# Delete User

Deactivate a user account. This is a soft-delete — data is retained but the user can no longer authenticate.

## Overview

Deleting a user sets their account status to `inactive`. Their wallets, transactions, and history are preserved for audit and compliance purposes. The user will not be able to log in after deletion.

A successful deletion returns `204 No Content` with no response body. This action should be treated as irreversible from the user's perspective — always confirm with the user before calling this endpoint.

> ⚠️ This action immediately revokes the user's ability to authenticate. Any active sessions will be invalid on the next token verification. Ensure you have confirmation from the user or admin before calling this endpoint.

### `DELETE /v1/users/{id}`

Authentication: bearer token required.

Soft-deletes a user. Account is deactivated; data is retained.

**Path parameters**

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `id` | string | yes | User UUID |

**Responses**

`204` No Content

`404` Not Found

```json
{ "detail": "User not found" }
```

## Implementation

```javascript
async function deleteUser(token, userId) {
  const res = await fetch(`https://api.aureahub.com/v1/users/${userId}`, {
    method: 'DELETE',
    headers: { 'Authorization': `Bearer ${token}` }
  });

  if (res.status === 404) throw new Error('User not found');
  if (!res.ok) throw new Error('Failed to delete user');

  // 204 No Content — no response body
  return true;
}

// Example: account deletion flow with confirmation
async function requestAccountDeletion(token, userId) {
  const confirmed = confirm('Are you sure you want to delete your account? This cannot be undone.');
  if (!confirmed) return;

  await deleteUser(token, userId);

  // Clear local tokens and redirect to homepage
  sessionStorage.removeItem('access_token');
  localStorage.removeItem('refresh_token');
  window.location.href = '/';
}
```

---

Web version: https://docs.aureahub.com/#users-delete
