delete_end_user
Generated automatically from the published contract sources.
Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.
A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/delete_end_user, with a bearer credential and the action's payload as the JSON body.
Contract description
Delete one of an application's end users — their identities, sessions, and passkeys with the user row; the realm's event log keeps its rows. Destructive: needs a credential holding the destructive class (a signed-in session, or a token minted with `destructive`); the call creates a pending action, and the deletion runs only after a person approves it in the browser. An optional `environment` (`development` or `production`; absent, `production`) names the realm the call addresses, development's standing only once `create_environment` has turned development on.
Access and action metadata
{
"name": "delete_end_user",
"resource": "realm",
"tier": "destructive",
"summary": "Remove one end user's rows through the pending action, its description rendered from the platform's own record.",
"annotations": {
"readOnlyHint": false,
"destructiveHint": true,
"openWorldHint": false
}
}
MCP catalog entry
{
"name": "delete_end_user",
"tier": "destructive",
"summary": "Delete one of an application's end users — their identities, sessions, and passkeys with the user row; the realm's event log keeps its rows. Destructive: needs a credential holding the destructive class (a signed-in session, or a token minted with `destructive`); the call creates a pending action, and the deletion runs only after a person approves it in the browser. An optional `environment` (`development` or `production`; absent, `production`) names the realm the call addresses, development's standing only once `create_environment` has turned development on.",
"owners": [
"ACS-L0-01",
"MAPI-05",
"PLD-L0-40"
],
"scenario": "ACS-L0-08"
}
request
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["application","end_user"] Additional properties: false |
| / |
The application id, from `list_applications`. Type: string |
| / |
The end user's opaque id, from `list_end_users`. Type: string |
| / |
Your request identity for this pending action: any string you choose. Repeating the call with the same request_id, from the same account, while the earlier pending action is still live — requested, approved, or executing — answers that pending action again and creates no second one. Once it has completed, failed, been declined, or expired, the same request_id starts a new one. Omitted, every call creates a new pending action. Type: string |
| / |
Optional. The environment whose realm the call addresses, `development` or `production` (the accounts service PRD's realm statement); absent, `production`. Type: string Pattern: ^(development|production)$ |
response
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | The 202 creation envelope: the pending action and its approval link (API-L0-07); the terminal outcome rides the pending record via read_pending_action. Type: object Required fields: ["contract_version","pending_action","approval_url"] |
| / |
Required value: 1 |
| / |
The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call. Type: string Pattern: ^[0-9a-f]{10}$ |
| / |
$ref: #/shapes/pending_action |
| / |
Type: string |
| / |
Type: string |
Complete payload contract
{
"request": {
"type": "object",
"required": [
"application",
"end_user"
],
"properties": {
"application": {
"type": "string",
"description": "The application id, from `list_applications`."
},
"end_user": {
"type": "string",
"description": "The end user's opaque id, from `list_end_users`."
},
"request_id": {
"type": "string",
"description": "Your request identity for this pending action: any string you choose. Repeating the call with the same request_id, from the same account, while the earlier pending action is still live — requested, approved, or executing — answers that pending action again and creates no second one. Once it has completed, failed, been declined, or expired, the same request_id starts a new one. Omitted, every call creates a new pending action."
},
"environment": {
"type": "string",
"pattern": "^(development|production)$",
"description": "Optional. The environment whose realm the call addresses, `development` or `production` (the accounts service PRD's realm statement); absent, `production`."
}
},
"additionalProperties": false
},
"response": {
"type": "object",
"description": "The 202 creation envelope: the pending action and its approval link (API-L0-07); the terminal outcome rides the pending record via read_pending_action.",
"required": [
"contract_version",
"pending_action",
"approval_url"
],
"properties": {
"contract_version": {
"const": 1
},
"reference": {
"type": "string",
"pattern": "^[0-9a-f]{10}$",
"description": "The short reference the platform recorded this call under, ten lowercase hexadecimal characters, the value the call’s record row carries; quote it when reporting the call."
},
"pending_action": {
"$ref": "#/shapes/pending_action"
},
"approval_url": {
"type": "string"
},
"detail": {
"type": "string"
}
}
}
}
Shared contracts
- Refusals: every refusal, by surface, with its cause and its remedy
- schemas/wire_error.schema.json
- schemas/wire_errors.json
- schemas/action_payloads.json (includes shared shapes)
- management_api_contract.md