delete_test_end_users
Generated automatically from the published contract sources.
Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.
A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/delete_test_end_users, with a bearer credential and the action's payload as the JSON body.
Contract description
Remove test end users from one of your application's sign-in realms at once, naming `end_users` (their ids) or `all: true`. The `environment` argument is required: `development` or `production`, the realm the call addresses; development's standing only once `create_environment` has turned development on. No pending action and no approval: a test end user holds no person's data. Each removal ends the user's sessions everywhere within the routers' sync (about thirty seconds), deletes its held codes, and ends the sign-ins they could still confirm. Refused whole `not_test_end_user`, removing nothing, where any named user is not a test end user of that realm; a real end user is removed with `delete_end_user`. Works while the platform's `TEST_END_USERS` setting is off, so you can always clean up.
Access and action metadata
{
"name": "delete_test_end_users",
"resource": "realm",
"tier": "reversible",
"summary": "Remove test end users from one realm of the calling account's own application at once, with no pending action, `application` and `environment` both required and either `end_users` or `all` true: each removal ends the user's rows, identities, and sessions, writes the user revocation row the routers sync, deletes the user's held codes, and takes the live tickets they were started under. Refused whole `not_test_end_user` where any named user is not a test end user of the realm; admitted while `TEST_END_USERS` reads `off`, so an operator's stop strands no test end user.",
"annotations": {
"readOnlyHint": false,
"destructiveHint": true,
"openWorldHint": false
}
}
MCP catalog entry
{
"name": "delete_test_end_users",
"tier": "reversible",
"summary": "Remove test end users from one of your application's sign-in realms at once, naming `end_users` (their ids) or `all: true`. The `environment` argument is required: `development` or `production`, the realm the call addresses; development's standing only once `create_environment` has turned development on. No pending action and no approval: a test end user holds no person's data. Each removal ends the user's sessions everywhere within the routers' sync (about thirty seconds), deletes its held codes, and ends the sign-ins they could still confirm. Refused whole `not_test_end_user`, removing nothing, where any named user is not a test end user of that realm; a real end user is removed with `delete_end_user`. Works while the platform's `TEST_END_USERS` setting is off, so you can always clean up.",
"owners": [
"ACS-L0-21",
"ACS-L0-06",
"PLD-L0-40"
],
"scenario": "ACS-L0-21"
}
request
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["application","environment"] Additional properties: false |
| / |
The application id, from `list_applications`; one of the calling account's own. Type: string |
| / |
Required. The environment whose realm the call addresses, `development` or `production` (the accounts service PRD's realm statement). Type: string Pattern: ^(development|production)$ |
| / |
The test end users to remove, by opaque identifier; one of `end_users` and `all` is required, and never both. Any identifier that is not a test end user of the realm refuses the whole request 409 `not_test_end_user`, and nothing is removed. Type: array Minimum items: 1 Maximum items: 20 |
| / |
Type: string |
| / |
Remove every test end user of the realm; one of `end_users` and `all` is required, and never both. Required value: true |
response
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["contract_version","realm","application","environment","removed"] Additional properties: false |
| / |
Required value: 1 |
| / |
The realm identifier: the application id for production, `<id>:development` for development. Type: string |
| / |
Type: string |
| / |
Type: string Pattern: ^(development|production)$ |
| / |
The identifiers of the test end users removed, each with its identities, sessions, held codes, and live tickets; empty where `all` found none. Type: array |
| / |
Type: string |
| / |
Type: string |
Complete payload contract
{
"request": {
"type": "object",
"required": [
"application",
"environment"
],
"properties": {
"application": {
"type": "string",
"description": "The application id, from `list_applications`; one of the calling account's own."
},
"environment": {
"type": "string",
"pattern": "^(development|production)$",
"description": "Required. The environment whose realm the call addresses, `development` or `production` (the accounts service PRD's realm statement)."
},
"end_users": {
"type": "array",
"minItems": 1,
"maxItems": 20,
"items": {
"type": "string"
},
"description": "The test end users to remove, by opaque identifier; one of `end_users` and `all` is required, and never both. Any identifier that is not a test end user of the realm refuses the whole request 409 `not_test_end_user`, and nothing is removed."
},
"all": {
"const": true,
"description": "Remove every test end user of the realm; one of `end_users` and `all` is required, and never both."
}
},
"additionalProperties": false
},
"response": {
"type": "object",
"required": [
"contract_version",
"realm",
"application",
"environment",
"removed"
],
"properties": {
"contract_version": {
"const": 1
},
"realm": {
"type": "string",
"description": "The realm identifier: the application id for production, `<id>:development` for development."
},
"application": {
"type": "string"
},
"environment": {
"type": "string",
"pattern": "^(development|production)$"
},
"removed": {
"type": "array",
"items": {
"type": "string"
},
"description": "The identifiers of the test end users removed, each with its identities, sessions, held codes, and live tickets; empty where `all` found none."
},
"detail": {
"type": "string"
}
},
"additionalProperties": false
}
}
Shared contracts
- Refusals: every refusal, by surface, with its cause and its remedy
- schemas/wire_error.schema.json
- schemas/wire_errors.json
- schemas/action_payloads.json (includes shared shapes)
- management_api_contract.md