Skip to main content

Delete user

MethodPath
DELETE/v1/slim/user/:profileType/:profileId

Authentication · Access policies

Removes a practitioner from a project: deletes their membership and practitioner profile, and their user account when this was their last membership. Use it to offboard a team member.

Auth: Bearer token for a practitioner, project admin or System Owner session. The caller's access policy must grant Practitioner:delete (project admins skip this check). Scope: The practitioner's project must be the caller's project (from the token) or a direct child of it.

Behaviour​

  • profileType must be Practitioner and profileId a UUID.
  • The membership, the practitioner and, when it has no other membership, the user are deleted together or not at all.
  • The owner of the caller's own project cannot be deleted. The owner of a child project can.
  • After the delete, an account-deletion email is sent to the user's email address, if they have one. A failed email does not fail the request.
  • Returns { "success": true }.

Example​

curl -X DELETE 'https://api.sandbox.ovok.com/v1/slim/user/Practitioner/3f1c2b7e-8d4a-4c1e-9b2f-6a7d5e4c3b21' \
-H "Authorization: Bearer ${OVOK_TOKEN}"

Successful response​

200 — User deleted successfully.

Errors​

StatusMeaning
401The bearer token is missing or invalid.
403The session is not a practitioner, admin or System Owner session, its access policy lacks Practitioner:delete, the practitioner is outside the caller's project and its direct children, or the practitioner owns the caller's project.
404No account matches the profile.
409Another change to the same account is in progress.
422profileType or profileId fails validation.