Remove your own profile photo
/api/profile/avatarDeletes the object and nulls the metadata field.
Authorization
sessionCookie The dashboard's Supabase Auth session cookie, set at sign-in. Large sessions are split across
numbered chunks (…auth-token.0, .1), so treat this as a cookie family rather than one name.
Every request re-validates it against the Auth server (getUser()), never by decoding the cookie
locally: a JWT nothing has checked is not a credential. Tenancy is then read from the verified
app_metadata.company_id claim and enforced by row-level security; it is never read from request
input, on any route, ever.
role (admin / staff) is deliberately not in RLS. It gates specific actions in route code,
the operations marked admin below, so hiding a button in the UI is cosmetic only, and a route's
own check is the enforcement.
In: cookie
Response Body
application/json
application/json
application/json
curl -X DELETE "https://example.com/api/profile/avatar"{ "ok": true}Upload your own profile photo POST
Personal account data, not tenant data; a plain signed-in check, no organization scoping, no role. The storage policy pins writes to `{userId}/avatar`, which is what actually enforces "only your own folder". Stored on the auth user's metadata, not on any booking table.
Delete your own account DELETE
Danger zone. Unlike a one-account-per-company product, a Booking org can have several members, so deleting YOUR account does not always take the workspace with it: - **Last member standing**: nobody would be left who could ever sign in and manage or delete the org, so the whole workspace is deleted too. - **Teammates remain**: only this user's membership and personal data go; the workspace is shared, not owned. - **Sole admin with staff remaining**: refused with 400. Promote a teammate first. This mirrors the "cannot remove the last admin" rule on DELETE /api/members/{id}, so an admin cannot self-delete into an org nobody can administer. When the workspace does go, its live Stripe subscriptions are cancelled immediately, before the database cascade, and that cancellation has to succeed for the deletion to proceed (see the 502). The Stripe customer and its invoices are deliberately NOT deleted: Australian tax law requires seven years of sales records, so erasure covers the account and retention covers the invoices. This route is exempted from the onboarding redirect in middleware so a mid-onboarding account can still delete itself.