OUTCOME · Create or advance
What changes
Creates or advances only the account closure request resource described by this contract after authorization, validation, policy, and idempotency gates pass.
v2Identity sessions and federation
/api/v2/account-closure-requests/{request_uuid}/cancellationsPURPOSE + BUSINESS CONTEXT
WHEN THIS CALL IS USEFUL
Call this when an account holder, authentication client, security administrator, or identity-lifecycle agent needs to apply the documented account closure request transition after re-reading the current authoritative state so it can create and govern account access through explicit registration, activation, session, authenticator, recovery, and closure stages.
OUTCOME · Create or advance
Creates or advances only the account closure request resource described by this contract after authorization, validation, policy, and idempotency gates pass.
WHY IT MATTERS
ISOLATION + AUTHORITY
Tenant identity, profile, password, authenticator enrollment, recovery code, device, session, access token, refresh credential, step-up grant, and account-closure state remain distinct. Authentication proves only the admitted session and scopes; it grants no workspace role, wallet, payment, settlement, publisher, matching, or trading authority.
BEFORE YOU CALL
WHAT TO DO NEXT
AGENT GUIDANCE
The exact deployed parameters, schemas, responses, security requirements, and Hybrid-Chain agent metadata are authoritative at this operation's production OpenAPI JSON Pointer. The readable tables below add integration guidance; the deployed OpenAPI controls if guidance and the machine contract ever differ.
Open the authoritative production contract ↗EXTENDED INTEGRATION GUIDANCE
Examples illustrate integration intent; the referenced OpenAPI operation and component schemas define the executable shape.
PARAMETERS
AuthorizationheaderRequiredBearer tokenCredential containing the profile:write scope.EXAMPLEBearer hc_live_…
Idempotency-KeyheaderRequiredASCII string · 1–128Caller-generated key reused for every retry of the same logical mutation.EXAMPLElaunch-treasury-v1-001
Content-TypeheaderRequiredapplication/jsonSigned mutations accept canonical JSON only.EXAMPLEapplication/json
Content-DigestheaderRequiredRFC 9530 SHA-256 digestDigest of the exact transmitted body bytes.EXAMPLEsha-256=:47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=:
Signature-InputheaderRequiredRFC 9421 signature parametersCovers @method, @path, content-digest, content-type, and idempotency-key; includes keyid, nonce, created, and expires.EXAMPLEsig1=("@method" "@path" "content-digest" "content-type" "idempotency-key");created=1786582800;expires=1786583100;nonce="01J…";keyid="machine-prod"
SignatureheaderRequiredEd25519 HTTP Message SignatureSignature made by an active public key registered to the authenticated client.EXAMPLEsig1=:base64-signature:
request_uuidpathRequired32-character identifierAccount-closure request owned by the authenticated identity.EXAMPLE6f8d6b1165bb47ca9746897e38c31bd2
X-Request-IDheaderOptionalcorrelation identifier · max 128Optional caller correlation identifier.
step_up_tokenbodyOptionalhcsu_ tokenFresh ACCOUNT_CLOSURE_REQUEST authorization. Required when TOTP is enabled.
REQUEST
{
"step_up_token": "hcsu_…"
}STABLE ERROR CODES
These codes are published by the authoritative gateway contract for this endpoint. Treat message as safe diagnostic text; integrations should branch on code and HTTP status.
invalid_jsonThe JSON body is malformed or fails the published account schema.invalid_security_requestThe account lifecycle request is invalid.missing_idempotency_keyA nonempty Idempotency-Key is required for this mutation.invalid_credentialsThe bearer, password, activation, or reset credential is invalid.step_up_requiredFresh purpose-bound authenticator verification is required.account_closure_not_foundThe account closure request was not found.security_conflictThe requested account transition conflicts with current security state.account_closure_conflictThe account closure transition conflicts with current lifecycle state.identity_security_unavailableThe authoritative Identity security service is temporarily unavailable.RESPONSES
{
"request_uuid": "6f8d6b1165bb47ca9746897e38c31bd2",
"profile_uuid": "f8317aef81764e1f923037c1b76df8de",
"tenant_uuid": "global",
"status": "CANCELLED",
"reason_code": "PRIVACY",
"version": 2,
"requested_at": "2026-08-13T19:20:00Z",
"scheduled_for": "2026-09-12T19:20:00Z",
"cancelled_at": "2026-08-14T08:10:00Z",
"completed_at": null,
"processing_attempts": 0,
"blocked_until": null,
"blocker_code": null,
"last_error_code": null,
"idempotent_replay": false
}{
"code": "invalid_security_request",
"message": "The JSON body, identifier, or required signed headers are invalid."
}invalid_security_request{
"code": "invalid_credentials",
"message": "The bearer credential or HTTP Message Signature is missing, expired, replayed, or invalid."
}invalid_credentials{
"code": "step_up_required",
"message": "The session lacks profile authority, current-password proof failed, or fresh authenticator verification is required."
}step_up_required{
"code": "account_closure_not_found",
"message": "The request does not exist for the authenticated identity or is no longer cancellable."
}account_closure_not_found{
"code": "identity_security_unavailable",
"message": "The authoritative Identity lifecycle is unavailable."
}identity_security_unavailableOPERATIONAL NOTES
This route is implemented in canonical gateway source and appears in the production OpenAPI snapshot observed 2026-09-11T06:35:11.572Z. Authentication, tenant, feature, venue, and market policy still apply.
Verify the exact production OpenAPI operation ↗Return to the V2 directory ↗