Remove Organization Member
DELETE /members/{user_id}
DELETE /members/{user_id}Interactive request editor loads with JavaScript.
Authorization
BearerAdminToken Organization-scoped admin token. Read operations require a valid token, and write operations require a token with write permission.
In: header
Path Parameters
User ID of the organization member.
uuidResponse Body
application/json
application/json
application/json
application/json
application/json
application/json
curl -X DELETE "$AISIX_CP/members/$USER_ID" \ -H "Authorization: Bearer $AISIX_TOKEN"Removed
{
"deleted": true,
"user_id": "a169451c-8525-4352-b8ca-070dd449a1a5"
}Request body or parameters failed validation.
{
"error": {
"code": "string",
"message": "string"
}
}Missing or invalid bearer.
{
"error": {
"code": "UNAUTHENTICATED",
"message": "no org context"
}
}Authenticated request is not permitted.
{
"error": {
"code": "CUSTOM_KEY_DISABLED",
"message": "custom API key values are disabled for this organization"
}
}Resource not found.
{
"error": {
"code": "NOT_FOUND",
"message": "provider key not found"
}
}The removal would remove the last owner.
{
"error": {
"code": "LAST_OWNER",
"message": "cannot remove the last owner"
}
}Complete operation details and schema variants
DELETE /members/{user_id}
Remove Organization Member
Remove a member from the organization. Only an organization owner can do this, and the last owner cannot be removed.
The member's environment role bindings and team memberships go
with them. Caller API keys they own are not deleted and keep
working — the user_id already recorded on usage rows still
resolves to them, so past traffic stays attributable. Delete or
reassign those keys separately if the removal is meant to cut off
their traffic.
Parameters
user_id(path, string, required): User ID of the organization member.
Responses
-
200: Removed -
deleted(boolean, required): -
user_id(string, required): -
400: Request body or parameters failed validation. -
error(object, required): Error details. -
error.code(string, required): Machine-readable identifier. Examples:UNAUTHENTICATED,INVALID_REQUEST,MASTER_KEY_UNSET,INTERNAL. -
error.message(string, required): Human-readable explanation; safe to surface to operators. -
401: Missing or invalid bearer. Response fields (application/json): identical toDELETE /members/{user_id}, response 400 above. -
403: Authenticated request is not permitted. Response fields (application/json): identical toDELETE /members/{user_id}, response 400 above. -
404: Resource not found. Response fields (application/json): identical toDELETE /members/{user_id}, response 400 above. -
409: The removal would remove the last owner. Response fields (application/json): identical toDELETE /members/{user_id}, response 400 above.
cURL
curl -X DELETE '$AISIX_CP/members/{user_id}' -H 'Authorization: Bearer $AISIX_TOKEN'