Delete persona
HARD DELETE. models.BaseModel declares no gorm.DeletedAt, so DB.Delete issues a real DELETE and the row is gone — this is not the logical delete used elsewhere in the platform, and there is no way to recover the persona through the API. Answers 200 through Ok200, so the body is {"status": 200, "message": "OK"} — not 204 and not the deleted record. The RBAC grants written at create time are not cleaned up.
Authorization
bearerAuth In: header
Path Parameters
Persona id. A value that does not parse is 400 personas_m.invalid_persona_id.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X DELETE "https://example.com/v1/personas/497f6eca-6276-4993-bfeb-53cbbbba6f08"{
"status": 200,
"message": "OK"
}{
"status": 400,
"message": "Invalid input",
"code": "common.invalid_input",
"class": "validation"
}{
"status": 401,
"message": "Unauthorized",
"code": "common.unauthorized",
"class": "business"
}{
"status": 403,
"message": "No access to the record",
"code": "common.rbac_no_rec_access",
"class": "business"
}{
"status": 404,
"message": "Record not found",
"code": "common.record_not_found",
"class": "business"
}{
"status": 429,
"message": "Rate limit exceeded",
"code": "rate_limits_m.exceeded",
"class": "temporary",
"retryable": true
}{
"status": 500,
"message": "Internal server error",
"code": "common.server_error",
"class": "business"
}{
"overall_status": "unhealthy",
"message": "Service is shutting down",
"timestamp": "2026-08-27T15:04:05Z"
}Deletes the link. ANSWERS 200, NOT 204: the shared helper finishes with apireply.Ok200, so the body is {"status": 200, "message": "OK"}. The 204 this operation used to document was never written by the code.
Resolves the persona linked to the user through common/links, then reads it. The link must be stored with the persona on the x side and the user on the y side, which is the orientation POST /v1/persona-links writes. A user with no such link answers 404. A LINK THAT POINTS AT A ROW THAT IS GONE ANSWERS 500, NOT 404: the read is a bare First() whose error is wrapped as common.database_error without separating gorm.ErrRecordNotFound. Because DELETE /v1/personas/{persona_id} is a hard delete that leaves the links behind, this is a state a client will actually meet. The permission checked is read on the USER record, not on the persona — so a caller who may read the user gets the persona whether or not they hold a grant on the persona itself.