Delete a project
DELETE/api/v1/projects/:project_id
Delete a project and everything that belongs to it.
Removes the project row, every source archive we hold for it and for its assessments, its scheduled scans and monitoring, its PR reviews and monitor runs, its project-scoped suppressions, webhooks, notification targets and export targets, and its living knowledge base on the runner.
Its assessments are KEPT, with their findings and reports, and unlinked from any project. Their source is deleted with everything else.
409 only while an attached assessment is still running: a live run merges
back into the living KB at completion and would recreate what this removes.
Requires admin-or-above role + projects:delete scope.
Request
Responses
- 200
- 400
- 401
- 403
- 404
- 409
- 422
- 429
- 500
Successful Response
Bad request — malformed input or failed validation.
Missing, expired, or invalid credentials.
Authenticated but not authorized for this resource. Note: cross-organization reads return 404, not 403.
Resource not found, or hidden for tenant-enumeration safety (the caller lacks permission to know whether the resource exists).
Conflict — the current resource state does not allow this operation (e.g. assessment already started, email already in use).
Semantic validation failure — request shape was valid but contents were not.
Too many requests — rate limited. Retry after the window resets.
Internal server error — unexpected failure.