List recently deleted databases
GET /api/v1/databases/deleted
Returns unpurged tombstones owned by the API-key owner. Each item includes
deletedAt, purgeAfter, recoveryStatus and metadata for the exact verified
deletion backup:
recoveryStatus is recoverable, unavailable, or expired. An incomplete
backup or access-snapshot binding is reported as unavailable rather than being
offered for recovery. deletionBackup.downloadUrl is null after
purgeAfter, even while metadata remains visible during a short purge retry.
Download the deletion backup
GET /api/v1/databases/{id}/deletion-backup
Returns the exact operation-bound deletion artifact as a download or short-lived
redirect. The caller cannot select a filename. The route returns 404 DELETION_BACKUP_NOT_AVAILABLE after expiry, purge, ownership mismatch or any
database, operation, backup, verification or retention-binding mismatch.
Recover the database
POST /api/v1/databases/{id}/recover
Returns 202 Accepted with an operation. Recovery requires available plan
quota and restores the isolated PostgreSQL generation, active team memberships,
the IP allowlist and still-existing selected-database API-key bindings. Missing
users or keys are skipped and reported in the completed operation. Pending
invitations are not restored.
For a deleted preview, recovery is available only when preview recovery is
enabled. It uses this same endpoint and a full-account key; a CI preview key
cannot recover a deleted database. A successful recovery starts a new 24-hour
preview lease. Later lease renewals can request up to 72 hours. Repeated
requests reuse the recovery operation for that deletion.
After purgeAfter, download and recovery are disabled. Permanent deletion can
be briefly delayed by a safe retry, but the database and deletion backup are
removed together before the tombstone disappears from this list.