Sandbox keys create no live balances or end users and
need no cleanup.
Prepare a test user for retirement
1
Stop new activity
Stop issuing calls, tokens, and top-ups for the identity.
2
Wait for pending activity
Let in-flight calls settle and hosted checkout sessions complete or expire.
3
Return the remaining credits
Deallocate the balance to the workspace pool.
409 END_USER_RETIREMENT_BLOCKED, resolve the conditions listed in the response and retry.
Retire the user
A workspace owner or admin withtokens:manage completes fresh MFA or passkey
verification, then calls:
Retire a test user
Reset a policy without retiring the user
Use this when the identity should remain available for another test:Reset a policy
tokens:manage; dashboard callers must be an owner or admin. The reset waits until no active reservation depends on the policy and preserves its decision history.
The API reference covers permissions, blockers, and responses.