Skip to content
PacSpace
Talk to us

Workspace

Read your workspace, set its retention window and the sites that may embed a Shared Record, and delete the account.

Every PacSpace account belongs to one workspace, your organization. The dashboard shows it under Settings; these are the routes behind that page. The workspace is the same in Sandbox and Production, so these routes take no environment header.

Every route here needs a dashboard session cookie (-b pacspace-dashboard-cookies.txt). A PATCH or DELETE made with the cookie also sends X-Pacspace-CSRF: 1 and Origin: https://app.pacspace.io; without them the answer is 403.

Base URL: https://app.pacspace.io

http
GET https://app.pacspace.io/dashboard/tenant

Read the workspace

bash
curl https://app.pacspace.io/dashboard/tenant \
  -b pacspace-dashboard-cookies.txt

Answer 200 OK

json
{
  "success": true,
  "data": {
    "id": "cmw3h8d2q0000s601x1v0r7kp",
    "name": "Example Lab",
    "createdAt": "2026-10-01T14:01:52.000Z",
    "updatedAt": "2026-10-05T13:52:18.102Z",
    "plan": "pilot",
    "namespaceAddress": "0x...",
    "dataRetentionDays": null,
    "brandingRevision": 0,
    "embedOrigins": ["https://evals.example.com"],
    "disputeUrl": null,
    "buyerMode": "RECORDS_OPERATOR",
    "buyerModeConfirmedAt": "2026-10-01T14:02:11.000Z",
    "buyerModeConfirmedByUserId": "cmw3h8d2q0001s601b4n6c2wd"
  }
}
FieldMeaning
idThe workspace id.
nameYour organization's name, as registered. It is the name a Shared Record shows as the writing side, and the word you type to delete the account.
planfree, pilot, starter, growth, scale, or enterprise; deleted after the account is deleted. See Plan and usage.
dataRetentionDaysnull for Forever, or 7, 30, or 90. See Data retention.
embedOriginsThe sites allowed to show a Shared Record in a frame. Empty means none.
buyerModeRECORDS_OPERATOR for a records workspace. It can be changed under Settings until the first entry is committed, and not after.
buyerModeConfirmedAt, buyerModeConfirmedByUserIdWhen the workspace kind was last set, and the member who set it: the person who registered, or whoever changed it later in Settings.
namespaceAddress, brandingRevision, disputeUrlKept for other parts of the product. Nothing on these pages reads them.

Set the retention window

bash
curl -X PATCH https://app.pacspace.io/dashboard/tenant/retention \
  -b pacspace-dashboard-cookies.txt \
  -H "X-Pacspace-CSRF: 1" \
  -H "Origin: https://app.pacspace.io" \
  -H "Content-Type: application/json" \
  -d '{ "dataRetentionDays": 30 }'

dataRetentionDays is null for Forever, or 7, 30, or 90; any other value is refused with 400. Takes the admin or manager role. The answer carries dataRetentionDays and a sentence that states the window.

Entries in a record are never removed. What a window removes is the payload of a delivered webhook once it is that old, and the removal runs daily at 03:00 UTC. See Data retention.

Set embed origins

A lab that shows its evaluation records inside its own evaluator portal lists the portal's address:

bash
curl -X PATCH https://app.pacspace.io/dashboard/tenant/embed-origins \
  -b pacspace-dashboard-cookies.txt \
  -H "X-Pacspace-CSRF: 1" \
  -H "Origin: https://app.pacspace.io" \
  -H "Content-Type: application/json" \
  -d '{ "embedOrigins": ["https://evals.example.com"] }'

Each entry is an https origin, scheme and host, with no path, query, or fragment; at most 20. The list replaces the one before, and an empty list allows none. Takes the admin or manager role. The answer carries the stored list, lowercased with repeats removed, and "Embed origins updated."

Delete the account

Takes the admin role and the organization's exact name as confirmation.

bash
curl -X DELETE https://app.pacspace.io/dashboard/tenant \
  -b pacspace-dashboard-cookies.txt \
  -H "X-Pacspace-CSRF: 1" \
  -H "Origin: https://app.pacspace.io" \
  -H "Content-Type: application/json" \
  -d '{ "confirmation": "Example Lab" }'

A confirmation that does not match is refused with 400: "Confirmation does not match your organization name. Please type it exactly."

What happens: every member is deactivated and sent an email saying so, every API key is disabled, the Production webhook endpoint is disabled, the environments are turned off, and the plan is cancelled. What was committed stays committed: the records, their seals, and the history of every entry are kept, and a history file anyone holds still checks. Nothing about a record is deleted by deleting the account.

This cannot be undone from the dashboard. To restore an account, write to support@pacspace.io.

Routes

RouteMethodRole
/dashboard/tenantGETany member
/dashboard/tenant/retentionPATCHadmin, manager
/dashboard/tenant/embed-originsPATCHadmin, manager
/dashboard/tenantDELETEadmin