DevelopersChanges data

erase_customer

API reference — one of six tools an AI assistant can call on an Avrosh account.

What it does

IRREVERSIBLY strip one person's identity from the records, GROUP-WIDE - every branch, every booking they are on (the business records survive, the person is scrubbed off them). This is the right-to-erasure verb for a request the business actually received. Before calling: read the person back to the human (get_customer), state that it is permanent and group-wide, and get an explicit yes. Then pass confirm: 'ERASE' - the tool refuses without it. There is no undo, and afterwards not even the audit trail can say who the row was about.

This is the exact text the model reads before deciding to call.

Parameters

business_idstringrequired

The id returned by list_businesses.

customer_idstringrequired

From list_customers.

confirmstringrequired

The literal string 'ERASE'. Only send it after the human explicitly confirmed.

one of: ERASE

Request

curl -X POST https://us.avrosh.com/mcp \
  -H "Authorization: Bearer $AVROSH_KEY" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"erase_customer","arguments":{"business_id":"926135ac-487d-4367-8bad-25397d0d4b87","customer_id":"ct12…","confirm":"ERASE"}}}'

Response

The result arrives as an MCP content block; the JSON below is what the text field parses to.

{
  "erased": true
}

Authentication

Every request carries Authorization: Bearer avk_…. Create a key in the Avrosh dashboard under Docs; it is shown once, because only its hash is stored.

One key reaches every business on the account that made it, and no others. There are no scopes to configure and nothing to switch on — a connected assistant receives the whole toolset. What bounds it is whose account the key belongs to, which is enforced in the database rather than by a permission anybody sets.

curl https://us.avrosh.com/mcp \
  -H "Authorization: Bearer $AVROSH_KEY"