Workspace
Read your workspace, set its retention window and the sites that may embed a Shared Record, and delete the account.
Every PacSpace account belongs to one workspace, your organization. The dashboard shows it under Settings; these are the routes behind that page. The workspace is the same in Sandbox and Production, so these routes take no environment header.
Every route here needs a dashboard session cookie (-b pacspace-dashboard-cookies.txt). A PATCH or DELETE made with the cookie also sends X-Pacspace-CSRF: 1 and Origin: https://app.pacspace.io; without them the answer is 403.
Base URL: https://app.pacspace.io
GET https://app.pacspace.io/dashboard/tenantRead the workspace
curl https://app.pacspace.io/dashboard/tenant \
-b pacspace-dashboard-cookies.txtAnswer 200 OK
{
"success": true,
"data": {
"id": "cmw3h8d2q0000s601x1v0r7kp",
"name": "Example Lab",
"createdAt": "2026-10-01T14:01:52.000Z",
"updatedAt": "2026-10-05T13:52:18.102Z",
"plan": "pilot",
"namespaceAddress": "0x...",
"dataRetentionDays": null,
"brandingRevision": 0,
"embedOrigins": ["https://evals.example.com"],
"disputeUrl": null,
"buyerMode": "RECORDS_OPERATOR",
"buyerModeConfirmedAt": "2026-10-01T14:02:11.000Z",
"buyerModeConfirmedByUserId": "cmw3h8d2q0001s601b4n6c2wd"
}
}| Field | Meaning |
|---|---|
id | The workspace id. |
name | Your organization's name, as registered. It is the name a Shared Record shows as the writing side, and the word you type to delete the account. |
plan | free, pilot, starter, growth, scale, or enterprise; deleted after the account is deleted. See Plan and usage. |
dataRetentionDays | null for Forever, or 7, 30, or 90. See Data retention. |
embedOrigins | The sites allowed to show a Shared Record in a frame. Empty means none. |
buyerMode | RECORDS_OPERATOR for a records workspace. It can be changed under Settings until the first entry is committed, and not after. |
buyerModeConfirmedAt, buyerModeConfirmedByUserId | When the workspace kind was last set, and the member who set it: the person who registered, or whoever changed it later in Settings. |
namespaceAddress, brandingRevision, disputeUrl | Kept for other parts of the product. Nothing on these pages reads them. |
Set the retention window
curl -X PATCH https://app.pacspace.io/dashboard/tenant/retention \
-b pacspace-dashboard-cookies.txt \
-H "X-Pacspace-CSRF: 1" \
-H "Origin: https://app.pacspace.io" \
-H "Content-Type: application/json" \
-d '{ "dataRetentionDays": 30 }'dataRetentionDays is null for Forever, or 7, 30, or 90; any other value is refused with 400. Takes the admin or manager role. The answer carries dataRetentionDays and a sentence that states the window.
Entries in a record are never removed. What a window removes is the payload of a delivered webhook once it is that old, and the removal runs daily at 03:00 UTC. See Data retention.
Set embed origins
A lab that shows its evaluation records inside its own evaluator portal lists the portal's address:
curl -X PATCH https://app.pacspace.io/dashboard/tenant/embed-origins \
-b pacspace-dashboard-cookies.txt \
-H "X-Pacspace-CSRF: 1" \
-H "Origin: https://app.pacspace.io" \
-H "Content-Type: application/json" \
-d '{ "embedOrigins": ["https://evals.example.com"] }'Each entry is an https origin, scheme and host, with no path, query, or fragment; at most 20. The list replaces the one before, and an empty list allows none. Takes the admin or manager role. The answer carries the stored list, lowercased with repeats removed, and "Embed origins updated."
Delete the account
Takes the admin role and the organization's exact name as confirmation.
curl -X DELETE https://app.pacspace.io/dashboard/tenant \
-b pacspace-dashboard-cookies.txt \
-H "X-Pacspace-CSRF: 1" \
-H "Origin: https://app.pacspace.io" \
-H "Content-Type: application/json" \
-d '{ "confirmation": "Example Lab" }'A confirmation that does not match is refused with 400: "Confirmation does not match your organization name. Please type it exactly."
What happens: every member is deactivated and sent an email saying so, every API key is disabled, the Production webhook endpoint is disabled, the environments are turned off, and the plan is cancelled. What was committed stays committed: the records, their seals, and the history of every entry are kept, and a history file anyone holds still checks. Nothing about a record is deleted by deleting the account.
This cannot be undone from the dashboard. To restore an account, write to support@pacspace.io.
Routes
| Route | Method | Role |
|---|---|---|
/dashboard/tenant | GET | any member |
/dashboard/tenant/retention | PATCH | admin, manager |
/dashboard/tenant/embed-origins | PATCH | admin, manager |
/dashboard/tenant | DELETE | admin |