An account can delete itself. Today only admin user delete exists, and it refuses an account that anchors anything (store.DeleteUser's blocker list).
Decided:
- Authored content stays, reassigned to a ghost. Issues, MRs, comments, diff comments and reviews on repositories the account does not own move to a reserved
ghostaccount rendered as "deleted user". The name goes ininternal/policy/names.go; the account cannot sign in, own anything, or be deleted. - Owned content goes. The account's repositories, snippets, keys, emails, tokens, sessions, grants and watches are deleted. An org where it is the only admin blocks the deletion until another admin exists or the org is deleted.
- Stronger confirmation than any other action:
- Type the username (the
confirmfieldpartial on the web,--confirm <username>over SSH). - A link mailed to the primary verified address confirms the request. Over SSH this is the only way to do step 2.
- The account is disabled for 7 days, then purged. Signing in during the grace period (web login or an SSH command) cancels the deletion and re-enables the account. The mail says so and gives the purge date.
- Type the username (the
- The purge runs from the same reaper that drops pending accounts (
ReapPendingUsers). It is audited, and it frees the username only after the purge. - Suggest
account exportin the confirmation screen and the mail. - Command:
account delete(a write, every surface; a read-scoped token or runner key is refused). Web: a section at the bottom of the account settings page.
Parity row, Users wiki page, /privacy text ("deleted on request" becomes how).
closed by cmc in commit 161f585ca2: control: self-service account deletion
2026-10-02 15:41 UTC