> ## Documentation Index
> Fetch the complete documentation index at: https://cadenya.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Erase a tenant

> Destroy a tenant, its subjects, every objective it ever ran, and its widget sessions. Irreversible.

This destroys the tenant, its subjects, every objective associated with it plus everything reachable from those objectives, and its widget sessions. Erasure is terminal: once it starts, nothing comes back. This is the endpoint for a customer offboarding or a "delete my data" request.

<CodeGroup>
  ```typescript TypeScript theme={null}
  const tenant = await client.tenants.delete('external_id:acme-corp', { workspaceId });

  console.log(tenant.state);
  // STATE_ERASING
  ```

  ```go Go theme={null}
  tenant, err := client.Tenants.Delete(ctx, "external_id:acme-corp",
  	cadenya.TenantDeleteParams{WorkspaceID: cadenya.String(workspaceID)})
  if err != nil {
  	panic(err.Error())
  }
  fmt.Println(tenant.State)
  // STATE_ERASING
  ```

  ```ruby Ruby theme={null}
  tenant = cadenya.tenants.delete("external_id:acme-corp", workspace_id: workspace_id)

  puts tenant.state
  # STATE_ERASING
  ```

  ```bash cURL theme={null}
  curl -X DELETE "https://api.cadenya.com/v1/workspaces/${WORKSPACE_ID}/tenants/external_id:acme-corp" \
    -H "Authorization: Bearer ${CADENYA_API_KEY}"
  ```
</CodeGroup>

## The work runs in the background

A large tenant's history cannot be destroyed inside one request, so the response is the tenant in `STATE_ERASING`, not a count of what was removed. To follow it, poll [Get a tenant](/docs/api-reference/tenantservice/get-a-tenant-by-id): `STATE_ERASING` while it runs, `NotFound` once it finishes.

```typescript theme={null}
let gone = false;
while (!gone) {
  try {
    await client.tenants.retrieve(tenantId, { workspaceId });
    await new Promise((r) => setTimeout(r, 5000));
  } catch (err) {
    if (err instanceof Cadenya.NotFoundError) gone = true; // erasure finished
    else throw err;
  }
}
```

## Wider than deleting widget sessions

[Delete all of a tenant's widget sessions](/docs/api-reference/widgetsessionservice/delete-all-of-a-tenants-widget-sessions) removes only what widget sessions created. This endpoint is the full hammer: it takes the direct API objectives too, and the tenant record itself. Reach for the narrower one when the customer is only leaving your widget, and for this one when they are leaving you.

## Size the blast radius first

`includeInfo=true` on [Get a tenant](/docs/api-reference/tenantservice/get-a-tenant-by-id) returns `subjectCount`, `objectiveCount`, and `widgetSessionCount`. That is exactly the footprint this endpoint destroys, so read it before you pull the trigger.

## Related

<CardGroup cols={2}>
  <Card title="Get a tenant" icon="magnifying-glass" href="/docs/api-reference/tenantservice/get-a-tenant-by-id">
    Poll for STATE\_ERASING, then NotFound.
  </Card>

  <Card title="Delete a tenant's widget sessions" icon="broom" href="/docs/api-reference/widgetsessionservice/delete-all-of-a-tenants-widget-sessions">
    The narrower cleanup, widget data only.
  </Card>

  <Card title="List tenants" icon="list" href="/docs/api-reference/tenantservice/list-tenants">
    Find the tenant and its counts before erasing.
  </Card>
</CardGroup>


## OpenAPI

````yaml delete /v1/workspaces/{workspaceId}/tenants/{id}
openapi: 3.1.0
info:
  title: Cadenya API
  description: API for the Cadenya Agent Runtime platform.
  version: '1.0'
servers:
  - url: https://api.cadenya.com
    description: Production server
security:
  - bearerAuth: []
tags:
  - name: AIProviderKeyService
  - name: APIKeyService
    description: |-
      Issue, rotate, disable, and revoke a workspace's API keys. Every key
       belongs to exactly one workspace; the system-managed global account key is
       managed via GlobalAPIKeyService instead.
  - name: AccountService
    description: >-
      Manage the authenticated account. Accounts are the top-level
      organizational
       unit and contain one or more workspaces.
  - name: AgentScheduleService
    description: >-
      Manage recurring schedules attached to agents. Schedules trigger
      objectives
       on a cadence defined by AgentScheduleSpec.Schedule.
  - name: AgentService
    description: >-
      Manage AI agents within a workspace. Agents define AI behavior and tool
      access.
  - name: AgentVariationService
    description: >-
      Manage variations of an agent and their tool, sub-agent, and memory layer
      assignments.
  - name: GlobalAPIKeyService
    description: |-
      Manage the account's system-provisioned global API key. The global key is
       the only key that spans every workspace; it is created by the system and
       cannot be deleted, so the surface is retrieve, rotate, and the
       disable/enable kill switch.
  - name: MemoryService
    description: >-
      Manage memory layers and their entries. Layers are named containers that
      can
       be composed into an objective's memory cascade; entries are the keyed values
       within a layer. System-managed layers (e.g., episodic layers created by the
       runtime) cannot be mutated through this API.
  - name: ModelService
    description: |-
      Manage LLM models available to a workspace. Models represent provider and
       family pairs (e.g., "anthropic/claude-sonnet-4.6"). Workspaces are seeded
       with the supported models and you can enable or disable each one.
  - name: ObjectiveEventStreamsService
  - name: ObjectiveService
  - name: ProfilesService
    description: |-
      Operations on profiles, the account-level principals (users, API keys,
       system) that authenticate against the API.
  - name: SearchService
  - name: TenantService
    description: >-
      Read and erase tenants and the subjects under them. Tenants and subjects
      are
       created by assertion — on objective creation or widget session mint — never
       directly, so this service has no create or update: it exists to enumerate what
       assertions have produced, and to destroy it on request.
  - name: ToolService
    description: >-
      Manage tool sets and the tools they contain. Tool sets group related
      tools,
       and tools define specific capabilities available to agents.

       When a tool set is managed, only API key actors can modify its tools; human
       (profile) actors cannot.
  - name: UploadService
    description: |-
      Issue short-lived presigned URLs for direct client-to-object-storage
       uploads. Created uploads can be referenced by id when creating or updating
       resources that accept binary content (e.g., MemoryEntry).
  - name: WidgetService
    description: |-
      Manage embeddable chat widgets. A widget binds an agent to a globally
       unique hostname with a per-widget origin allowlist; browsers reach it with
       session tokens minted via WidgetSessionService.
  - name: WidgetSessionService
    description: >-
      Mint and manage widget sessions. Session creation is server-to-server
      only:
       the customer's backend authenticates its visitor, asserts tenant/subject
       context, attaches any per-visitor secrets, and receives a short-lived
       bearer token the browser uses against the widget host.
  - name: WorkspaceAdminService
    description: >-
      Administer workspaces across the account: create and archive workspaces
      and
       manage their membership. These operations are account-scoped and require the
       admin role (a token whose profile holds the WorkOS admin role); they live
       under /v1/account/workspaces rather than the workspace-scoped /v1/workspaces
       tree so an admin can manage any workspace in the account, including ones they
       are not themselves a member of.
  - name: WorkspaceSecretService
  - name: WorkspaceService
    description: |-
      Manage workspaces within an account. Workspaces provide organizational
       grouping and isolation for resources such as agents, tools, and API keys.

       This is the workspace-scoped, end-user surface. Administrative operations
       (create / archive workspaces, manage members) live in WorkspaceAdminService
       under /v1/account/workspaces and require the admin role.
paths:
  /v1/workspaces/{workspaceId}/tenants/{id}:
    delete:
      tags:
        - TenantService
        - Tenants
      summary: Erase a tenant
      description: >-
        Destroys the tenant, its subjects, every objective associated with it
        and everything reachable from those objectives, and its widget sessions.
        This is the full erasure hammer, wider than `DELETE /widget_sessions`,
        which removes only what widget sessions created. The work runs in the
        background: this returns the tenant in STATE_ERASING rather than a count
        of what was removed, since a large tenant's history cannot be destroyed
        inside a request. Poll the tenant to follow it — STATE_ERASING while it
        runs, NotFound once it finishes. Erasure is terminal; a tenant cannot be
        recovered once it starts.
      operationId: TenantService_DeleteTenant
      parameters:
        - name: workspaceId
          in: path
          description: Workspace ID.
          required: true
          schema:
            type: string
            example: workspace_01HXKD2E5NQM3T9AYWCF133E3Q
        - name: id
          in: path
          description: |-
            Tenant to destroy. Accepts the canonical `tenant_…` form or the
             `external_id:<value>` form.
          required: true
          schema:
            type: string
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Tenant'
        default:
          description: Default error response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Status'
      x-codeSamples:
        - lang: JavaScript
          source: |-
            import Cadenya from '@cadenya/cadenya';

            const client = new Cadenya({
              apiKey: process.env['CADENYA_API_KEY'], // This is the default and can be omitted
            });

            const tenant = await client.tenants.delete('id', {
              workspaceId: 'workspace_01HXKD2E5NQM3T9AYWCF133E3Q',
            });

            console.log(tenant.metadata);
        - lang: Python
          source: |-
            import os
            from cadenya import Cadenya

            client = Cadenya(
                api_key=os.environ.get("CADENYA_API_KEY"),  # This is the default and can be omitted
            )
            tenant = client.tenants.delete(
                id="id",
                workspace_id="workspace_01HXKD2E5NQM3T9AYWCF133E3Q",
            )
            print(tenant.metadata)
        - lang: Go
          source: "package main\n\nimport (\n\t\"context\"\n\t\"fmt\"\n\t\"go.cadenya.com/cadenya-go\"\n\t\"go.cadenya.com/cadenya-go/option\"\n)\n\nfunc main() {\n\tclient := cadenya.NewClient(\n\t\toption.WithAPIKey(\"My API Key\"),\n\t)\n\ttenant, err := client.Tenants.Delete(\n\t\tcontext.TODO(),\n\t\t\"id\",\n\t\tcadenya.TenantDeleteParams{\n\t\t\tWorkspaceID: cadenya.String(\"workspace_01HXKD2E5NQM3T9AYWCF133E3Q\"),\n\t\t},\n\t)\n\tif err != nil {\n\t\tpanic(err.Error())\n\t}\n\tfmt.Printf(\"%+v\\n\", tenant.Metadata)\n}\n"
        - lang: Ruby
          source: >-
            require "cadenya"


            cadenya = Cadenya::Client.new(api_key: "My API Key")


            tenant = cadenya.tenants.delete("id", workspace_id:
            "workspace_01HXKD2E5NQM3T9AYWCF133E3Q")


            puts(tenant)
        - lang: CLI
          source: |-
            cadenya tenants delete \
              --api-key 'My API Key' \
              --workspace-id workspace_01HXKD2E5NQM3T9AYWCF133E3Q \
              --id id
components:
  schemas:
    Tenant:
      required:
        - metadata
        - state
      type: object
      properties:
        metadata:
          $ref: '#/components/schemas/ResourceMetadata'
        info:
          $ref: '#/components/schemas/TenantInfo'
        state:
          readOnly: true
          enum:
            - STATE_UNSPECIFIED
            - STATE_ACTIVE
            - STATE_ERASING
          type: string
          description: The current lifecycle state of the tenant. Output only.
          format: enum
      description: >-
        Tenant is the customer's organization as a readable record rather than
        an
         echo. It carries no spec: a tenant is never configured, only asserted, so
         everything about it lives in the metadata envelope — `external_id` is the key
         the customer asserted it under, `name` is the most recent name they asserted,
         and `updated_at` is therefore when the tenant was last asserted.
    Status:
      type: object
      properties:
        code:
          type: integer
          description: >-
            The status code, which should be an enum value of
            [google.rpc.Code][google.rpc.Code].
          format: int32
        message:
          type: string
          description: >-
            A developer-facing error message, which should be in English. Any
            user-facing error message should be localized and sent in the
            [google.rpc.Status.details][google.rpc.Status.details] field, or
            localized by the client.
        details:
          type: array
          items:
            $ref: '#/components/schemas/GoogleProtobufAny'
          description: >-
            A list of messages that carry the error details.  There is a common
            set of message types for APIs to use.
      description: >-
        The `Status` type defines a logical error model that is suitable for
        different programming environments, including REST APIs and RPC APIs. It
        is used by [gRPC](https://github.com/grpc). Each `Status` message
        contains three pieces of data: error code, error message, and error
        details. You can find out more about this error model and how to work
        with it in the [API Design
        Guide](https://cloud.google.com/apis/design/errors).
    ResourceMetadata:
      required:
        - id
        - accountId
        - workspaceId
        - name
        - profileId
        - createdAt
      type: object
      properties:
        id:
          readOnly: true
          type: string
          description: >-
            Unique identifier for the resource (prefixed ULID, e.g.,
            "agent_01HXK...")
        accountId:
          readOnly: true
          example: account_01HXKD2E5NQM3T9AYWCFTJHJVF
          type: string
          description: >-
            Account this resource belongs to for multi-tenant isolation
            (prefixed ULID)
        workspaceId:
          readOnly: true
          example: workspace_01HXKD2E5NQM3T9AYWCF133E3Q
          type: string
          description: >-
            Workspace this resource belongs to for organizational grouping
            (prefixed ULID)
        name:
          type: string
          description: >-
            Human-readable name for the resource (e.g., "Customer Support
            Agent", "Email Tool")
             Required for resources that users interact with directly
        externalId:
          type: string
          description: >-
            External ID for the resource (e.g., a workflow ID from an external
            system)
        labels:
          type: object
          additionalProperties:
            type: string
          description: |-
            Key-value pairs for categorization and filtering. Values are 0-63
             alphanumeric characters with "-", "_", or "." allowed between; keys
             follow the same shape and additionally accept an optional DNS-subdomain
             prefix (e.g. "cadenya.com/") of at most 253 characters.
             Examples: {"environment": "production", "team": "platform", "version": "v2"}
        profileId:
          readOnly: true
          example: profile_01HXKD2E5NQM3T9AYWCFS0AP08
          type: string
          description: ID of the actor (user or service account) that created this resource
        createdAt:
          readOnly: true
          type: string
          description: Timestamp when this resource was created
          format: date-time
        updatedAt:
          readOnly: true
          type: string
          description: Timestamp when this resource was last updated
          format: date-time
      description: >-
        Standard metadata for persistent, named resources (e.g., agents, tools,
        prompts)
    TenantInfo:
      type: object
      properties:
        subjectCount:
          readOnly: true
          type: integer
          description: Number of subjects asserted under this tenant.
          format: int32
        objectiveCount:
          readOnly: true
          type: integer
          description: >-
            Number of objectives associated with this tenant, across every
            surface —
             widget conversations and objectives created directly against the API
             alike. This is the footprint a delete would destroy, which is why it is
             worth the count query that populating `info` costs.
          format: int32
        widgetSessionCount:
          readOnly: true
          type: integer
          description: Number of widget sessions minted for this tenant that still exist.
          format: int32
      description: TenantInfo provides read-only server-derived data about a tenant.
    GoogleProtobufAny:
      type: object
      properties:
        '@type':
          type: string
          description: The type of the serialized message.
      additionalProperties: true
      description: >-
        Contains an arbitrary serialized message along with a @type that
        describes the type of the serialized message.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT

````