> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hookie.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Deactivate, or permanently delete, a workflow

> By default the workflow is DEACTIVATED: `active` is set to 0, the definition and all its run history are kept, it stays in listWorkflows, and PATCH {"active": true} turns it back on. Runs already in progress carry on. With ?permanent=true it is deleted for good (#256): the definition (a workflow's version is a number on it, not a separate row) and its whole run history, meaning every run, its step log and any legacy-engine waiter. Nothing else goes: records and deliveries the runs produced, and the AI call log, are kept. A permanent delete is refused (409) while any run has not finished: pending, running, waiting, or paused by a workspace suspension. Cancel those runs first (POST workflow-instances/{id}/cancel). The workflow is deactivated before its history is deleted, so it starts no new runs meanwhile. The history goes in chunks, at most 10,000 runs a call; a longer one answers 202 with `done: false`, and the same DELETE again carries on until the one that removes the workflow answers 200. Each call that deletes something writes a `delete_workflow` audit row (details: permanent, done, name, project_id, runs_deleted, step_events_deleted); a deactivation writes one with `permanent: false`. Scoped to the caller's workspace and this project: a workflow of another project or workspace is not found.



## OpenAPI

````yaml /openapi.json delete /admin/api/projects/{project_id}/workflows/{workflow_id}
openapi: 3.1.0
info:
  title: Hookie API
  version: 1.0.0
  summary: Capture, route and deliver webhooks.
  description: >-
    Hookie exposes three HTTP surfaces.


    **Ingest + streaming** is the public plane. A path-form endpoint URL
    authenticates by its own high-entropy slug — there is no key, token or
    cookie — and an `ik_live_…` ingest key authenticates the `/v1/*` routes. An
    endpoint URL files each payload into the endpoint's own dataset through the
    endpoint's own criteria and mappings (none means the whole payload, as one
    record); `/v1/ingest/{ingest_key}/{dataset}` stores the payload whole into
    the named dataset. Project mapping rules are evaluated on exactly one shape,
    `POST /v1/ingest/{ingest_key}` with no dataset segment, and never on an
    endpoint URL.


    **The customer portal API** is a separate, token-authed surface for your end
    customers, scoped to one portal and one customer.


    **The admin API** drives the console. It accepts either a browser session or
    an OAuth bearer token from a connected coding agent — the same routes, the
    same validation, the same audit trail. An agent's authority is its user's
    workspace role narrowed to the scopes granted in the console. It also
    accepts an **admin API key** (`hk_…`, Settings → API keys) for CI,
    infrastructure-as-code and vendor backends: the key acts as the member who
    created it, capped at the key's role (viewer, developer or admin — never
    billing or platform administration), optionally limited to one project, with
    an optional expiry and IP allowlist. Keys are stored as a SHA-256 hash and
    shown once; if their creator leaves the workspace they stop working. The
    same key works on the hosted MCP server at `/mcp`.


    **A refused agent is told how to proceed.** An agent's grant is one rung of
    a ladder — `hookie:read` < `hookie:write` < `hookie:manage` — and a call
    above it answers 403 with `code: "agent_scope_insufficient"`, the
    `required_scope`, the `granted_scopes` and a `manage_url` to the console
    page where its user widens it. When the user's own role is the limit the
    code is `insufficient_role` and there is no link, because no grant can
    exceed the user; billing, platform admin, managing connected agents and
    destination signing secrets answer `agent_not_permitted` at every scope. A
    human in the console still reads `Insufficient role`.


    **A suspended workspace** (an operator action, for abuse or non-payment)
    answers every surface with 403 and `reason: "workspace_suspended"`: ingest
    (endpoint URLs and ingest keys), `/v1/data` and `/v1/stream` refuse before
    anything is stored or counted, and every admin API write — console, OAuth
    agent or hosted MCP alike — is refused except billing, platform admin,
    connected-agent management, revoking an API key and the POST-bodied
    searches. The customer portal API is read-only in the same way: destination
    writes answer 403 `workspace_suspended`. Reads keep working. Nothing is sent
    while it is suspended: pending deliveries are paused, workflow runs already
    under way are paused, open `/v1/stream` connections are closed, and cron
    triggers, database sources and WebSocket listeners stop. Reinstating sends
    the paused deliveries, resumes the paused workflow runs where they stopped,
    and resumes the rest; no stored data is lost.


    **Rate limits.** `/admin/api/*` and `/mcp` allow about 100 requests every 10
    seconds per credential — per API key, per connected agent, or per signed-in
    person. Over that, the answer is 429 with `Retry-After` (seconds). Like
    every burst limit here, ingest's included, it is a best-effort guard rather
    than an exact count: it is counted separately at each Cloudflare location
    and catches up within seconds, so a short burst can get through above it.
    The monthly event quota is the exact count.


    **Idempotency.** A `POST` to `/admin/api/*` may carry an `Idempotency-Key`
    header (1–255 printable characters, e.g. a UUID). The first request runs and
    its response is stored for 24 hours; a retry with the same key from the same
    credential, with the same path and body, gets that response back with
    `Idempotent-Replayed: true` and runs nothing. The same key with a different
    path, body or credential is refused with 422; a retry while the first
    request is still running gets 409. 5xx responses are not stored. `POST
    /admin/api/api-keys` refuses the header, because its response is a secret
    shown once and is never stored.


    **Versioning.** Every `/admin/api/*` and `/mcp` response carries
    `Hookie-Version` (currently `2026-09-29`). Additive changes — a new route, a
    new response field, a new optional parameter — ship under the current
    version, so clients must ignore fields they do not know. A breaking change
    gets a new dated version, announced in the changelog, and the previous
    version stays available for at least 12 months; a client pins one by sending
    `Hookie-Version` on its requests. A version this deployment does not serve
    is refused with 400 and the list of `supported_versions`.


    This document is generated from the request handlers and adversarially
    verified against them.
  contact:
    name: Hookie
    url: https://hookie.ai
  license:
    name: Proprietary
    url: https://hookie.ai/legal/terms
servers:
  - url: https://app.hookie.ai
    description: Production
  - url: https://app.preview.hookie.ai
    description: Preview
security: []
tags:
  - name: Ingest
    description: Send events to Hookie.
  - name: Streaming
    description: Tail events in real time over SSE or WebSocket.
  - name: Portal
    description: Token-authed surface for your end customers.
  - name: Projects
    description: Projects and their settings.
  - name: Routing
    description: Rules, endpoints, datasets and records.
  - name: Delivery
    description: Destinations, deliveries and replay.
  - name: Workflows
    description: Multi-step workflows, triggers and AI agents.
  - name: Observability
    description: Search, correlation, stats and the audit log.
  - name: Workspace
    description: >-
      The workspace itself: its name and slug, admin API keys, data export and
      closure. There are no member invites or member routes yet (#258): a
      workspace has its owner, plus any admin the platform sets up.
  - name: Data API
    description: >-
      Read-only access to the datasets and columns a project exposes, with
      per-project keys.
  - name: Broadcast Logs
    description: >-
      Forward a project's logs and traces over OTLP/HTTP (JSON) to Datadog,
      Grafana Cloud, an OpenTelemetry Collector, PostHog or Sentry.
paths:
  /admin/api/projects/{project_id}/workflows/{workflow_id}:
    delete:
      tags:
        - Workflows
      summary: Deactivate, or permanently delete, a workflow
      description: >-
        By default the workflow is DEACTIVATED: `active` is set to 0, the
        definition and all its run history are kept, it stays in listWorkflows,
        and PATCH {"active": true} turns it back on. Runs already in progress
        carry on. With ?permanent=true it is deleted for good (#256): the
        definition (a workflow's version is a number on it, not a separate row)
        and its whole run history, meaning every run, its step log and any
        legacy-engine waiter. Nothing else goes: records and deliveries the runs
        produced, and the AI call log, are kept. A permanent delete is refused
        (409) while any run has not finished: pending, running, waiting, or
        paused by a workspace suspension. Cancel those runs first (POST
        workflow-instances/{id}/cancel). The workflow is deactivated before its
        history is deleted, so it starts no new runs meanwhile. The history goes
        in chunks, at most 10,000 runs a call; a longer one answers 202 with
        `done: false`, and the same DELETE again carries on until the one that
        removes the workflow answers 200. Each call that deletes something
        writes a `delete_workflow` audit row (details: permanent, done, name,
        project_id, runs_deleted, step_events_deleted); a deactivation writes
        one with `permanent: false`. Scoped to the caller's workspace and this
        project: a workflow of another project or workspace is not found.
      operationId: deleteWorkflow
      parameters:
        - name: project_id
          in: path
          required: true
          schema:
            type: string
        - name: workflow_id
          in: path
          required: true
          schema:
            type: string
        - name: permanent
          in: query
          required: false
          description: >-
            true deletes the workflow and its run history for good. Omitted or
            false, the workflow is only deactivated (active set to 0), and PATCH
            active:true brings it back. Any other value is refused with 400.
          schema:
            type: boolean
            default: false
      responses:
        '200':
          description: >-
            Deactivated (`{"ok": true}`), or with ?permanent=true deleted along
            with its runs and their step log (`done: true`, and what went in
            `deleted`).
          content:
            application/json:
              schema:
                type: object
                required:
                  - ok
                properties:
                  ok:
                    type: boolean
                    enum:
                      - true
                  done:
                    type: boolean
                    enum:
                      - true
                    description: 'Permanent delete only: the workflow itself is gone.'
                  deleted:
                    type: object
                    required:
                      - runs
                      - step_events
                    properties:
                      runs:
                        type: integer
                        description: Runs this call deleted.
                      step_events:
                        type: integer
                        description: Step-log rows this call deleted with them.
                    description: 'Permanent delete only: what this call deleted.'
        '202':
          description: >-
            Permanent delete only: the run history is longer than one call
            deletes (10,000 runs). This call deleted `deleted`; `remaining_runs`
            are left, and the workflow is still listed, now inactive. Send the
            same DELETE again to carry on.
          content:
            application/json:
              schema:
                type: object
                required:
                  - ok
                  - done
                  - deleted
                  - remaining_runs
                  - message
                properties:
                  ok:
                    type: boolean
                    enum:
                      - true
                  done:
                    type: boolean
                    enum:
                      - false
                  deleted:
                    type: object
                    required:
                      - runs
                      - step_events
                    properties:
                      runs:
                        type: integer
                        description: Runs this call deleted.
                      step_events:
                        type: integer
                        description: Step-log rows this call deleted with them.
                  remaining_runs:
                    type: integer
                    description: Runs of the workflow still to delete.
                  message:
                    type: string
        '400':
          description: >-
            `permanent must be true or false`: the query parameter had another
            value.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Not signed in.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: >-
            `Insufficient role`, or `Missing X-Requested-With header`. Also
            `reason: "workspace_suspended"` while the workspace is suspended.
            For an OAuth-connected agent the body also carries `code`,
            `required_scope` and `granted_scopes`, plus `manage_url` when
            widening its grant in Settings → Connected agents would let the call
            through (see Error).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: '`Workflow not found`, or `Project not found`.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '409':
          description: >-
            Permanent delete only: a run of this workflow has not finished
            (pending, running, waiting, or paused by a suspension), so nothing
            was changed. `error` says to cancel those runs first (and to
            deactivate the workflow, if it is on) and then names up to 10 of
            them by id, so an agent that sees only the message can cancel them;
            `instances` lists the same runs, oldest first.
          content:
            application/json:
              schema:
                type: object
                required:
                  - error
                  - code
                  - unfinished_runs
                  - instances
                properties:
                  error:
                    type: string
                    description: Human-readable reason, naming up to 10 unfinished runs.
                  code:
                    type: string
                    enum:
                      - unfinished_runs
                  unfinished_runs:
                    type: integer
                    description: >-
                      How many runs have not finished; may be more than are
                      listed.
                  instances:
                    type: array
                    maxItems: 10
                    items:
                      type: object
                      required:
                        - id
                        - state
                        - paused
                      properties:
                        id:
                          type: string
                          description: >-
                            The run (workflow instance) id, as
                            cancelWorkflowInstance takes it.
                        state:
                          type: string
                          description: 'Its state: pending, running or waiting.'
                        paused:
                          type: boolean
                          description: True when a workspace suspension paused it.
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          description: '`Internal error`.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - session: []
        - bearerAuth: []
        - apiKey: []
components:
  schemas:
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: string
          description: Human-readable reason.
        retry_after:
          type: integer
          description: Seconds to wait. Present on 429.
        upgrade_url:
          type: string
          format: uri
          description: Present only on a monthly-quota 429.
        reason:
          type: string
          description: >-
            Machine-readable reason, where the status alone is ambiguous.
            `workspace_suspended` (403): the workspace is suspended;
            `delivery_allowance_exhausted` (429): a replay was refused because
            the monthly delivery allowance is used. `endpoint_disabled` (503):
            the endpoint is switched off; `handshake_failed`: a provider
            URL-verification challenge could not be answered (#193).
            `missing_header`, `bad_signature`, `stale_timestamp` (401): an
            endpoint's provider signature check failed; `scheme` names the
            check.
        code:
          type: string
          enum:
            - agent_scope_insufficient
            - insufficient_role
            - agent_not_permitted
          description: >-
            Present on a 403 to an OAuth-connected agent.
            `agent_scope_insufficient`: the agent's grant is below what the call
            needs, and widening it would let the call through (see
            `required_scope` and `manage_url`). `insufficient_role`: the user's
            OWN workspace role does not allow the call, so no grant can — and
            roles cannot be changed in the product yet, so the call is one for
            the workspace owner. `agent_not_permitted`: no connected agent may
            do this at any scope (billing, platform admin, managing connected
            agents, a destination's signing secret).
        required_scope:
          type: string
          enum:
            - hookie:read
            - hookie:write
            - hookie:manage
          description: 'With `code`: the scope the refused call needs.'
        granted_scopes:
          type: array
          items:
            type: string
          description: 'With `code`: the scopes the agent''s grant holds now.'
        manage_url:
          type: string
          format: uri
          description: >-
            With `code: "agent_scope_insufficient"` only: the console's Settings
            → Connected agents page, opened on this agent
            (`…/#/settings/agents?client=<client_id>`), where its user widens
            the grant. The change applies on the agent's next request.
        scheme:
          type: string
          description: 'Present on a signature 401: the endpoint''s verification scheme.'
  responses:
    RateLimited:
      description: >-
        Over this credential's burst limit (about 100 requests per 10 seconds;
        best-effort, counted separately at each Cloudflare location). Retry
        after `Retry-After` seconds.
      headers:
        Retry-After:
          schema:
            type: integer
          description: Seconds to wait.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    session:
      type: apiKey
      in: cookie
      name: hookie_session
      description: >-
        The console's sealed session cookie, set by WorkOS AuthKit. Mutating
        requests also require the `X-Requested-With` CSRF header.
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        An OAuth 2.1 access token from a connected agent, audienced at the
        `/mcp` resource URI. The agent acts as its user, with that user's role
        narrowed to the granted `hookie:*` scopes. No CSRF header is required —
        a bearer token is not ambient credentials.
    apiKey:
      type: http
      scheme: bearer
      description: >-
        An `hk_…` admin API key from Settings → API keys. Acts as the member who
        created it, capped at the key's role (viewer, developer or admin) and
        optionally one project. Stored as a SHA-256 hash, shown once. No CSRF
        header is required.

````