Skip to main content
theAuth includes built-in tools for three data subject requests that commonly require custom code: exporting a user’s data, deleting their account on request, and anonymizing their account. Deleting an account can also anonymize the user’s audit rows.
These tools cover part of the technical layer and do not make a deployment compliant by themselves. Your privacy policy, data processing agreements, and response timelines are your responsibility.

Setup

The gdpr plugin takes no options. It registers three self-service endpoints scoped to the authenticated user. The user is resolved through the same mechanism as other plugin endpoints (your configured auth adapter or session); unauthenticated requests get a 401.
lib/theauth.ts

Export user data

GET /auth/gdpr/export Returns a JSON bundle covering the authenticated user’s profile, agents, sessions, audit events, delegations, organization memberships, and API keys (GDPR Article 20). It is not a dump of every table: it omits, for example, TOTP records, passkeys, OAuth tokens, approval requests, and budget policies, and each section contains a few summary fields only (API keys: id, name, createdAt; sessions: id and timestamps). Audit events and delegations are only included if the user owns at least one agent.
Request export (client)

Delete account

DELETE /auth/gdpr/delete Deletes the user account and associated data (GDPR Article 17). Requires an explicit confirmation string in the request body:
Delete account (client)
What the delete does, in order: revokes the user’s agents; deletes sessions, delegation chains involving those agents, and API keys; anonymizes the audit rows of those agents (or deletes the rows of this user when keepAuditLogs is false); deletes approval requests, budget policies, OAuth tokens and codes, magic links, email OTPs, TOTP records, passkeys, and org memberships; optionally deletes owned organizations; then deletes the user row. Note that with keepAuditLogs: true the agent rows are kept with status revoked (so deletedAgents counts agents revoked, not rows removed), and they still carry their name and metadata. With keepAuditLogs: false the agent rows are deleted.
The module toggles PRAGMA foreign_keys while deleting and anonymizing audit rows. That statement is SQLite syntax, so on Postgres or MySQL the keepAuditLogs: true path and the final user deletion will fail with a database error unless the statement is accepted by your driver. Test deletion against your production database engine before relying on it.
Deletion is irreversible. Any app data you store outside theAuth that references the user ID will become orphaned, the plugin has no onBeforeDelete hook, cascade those deletes yourself before calling this endpoint.

Anonymize account

POST /auth/gdpr/anonymize Replaces the email with a deterministic anonymous value (deleted-<hash>@anon.invalid) and clears name, external ID, and metadata, while keeping the account row, agents, and audit history. It also deletes the user’s TOTP records and passkeys. It does not revoke sessions, and it does not touch audit rows (those still reference the same user ID). Use this instead of deletion when org membership or audit referential integrity must be preserved.
Anonymize account (client)

Using the module directly

The plugin wraps createGdprModule, which you can also call directly (for background jobs, admin tooling, or CLI scripts) without going through the HTTP endpoints:

Compliance

Framework mapping and evidence export (JSON, CSV, verifiable credentials).

Audit trail

The audit log that GDPR anonymization targets.

Hooks

Lifecycle hooks for authorization and agent events. There is no account deletion hook.

Multi-session

Session revocation that runs as part of account deletion.
Last modified on October 7, 2026