AdminDelete all aggregates (dev only)

Delete all aggregates (dev only)

Admin-only endpoint that performs a complete environment wipe. Deletes all events from R2, removes all aggregates from D1 (users, locks, temp_keys), and cleans up Durable Object instances. API keys are preserved so subsequent tests still work. ONLY permitted in the dev environment — returns 403 Forbidden on stage or production. Requires dual authentication: X-Admin-API-Key header and a JWT with @smartphonekey.com email domain.

curl -X POST "https://api.spkey.co/admin/cleanup/delete-all" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer YOUR_API_TOKEN (JWT)" \
  -H "X-API-Key: YOUR_API_KEY"
{
  "success": true,
  "operations": [
    "null"
  ],
  "deletionSummary": "example_string",
  "auditLogPath": "example_string",
  "duration": 3.14,
  "errors": [
    "example_string"
  ]
}
POST
/admin/cleanup/delete-all
POST
Base URLstring

Target server for requests. Edit to use your own host.

Bearer Token (JWT)
Bearer Tokenstring
Required

JWT token from SmartphoneKey authentication. Identifies the B2C user or B2B service.

JWT token from SmartphoneKey authentication. Identifies the B2C user or B2B service.
API Key (header: X-API-Key)
X-API-Keystring
Required

API key for B2B organization access. Provided during organization onboarding.

API key for B2B organization access. Provided during organization onboarding.
Request Preview
Response

Response will appear here after sending the request

Authentication

header
Authorizationstring
Required

Bearer token (JWT). JWT token from SmartphoneKey authentication. Identifies the B2C user or B2B service.

header
X-API-Keystring
Required

API Key for authentication. API key for B2B organization access. Provided during organization onboarding.

Responses

successboolean
Required
operationsstring[]
Required
deletionSummarystring
auditLogPathstring
Required
durationnumber
Required
errorsstring[]
Required