MemorySync
API Reference

Suspend User

Suspend a user account. The handler revokes every active session, blocks new logins, and writes an audit row with the suspending actor and reason. Suspended users keep their data; reactivation restores access.
POST/api/v1/users/{user_id}/suspend

Authentication

Accepts a JWT bearer token (Authorization: Bearer eyJ…) or an API key (X-API-Key: ms_live_…). API-key callers should send X-Project-ID unless the key is project-locked. Cross-tenant operators must send X-Tenant-ID.

Path parameters

FieldTypeRequiredDescription
user_idintegerrequiredUser to suspend. Cannot be the organisation owner.

Query parameters

FieldTypeRequiredDescription
organization_idintegeroptionalOrganisation context.
actor_idintegeroptionalUser performing the action (defaults to JWT subject).

Request body

FieldTypeRequiredDescription
reasonstringrequiredStored on the audit row.
request.json
{
"reason": "policy_violation"
}

Response

Returns 200 OK with the following body.

FieldTypeRequiredDescription
user_idintegeroptionalSuspended user id.
statusstringoptionalAlways suspended.
sessions_revokedintegeroptionalNumber of sessions invalidated.
suspended_atstringoptionalRFC 3339 UTC.
200.json
{
"user_id": 4271,
"status": "suspended",
"sessions_revoked": 3,
"suspended_at": "2026-05-04T12:30:11Z"
}

Errors

StatusCodeDescription
400validation_errorBody or query failed schema validation. The error includes the offending field name.
401unauthenticatedMissing or invalid bearer token / API key.
403forbiddenAuthenticated principal lacks the required scope, role, or project access.
404not_foundTarget resource does not exist or is not visible to the calling tenant.
429rate_limitedPer-IP or per-route limit exceeded. Respect the Retry-After header.
500internal_errorUnhandled server error. Quote the request_id when contacting support.

Examples

cURL
curl -X POST https://api.memorysync.io/api/v1/users/EXAMPLE_ID/suspend \
-H "Authorization: Bearer $MEMORYSYNC_KEY" \
-H "Content-Type: application/json" \
-d '{
"reason": "policy_violation"
}'
javascript
import { MemorySync } from 'memorysync'
const client = new MemorySync({ apiKey: process.env.MEMORYSYNC_KEY })
const result = await client.request({
method: 'POST',
path: '/api/v1/users/EXAMPLE_ID/suspend',
body: {
"reason": "policy_violation"
},
})
console.log(result)
python
from memorysync import Client
client = Client(api_key=os.environ["MEMORYSYNC_KEY"])
result = client.request(
method="POST",
path="/api/v1/users/EXAMPLE_ID/suspend",
json={
"reason": "policy_violation"
},
)
print(result)

Behavior & notes

Idempotent through Idempotency-Key on writes. Replays within 24h return the original response unchanged.