purge_synthetic_accounts
Generated automatically from the published contract sources.
Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.
A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/purge_synthetic_accounts, with a bearer credential and the action's payload as the JSON body.
Contract description
Remove synthetic accounts whole, by `accounts` or with `all: true`. Platform operator or its harness (the `synthetic_estate` grant, the `synthetic_seed_purge` grant, or `super_admin`) only. Under either synthetic grant, `accounts` names only accounts in batches the caller's own credential seeded, refused `account_outside_batches` otherwise. The `all: true` form is admitted under the stress mode to `super_admin` alone and refused `synthetic_posture_refuses` otherwise. The call creates no pending action: the accounts are the operator's own test fixtures holding no customer data. A named account that stands and is not synthetic refuses the whole call `account_not_synthetic`; under the `synthetic_seed_purge` grant it refuses `account_outside_batches`, as every id outside the caller's batches does.
Answers 202 at once with the purge id and the state `running`. The walk runs detached — every application torn down as `delete_application` tears it down, then the account removed as `delete_account` removes it, its sessions ended and its tokens revoked — and `read_synthetic_purge` reads the progress.
An account another running purge holds joins that purge; an account already gone reports zero removals; a repeat with the same `request_id` answers the same purge; `drop_metering: true` also removes the accounts' meter rows. Under the `synthetic_seed_purge` grant a repeat answers only a purge of the caller's own batches, and any other refuses `account_outside_batches`. Admitted while the platform's synthetic-account mode is not off and refused `synthetic_estate_disabled` while it is off.
Access and action metadata
{
"name": "purge_synthetic_accounts",
"resource": "account",
"tier": "reversible",
"grant": "synthetic_estate",
"switch": "synthetic_estate",
"admits": [
"synthetic_seed_purge"
],
"summary": "Remove synthetic accounts whole — the named `accounts`, or every synthetic account with `all: true`, which the `stress` mode alone admits and to `super_admin` alone, refused `synthetic_posture_refuses` otherwise — with no pending action and no browser approval: the accounts are the company's own test fixtures holding no customer data, so the tier is reversible on `set_plan_quota`'s pattern, and no tool approves a pending action. Under the `synthetic_estate` or the `synthetic_seed_purge` grant alone every named account must lie in a batch the caller's own credential seeded, refused 409 `account_outside_batches` otherwise; `super_admin` reaches every synthetic account. A named id that is a standing account and not synthetic refuses the whole request 409 `account_not_synthetic` and deletes nothing. Under the `synthetic_seed_purge` grant the scoping is read first, so every named id outside the caller's own batches refuses `account_outside_batches`, a customer's account and an id no account holds among them. The call answers 202 at once with the purge's id, the state `running`, and the accounts (`deploy`'s shape) and runs detached: per account, the deletion walk `delete_application` runs after approval for each of its applications — compute, databases, realms with their passkeys and invitations, bound areas with every partition, secrets, platform credentials, version rows and images, logs and schedule rows, the hostnames retired — then the account's own removal as `delete_account` runs it, its sessions ended and its tokens revoked; `read_synthetic_purge` reads the progress. An account another running purge holds joins that purge, the walking purge dropping the metering where either asked; an account already gone reports zero removals; a walk that stops at a failing member is rerun by a repeat purge naming the account; a purge interrupted by a restart ends `failed` with the outcome `interrupted` under the rule deploys follow, and a repeat converges. With `drop_metering: true` the accounts' meter rows are removed too, the action records standing. Admitted while the `SYNTHETIC_ESTATE` mode is not `off` and refused `synthetic_estate_disabled` ahead of every other check while it is `off`; the platform's own lifetime sweep purges an expired batch through this same walk regardless of the mode; a repeat carrying the same `request_id` answers the same purge, and under the `synthetic_seed_purge` grant only a purge of the caller's own batches, any other refused `account_outside_batches`.",
"annotations": {
"readOnlyHint": false,
"destructiveHint": true,
"openWorldHint": true
}
}
MCP catalog entry
{
"name": "purge_synthetic_accounts",
"tier": "reversible",
"scenario": "API-L0-12",
"summary": "Remove synthetic accounts whole, by `accounts` or with `all: true`. Platform operator or its harness (the `synthetic_estate` grant, the `synthetic_seed_purge` grant, or `super_admin`) only. Under either synthetic grant, `accounts` names only accounts in batches the caller's own credential seeded, refused `account_outside_batches` otherwise. The `all: true` form is admitted under the stress mode to `super_admin` alone and refused `synthetic_posture_refuses` otherwise. The call creates no pending action: the accounts are the operator's own test fixtures holding no customer data. A named account that stands and is not synthetic refuses the whole call `account_not_synthetic`; under the `synthetic_seed_purge` grant it refuses `account_outside_batches`, as every id outside the caller's batches does.\n\nAnswers 202 at once with the purge id and the state `running`. The walk runs detached — every application torn down as `delete_application` tears it down, then the account removed as `delete_account` removes it, its sessions ended and its tokens revoked — and `read_synthetic_purge` reads the progress.\n\nAn account another running purge holds joins that purge; an account already gone reports zero removals; a repeat with the same `request_id` answers the same purge; `drop_metering: true` also removes the accounts' meter rows. Under the `synthetic_seed_purge` grant a repeat answers only a purge of the caller's own batches, and any other refuses `account_outside_batches`. Admitted while the platform's synthetic-account mode is not off and refused `synthetic_estate_disabled` while it is off.",
"owners": [
"MAPI-06",
"ACS-L0-02",
"MAPI-04"
]
}
request
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object |
| / |
The synthetic account ids to remove; one of `accounts` and `all`, never both. An id that is a standing account and not synthetic refuses the whole request 409 `account_not_synthetic` and deletes nothing; an id no account row stands for is admitted and completes with zero removals. Under the `synthetic_seed_purge` grant every id outside the batches the caller's own credential seeded refuses 409 `account_outside_batches` first, whatever it names. Type: array |
| / |
Type: string |
| / |
true removes every synthetic account; one of `accounts` and `all`, never both. Type: boolean |
| / |
true also removes the accounts' meter rows after each walk — the usage events, the storage and egress call rows, the traffic and verification rollups, and the database samples — so the test leaves no trace in platform usage. The action records stand and so do the realm event log's rows. Absent or false keeps the rows. Type: boolean |
| / |
Your request identity for this call: any string you choose, matched by equality with the operator's own account and never interpreted. A repeat carrying the same value answers the same purge with `repeated: true` and starts no second one. Under the `synthetic_seed_purge` grant a value another credential's purge carries refuses `account_outside_batches`: choose another. Type: string |
response
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Answered 202 at once, before the walk starts (MAPI-04; `deploy`'s shape): the purge row and its account rows were written `running`, and the walk continues after the answer, one account after another; `read_synthetic_purge` reads its end. Refused 403 `synthetic_estate_disabled` ahead of every other check while the `SYNTHETIC_ESTATE` setting is off, and 409 `account_not_synthetic` where a named id is a standing account that is not synthetic (MAPI-16). Under the `synthetic_seed_purge` grant such an id refuses 409 `account_outside_batches`. Type: object Required fields: ["contract_version","purge","state","accounts","repeated"] Additional properties: false |
| / |
Required value: 1 |
| / |
The purge's id, the one `read_synthetic_purge` takes. Type: string |
| / |
`running` at the answer, which precedes the work; `completed` where the call named nothing to walk; a repeat answers the standing purge's state. Type: string Allowed values: ["running","completed","failed"] |
| / |
Type: ["string","null"] |
| / |
Type: boolean |
| / |
Type: string |
| / |
Type: ["string","null"] |
| / |
The account ids the purge names, the joined ones included. Type: array |
| / |
Type: string |
| / |
The accounts another running purge already held when this one was requested, each with that purge's id: walked once, there, and read from either purge. Type: array |
| / |
Type: object Required fields: ["account","purge"] Additional properties: false |
| / |
Type: string |
| / |
Type: ["string","null"] |
| / |
Type: boolean |
| / |
Type: string |
Complete payload contract
{
"request": {
"type": "object",
"properties": {
"accounts": {
"type": "array",
"items": {
"type": "string"
},
"description": "The synthetic account ids to remove; one of `accounts` and `all`, never both. An id that is a standing account and not synthetic refuses the whole request 409 `account_not_synthetic` and deletes nothing; an id no account row stands for is admitted and completes with zero removals. Under the `synthetic_seed_purge` grant every id outside the batches the caller's own credential seeded refuses 409 `account_outside_batches` first, whatever it names."
},
"all": {
"type": "boolean",
"description": "true removes every synthetic account; one of `accounts` and `all`, never both."
},
"drop_metering": {
"type": "boolean",
"description": "true also removes the accounts' meter rows after each walk — the usage events, the storage and egress call rows, the traffic and verification rollups, and the database samples — so the test leaves no trace in platform usage. The action records stand and so do the realm event log's rows. Absent or false keeps the rows."
},
"request_id": {
"type": "string",
"description": "Your request identity for this call: any string you choose, matched by equality with the operator's own account and never interpreted. A repeat carrying the same value answers the same purge with `repeated: true` and starts no second one. Under the `synthetic_seed_purge` grant a value another credential's purge carries refuses `account_outside_batches`: choose another."
}
}
},
"response": {
"type": "object",
"required": [
"contract_version",
"purge",
"state",
"accounts",
"repeated"
],
"properties": {
"contract_version": {
"const": 1
},
"purge": {
"type": "string",
"description": "The purge's id, the one `read_synthetic_purge` takes."
},
"state": {
"type": "string",
"enum": [
"running",
"completed",
"failed"
],
"description": "`running` at the answer, which precedes the work; `completed` where the call named nothing to walk; a repeat answers the standing purge's state."
},
"outcome": {
"type": [
"string",
"null"
]
},
"drop_metering": {
"type": "boolean"
},
"requested_at": {
"type": "string"
},
"ended_at": {
"type": [
"string",
"null"
]
},
"accounts": {
"type": "array",
"items": {
"type": "string"
},
"description": "The account ids the purge names, the joined ones included."
},
"joined": {
"type": "array",
"items": {
"type": "object",
"required": [
"account",
"purge"
],
"properties": {
"account": {
"type": "string"
},
"purge": {
"type": [
"string",
"null"
]
}
},
"additionalProperties": false
},
"description": "The accounts another running purge already held when this one was requested, each with that purge's id: walked once, there, and read from either purge."
},
"repeated": {
"type": "boolean"
},
"detail": {
"type": "string"
}
},
"additionalProperties": false,
"description": "Answered 202 at once, before the walk starts (MAPI-04; `deploy`'s shape): the purge row and its account rows were written `running`, and the walk continues after the answer, one account after another; `read_synthetic_purge` reads its end. Refused 403 `synthetic_estate_disabled` ahead of every other check while the `SYNTHETIC_ESTATE` setting is off, and 409 `account_not_synthetic` where a named id is a standing account that is not synthetic (MAPI-16). Under the `synthetic_seed_purge` grant such an id refuses 409 `account_outside_batches`."
}
}
Shared contracts
- Refusals: every refusal, by surface, with its cause and its remedy
- schemas/wire_error.schema.json
- schemas/wire_errors.json
- schemas/action_payloads.json (includes shared shapes)
- management_api_contract.md