---
title: "Deprovision an app user"
method: DELETE
path: "/api/apps/{app_id}/users/provisions"
---

# Deprovision an app user

`DELETE /api/apps/{app_id}/users/provisions`

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Removes a person's access to this app, including their app user if they've already signed in. A workspace API key needs the **Provision app users** permission. Limited to 120 requests a minute per app, shared with provisioning. Higher plans get a higher limit.

## Path parameters

- `app_id` string, required — ID of the app.

## Request body

- DeprovisionUserPayload — Payload for server-to-server app-user deprovisioning (embedded platforms). The email travels in the body, not the path: a URL reaches access logs, proxies and traces, and an address is personal data.
  - `email` string, email, required — The app user's email

## Response `200`

Successful Response

- DeprovisionUserResponse — The app user whose access was removed.
  - `status` 'deleted', required — Always `deleted`.
  - `email` string, required — The email, lowercased.

## Other responses

- `401` — Missing or invalid credentials.
- `403` — The email belongs to the app's owner or to someone with platform-level access: error.code privileged_user.
- `404` — The email isn't provisioned for this app: error.code unknown_user.
- `422` — Validation Error
- `429` — The app went over its per-minute limit for provision and deprovision requests combined.

## Changes

> 22 revisions in range; 1 not diffed.

- **2026-10-01** `862b46d283f0` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/adexad/apis/base44-app-management-api/changes/api/apps/:app_id/users/provisions/delete.md)

---

[API](https://skmtc.dev/adexad/apis/base44-app-management-api.md) · [All operations](https://skmtc.dev/adexad/apis/base44-app-management-api/llms.txt) · [OpenAPI document](https://skmtc.dev/adexad/apis/base44-app-management-api/revisions/862b46d283f0?raw)
