purge_synthetic_accounts

Generated automatically from the published contract sources.

Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.

A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/purge_synthetic_accounts, with a bearer credential and the action's payload as the JSON body.

Contract description

Remove synthetic accounts whole, by `accounts` or with `all: true`. Platform operator or its harness (the `synthetic_estate` grant, the `synthetic_seed_purge` grant, or `super_admin`) only. Under either synthetic grant, `accounts` names only accounts in batches the caller's own credential seeded, refused `account_outside_batches` otherwise. The `all: true` form is admitted under the stress mode to `super_admin` alone and refused `synthetic_posture_refuses` otherwise. The call creates no pending action: the accounts are the operator's own test fixtures holding no customer data. A named account that stands and is not synthetic refuses the whole call `account_not_synthetic`; under the `synthetic_seed_purge` grant it refuses `account_outside_batches`, as every id outside the caller's batches does.

Answers 202 at once with the purge id and the state `running`. The walk runs detached — every application torn down as `delete_application` tears it down, then the account removed as `delete_account` removes it, its sessions ended and its tokens revoked — and `read_synthetic_purge` reads the progress.

An account another running purge holds joins that purge; an account already gone reports zero removals; a repeat with the same `request_id` answers the same purge; `drop_metering: true` also removes the accounts' meter rows. Under the `synthetic_seed_purge` grant a repeat answers only a purge of the caller's own batches, and any other refuses `account_outside_batches`. Admitted while the platform's synthetic-account mode is not off and refused `synthetic_estate_disabled` while it is off.

Access and action metadata

{
  "name": "purge_synthetic_accounts",
  "resource": "account",
  "tier": "reversible",
  "grant": "synthetic_estate",
  "switch": "synthetic_estate",
  "admits": [
    "synthetic_seed_purge"
  ],
  "summary": "Remove synthetic accounts whole — the named `accounts`, or every synthetic account with `all: true`, which the `stress` mode alone admits and to `super_admin` alone, refused `synthetic_posture_refuses` otherwise — with no pending action and no browser approval: the accounts are the company's own test fixtures holding no customer data, so the tier is reversible on `set_plan_quota`'s pattern, and no tool approves a pending action. Under the `synthetic_estate` or the `synthetic_seed_purge` grant alone every named account must lie in a batch the caller's own credential seeded, refused 409 `account_outside_batches` otherwise; `super_admin` reaches every synthetic account. A named id that is a standing account and not synthetic refuses the whole request 409 `account_not_synthetic` and deletes nothing. Under the `synthetic_seed_purge` grant the scoping is read first, so every named id outside the caller's own batches refuses `account_outside_batches`, a customer's account and an id no account holds among them. The call answers 202 at once with the purge's id, the state `running`, and the accounts (`deploy`'s shape) and runs detached: per account, the deletion walk `delete_application` runs after approval for each of its applications — compute, databases, realms with their passkeys and invitations, bound areas with every partition, secrets, platform credentials, version rows and images, logs and schedule rows, the hostnames retired — then the account's own removal as `delete_account` runs it, its sessions ended and its tokens revoked; `read_synthetic_purge` reads the progress. An account another running purge holds joins that purge, the walking purge dropping the metering where either asked; an account already gone reports zero removals; a walk that stops at a failing member is rerun by a repeat purge naming the account; a purge interrupted by a restart ends `failed` with the outcome `interrupted` under the rule deploys follow, and a repeat converges. With `drop_metering: true` the accounts' meter rows are removed too, the action records standing. Admitted while the `SYNTHETIC_ESTATE` mode is not `off` and refused `synthetic_estate_disabled` ahead of every other check while it is `off`; the platform's own lifetime sweep purges an expired batch through this same walk regardless of the mode; a repeat carrying the same `request_id` answers the same purge, and under the `synthetic_seed_purge` grant only a purge of the caller's own batches, any other refused `account_outside_batches`.",
  "annotations": {
    "readOnlyHint": false,
    "destructiveHint": true,
    "openWorldHint": true
  }
}

MCP catalog entry

{
  "name": "purge_synthetic_accounts",
  "tier": "reversible",
  "scenario": "API-L0-12",
  "summary": "Remove synthetic accounts whole, by `accounts` or with `all: true`. Platform operator or its harness (the `synthetic_estate` grant, the `synthetic_seed_purge` grant, or `super_admin`) only. Under either synthetic grant, `accounts` names only accounts in batches the caller's own credential seeded, refused `account_outside_batches` otherwise. The `all: true` form is admitted under the stress mode to `super_admin` alone and refused `synthetic_posture_refuses` otherwise. The call creates no pending action: the accounts are the operator's own test fixtures holding no customer data. A named account that stands and is not synthetic refuses the whole call `account_not_synthetic`; under the `synthetic_seed_purge` grant it refuses `account_outside_batches`, as every id outside the caller's batches does.\n\nAnswers 202 at once with the purge id and the state `running`. The walk runs detached — every application torn down as `delete_application` tears it down, then the account removed as `delete_account` removes it, its sessions ended and its tokens revoked — and `read_synthetic_purge` reads the progress.\n\nAn account another running purge holds joins that purge; an account already gone reports zero removals; a repeat with the same `request_id` answers the same purge; `drop_metering: true` also removes the accounts' meter rows. Under the `synthetic_seed_purge` grant a repeat answers only a purge of the caller's own batches, and any other refuses `account_outside_batches`. Admitted while the platform's synthetic-account mode is not off and refused `synthetic_estate_disabled` while it is off.",
  "owners": [
    "MAPI-06",
    "ACS-L0-02",
    "MAPI-04"
  ]
}

request

JSON pointer Description and constraints
"" (root) Type: object
/properties/accounts The synthetic account ids to remove; one of `accounts` and `all`, never both. An id that is a standing account and not synthetic refuses the whole request 409 `account_not_synthetic` and deletes nothing; an id no account row stands for is admitted and completes with zero removals. Under the `synthetic_seed_purge` grant every id outside the batches the caller's own credential seeded refuses 409 `account_outside_batches` first, whatever it names.

Type: array
/properties/accounts/items Type: string
/properties/all true removes every synthetic account; one of `accounts` and `all`, never both.

Type: boolean
/properties/drop_metering true also removes the accounts' meter rows after each walk — the usage events, the storage and egress call rows, the traffic and verification rollups, and the database samples — so the test leaves no trace in platform usage. The action records stand and so do the realm event log's rows. Absent or false keeps the rows.

Type: boolean
/properties/request_id Your request identity for this call: any string you choose, matched by equality with the operator's own account and never interpreted. A repeat carrying the same value answers the same purge with `repeated: true` and starts no second one. Under the `synthetic_seed_purge` grant a value another credential's purge carries refuses `account_outside_batches`: choose another.

Type: string

response

JSON pointer Description and constraints
"" (root) Answered 202 at once, before the walk starts (MAPI-04; `deploy`'s shape): the purge row and its account rows were written `running`, and the walk continues after the answer, one account after another; `read_synthetic_purge` reads its end. Refused 403 `synthetic_estate_disabled` ahead of every other check while the `SYNTHETIC_ESTATE` setting is off, and 409 `account_not_synthetic` where a named id is a standing account that is not synthetic (MAPI-16). Under the `synthetic_seed_purge` grant such an id refuses 409 `account_outside_batches`.

Type: object
Required fields: ["contract_version","purge","state","accounts","repeated"]
Additional properties: false
/properties/contract_version Required value: 1
/properties/purge The purge's id, the one `read_synthetic_purge` takes.

Type: string
/properties/state `running` at the answer, which precedes the work; `completed` where the call named nothing to walk; a repeat answers the standing purge's state.

Type: string
Allowed values: ["running","completed","failed"]
/properties/outcome Type: ["string","null"]
/properties/drop_metering Type: boolean
/properties/requested_at Type: string
/properties/ended_at Type: ["string","null"]
/properties/accounts The account ids the purge names, the joined ones included.

Type: array
/properties/accounts/items Type: string
/properties/joined The accounts another running purge already held when this one was requested, each with that purge's id: walked once, there, and read from either purge.

Type: array
/properties/joined/items Type: object
Required fields: ["account","purge"]
Additional properties: false
/properties/joined/items/properties/account Type: string
/properties/joined/items/properties/purge Type: ["string","null"]
/properties/repeated Type: boolean
/properties/detail Type: string

Complete payload contract

{
  "request": {
    "type": "object",
    "properties": {
      "accounts": {
        "type": "array",
        "items": {
          "type": "string"
        },
        "description": "The synthetic account ids to remove; one of `accounts` and `all`, never both. An id that is a standing account and not synthetic refuses the whole request 409 `account_not_synthetic` and deletes nothing; an id no account row stands for is admitted and completes with zero removals. Under the `synthetic_seed_purge` grant every id outside the batches the caller's own credential seeded refuses 409 `account_outside_batches` first, whatever it names."
      },
      "all": {
        "type": "boolean",
        "description": "true removes every synthetic account; one of `accounts` and `all`, never both."
      },
      "drop_metering": {
        "type": "boolean",
        "description": "true also removes the accounts' meter rows after each walk — the usage events, the storage and egress call rows, the traffic and verification rollups, and the database samples — so the test leaves no trace in platform usage. The action records stand and so do the realm event log's rows. Absent or false keeps the rows."
      },
      "request_id": {
        "type": "string",
        "description": "Your request identity for this call: any string you choose, matched by equality with the operator's own account and never interpreted. A repeat carrying the same value answers the same purge with `repeated: true` and starts no second one. Under the `synthetic_seed_purge` grant a value another credential's purge carries refuses `account_outside_batches`: choose another."
      }
    }
  },
  "response": {
    "type": "object",
    "required": [
      "contract_version",
      "purge",
      "state",
      "accounts",
      "repeated"
    ],
    "properties": {
      "contract_version": {
        "const": 1
      },
      "purge": {
        "type": "string",
        "description": "The purge's id, the one `read_synthetic_purge` takes."
      },
      "state": {
        "type": "string",
        "enum": [
          "running",
          "completed",
          "failed"
        ],
        "description": "`running` at the answer, which precedes the work; `completed` where the call named nothing to walk; a repeat answers the standing purge's state."
      },
      "outcome": {
        "type": [
          "string",
          "null"
        ]
      },
      "drop_metering": {
        "type": "boolean"
      },
      "requested_at": {
        "type": "string"
      },
      "ended_at": {
        "type": [
          "string",
          "null"
        ]
      },
      "accounts": {
        "type": "array",
        "items": {
          "type": "string"
        },
        "description": "The account ids the purge names, the joined ones included."
      },
      "joined": {
        "type": "array",
        "items": {
          "type": "object",
          "required": [
            "account",
            "purge"
          ],
          "properties": {
            "account": {
              "type": "string"
            },
            "purge": {
              "type": [
                "string",
                "null"
              ]
            }
          },
          "additionalProperties": false
        },
        "description": "The accounts another running purge already held when this one was requested, each with that purge's id: walked once, there, and read from either purge."
      },
      "repeated": {
        "type": "boolean"
      },
      "detail": {
        "type": "string"
      }
    },
    "additionalProperties": false,
    "description": "Answered 202 at once, before the walk starts (MAPI-04; `deploy`'s shape): the purge row and its account rows were written `running`, and the walk continues after the answer, one account after another; `read_synthetic_purge` reads its end. Refused 403 `synthetic_estate_disabled` ahead of every other check while the `SYNTHETIC_ESTATE` setting is off, and 409 `account_not_synthetic` where a named id is a standing account that is not synthetic (MAPI-16). Under the `synthetic_seed_purge` grant such an id refuses 409 `account_outside_batches`."
  }
}

Shared contracts