Close the account

POST /api/v2/me/actions/close-account

Permanently close the authenticated account.

Only an account that holds nothing can be closed; check GET /api/v2/me/actions/close-account first.

Closing stops all sign-in, revokes every session, API key and linked sign-in method, removes the personal details on the account, and closes open support tickets (abuse cases stay open).

Invoices that were already issued are kept.

A confirmation is sent to the address the account had.

This cannot be undone.

Requires a step-up: the current password, or, for account owners verified with BankID, a one-time BankID confirmation started from the account settings page (browser session only; the confirmation is held server-side and consumed on use).

API keys, contacts and delegated sessions cannot use this operation.

Account & Access Account

Authentication

Required API scope: write:account

Authenticate with an API key in the Authorization: Bearer <token> header.

Context

Headers

Authorization Bearer <token>
Accept application/json
Content-Type application/json

Body

required
application/json
currentPassword string

Required, unless the browser session holds a fresh one-time BankID confirmation. When it is omitted without that confirmation, the request fails with invalid_request; an expired or already-used confirmation fails with 401 bankid_verification_required.

Responses

200 The account is closed and every session on it is revoked, including the caller's.
closedAt string required

When the account was closed.

400 The body is not a JSON object, or currentPassword is missing without a BankID confirmation (invalid_request).

No response body

401 Authentication failed, the current password is incorrect (invalid_credentials), or the session's BankID confirmation is expired or already used (bankid_verification_required).

No response body

403 The authenticated identity is not allowed to close the account (API key, contact or delegated session).

No response body

404 Not found. The resource does not exist or is not owned by the caller.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
409 Something is still on the account (account_closure_blocked); the response carries the same fields as the eligibility read, so blockers says what to resolve. Or the account is not active (account_inactive). Nothing was changed.

No response body

429 Rate limited. Retry after the limit resets. 429 responses include Retry-After seconds plus X-RateLimit-* headers.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
500 Internal error. Retry later or contact support if the issue persists.
type string · Example: https://developer.hostup.se/errors/invalid_request
title string · Example: Validation failed
status integer · Example: 400
detail string · Example: The request body failed validation.
code string · Example: invalid_request

Stable machine-readable code. Branch on this field, not on detail.

instance string · Example: /api/v2/orders
requestId string · Example: req_01hxa3b4c5d6e7f8g9h0j1k2m3
timestamp string · Example: 2026-04-27T12:34:56.000Z
errors array<object>

Field-level validation errors when code is invalid_request.

errors[].pointer string required · Example: /items/0/eppCode
errors[].detail string required · Example: `eppCode` is required for this transfer.
errors[].code string required · Example: missing_required
extensions object
502 The account could not be checked or closed right now (upstream_failed). Nothing was changed; retry later.

No response body

503 Another change to the account's sign-in details is in progress (service_unavailable). Retry shortly.

No response body

POST https://cloud.hostup.se/api/v2/me/actions/close-account
For AI assistants
View as Markdown
cURL
curl -X POST "https://cloud.hostup.se/api/v2/me/actions/close-account" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{
    "currentPassword": "current-account-password"
  }'
Response
{
  "closedAt": "2026-10-06T12:00:00.000Z"
}
Request Body Close using the current password
{
  "currentPassword": "current-account-password"
}