## POST /api/v2/me/actions/close-account

**Close the account**

Permanently close the authenticated account. Only an account that holds nothing can be closed; check `GET /api/v2/me/actions/close-account` first. Closing stops all sign-in, revokes every session, API key and linked sign-in method, removes the personal details on the account, and closes open support tickets (abuse cases stay open). Invoices that were already issued are kept. A confirmation is sent to the address the account had. This cannot be undone. Requires a step-up: the current password, or, for account owners verified with BankID, a one-time BankID confirmation started from the account settings page (browser session only; the confirmation is held server-side and consumed on use). API keys, contacts and delegated sessions cannot use this operation.

### Related Endpoints

- `GET /api/v2/me/actions/close-account`: Check whether the account can be closed
- `GET /api/v2/me`: Get current account profile
- `PATCH /api/v2/me`: Update current account profile

### Headers

- `Accept`: application/json
- `Authorization`: Bearer YOUR_API_KEY
- Required API scope: `write:account`
- `Content-Type`: application/json

### Request Body

- `currentPassword` (string, optional): Required, unless the browser session holds a fresh one-time BankID confirmation. When it is omitted without that confirmation, the request fails with `invalid_request`; an expired or already-used confirmation fails with 401 `bankid_verification_required`.

### Request Examples

#### Close using the current password

```bash
curl -X POST "https://cloud.hostup.se/api/v2/me/actions/close-account" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{
    "currentPassword": "current-account-password"
  }'
```

```json
{
  "currentPassword": "current-account-password"
}
```

### Response Schema

- `closedAt` (string, required): When the account was closed.

### Responses

#### 200 - The account is closed and every session on it is revoked, including the caller's.
```json
{
  "closedAt": "2026-10-06T12:00:00.000Z"
}
```

#### 400 - The body is not a JSON object, or `currentPassword` is missing without a BankID confirmation (`invalid_request`).

#### 401 - Authentication failed, the current password is incorrect (`invalid_credentials`), or the session's BankID confirmation is expired or already used (`bankid_verification_required`).

#### 403 - The authenticated identity is not allowed to close the account (API key, contact or delegated session).

#### 404 - Not found. The resource does not exist or is not owned by the caller.
```json
{
  "type": "https://developer.hostup.se/errors/not_found",
  "title": "Not found",
  "status": 404,
  "detail": "The requested resource could not be found.",
  "code": "not_found",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 409 - Something is still on the account (`account_closure_blocked`); the response carries the same fields as the eligibility read, so `blockers` says what to resolve. Or the account is not active (`account_inactive`). Nothing was changed.

#### 429 - Rate limited. Retry after the limit resets. 429 responses include `Retry-After` seconds plus `X-RateLimit-*` headers.
```json
{
  "type": "https://developer.hostup.se/errors/rate_limit_exceeded",
  "title": "Too many requests",
  "status": 429,
  "detail": "Too many requests. Retry after the limit resets.",
  "code": "rate_limit_exceeded",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 500 - Internal error. Retry later or contact support if the issue persists.
```json
{
  "type": "https://developer.hostup.se/errors/internal_error",
  "title": "Internal server error",
  "status": 500,
  "detail": "An unexpected error occurred. Retry later or contact support if the issue persists.",
  "code": "internal_error",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 502 - The account could not be checked or closed right now (`upstream_failed`). Nothing was changed; retry later.

#### 503 - Another change to the account's sign-in details is in progress (`service_unavailable`). Retry shortly.
