{user_id}@anon.invalid. |
request.json
{"reason": "user_request_gdpr","anonymize": true}
Response
Returns 200 OK with the following body.
| Field | Type | Required | Description |
|---|---|---|---|
user_id | integer | optional | Removed user id. |
status | string | optional | Always removed. |
anonymized | boolean | optional | Whether email was anonymised. |
removed_at | string | optional | RFC 3339 UTC. |
200.json
{"user_id": 4271,"status": "removed","anonymized": true,"removed_at": "2026-05-04T12:30:11Z"}
Errors
| Status | Code | Description |
|---|---|---|
| 400 | validation_error | Body or query failed schema validation. The error includes the offending field name. |
| 401 | unauthenticated | Missing or invalid bearer token / API key. |
| 403 | forbidden | Authenticated principal lacks the required scope, role, or project access. |
| 404 | not_found | Target resource does not exist or is not visible to the calling tenant. |
| 429 | rate_limited | Per-IP or per-route limit exceeded. Respect the Retry-After header. |
| 500 | internal_error | Unhandled server error. Quote the request_id when contacting support. |
Examples
cURL
curl -X DELETE https://api.memorysync.io/api/v1/users/EXAMPLE_ID \-H "Authorization: Bearer $MEMORYSYNC_KEY" \-H "Content-Type: application/json" \-d '{"reason": "user_request_gdpr","anonymize": true}'
javascript
import { MemorySync } from 'memorysync'const client = new MemorySync({ apiKey: process.env.MEMORYSYNC_KEY })const result = await client.request({method: 'DELETE',path: '/api/v1/users/EXAMPLE_ID',body: {"reason": "user_request_gdpr","anonymize": true},})console.log(result)
python
from memorysync import Clientclient = Client(api_key=os.environ["MEMORYSYNC_KEY"])result = client.request(method="DELETE",path="/api/v1/users/EXAMPLE_ID",json={"reason": "user_request_gdpr","anonymize": true},)print(result)
Behavior & notes
Idempotent through Idempotency-Key on writes. Replays within 24h return the original response unchanged.