Skip to main content
Retire live test users when your integration tests are finished. This revokes their access while preserving the records needed to explain prior charges.
Sandbox keys create no live balances or end users and need no cleanup.

Prepare a test user for retirement

1

Stop new activity

Stop issuing calls, tokens, and top-ups for the identity.
2

Wait for pending activity

Let in-flight calls settle and hosted checkout sessions complete or expire.
3

Return the remaining credits

Deallocate the balance to the workspace pool.
If retirement returns 409 END_USER_RETIREMENT_BLOCKED, resolve the conditions listed in the response and retry.

Retire the user

A workspace owner or admin with tokens:manage completes fresh MFA or passkey verification, then calls:
Retire a test user
Retirement leaves the identity inactive. Issuing a new token cannot reactivate it. To reuse the identity, reset its policy instead.
Retirement revokes tokens and Agent Connections, cancels cost approvals, resets the active policy, and freezes the account. Repeated retirement is safe. Financial and security history remain available.

Reset a policy without retiring the user

Use this when the identity should remain available for another test:
Reset a policy
The caller needs tokens:manage; dashboard callers must be an owner or admin. The reset waits until no active reservation depends on the policy and preserves its decision history. The API reference covers permissions, blockers, and responses.