Skip to main content
Deleted-database lifecycle endpoints require a full-account API key and the enabled recovery feature.

List recently deleted databases

GET /api/v1/databases/deleted Returns unpurged tombstones owned by the API-key owner. Each item includes deletedAt, purgeAfter, recoveryStatus and metadata for the exact verified deletion backup:
recoveryStatus is recoverable, unavailable, or expired. An incomplete backup or access-snapshot binding is reported as unavailable rather than being offered for recovery. deletionBackup.downloadUrl is null after purgeAfter, even while metadata remains visible during a short purge retry.

Download the deletion backup

GET /api/v1/databases/{id}/deletion-backup Returns the exact operation-bound deletion artifact as a download or short-lived redirect. The caller cannot select a filename. The route returns 404 DELETION_BACKUP_NOT_AVAILABLE after expiry, purge, ownership mismatch or any database, operation, backup, verification or retention-binding mismatch.

Recover the database

POST /api/v1/databases/{id}/recover Returns 202 Accepted with an operation. Recovery requires available plan quota and restores the isolated PostgreSQL generation, active team memberships, the IP allowlist and still-existing selected-database API-key bindings. Missing users or keys are skipped and reported in the completed operation. Pending invitations are not restored. For a deleted preview, recovery is available only when preview recovery is enabled. It uses this same endpoint and a full-account key; a CI preview key cannot recover a deleted database. A successful recovery starts a new 24-hour preview lease. Later lease renewals can request up to 72 hours. Repeated requests reuse the recovery operation for that deletion. After purgeAfter, download and recovery are disabled. Permanent deletion can be briefly delayed by a safe retry, but the database and deletion backup are removed together before the tombstone disappears from this list.