Deletes one internal note from the current organization. For administrator sessions, the endpoint preserves author ownership checks. A scoped organization API key may delete any note owned by the authenticated organization and path conversation. A successful changed-row delete returns a simple success flag, then publishes an operator-only invalidation and audit event after commit. Access requires an active organization administrator session or an organization API key with the `conversations:write` scope. API-key calls also require the automation API module. Data is isolated to the authenticated organization; identifiers from another organization or site are not disclosed.
/api/notes/{conversationId}/{noteId}Organization API key supplied as Authorization: Bearer convor_sk_....
In: header
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
{
"success": true,
"deleted": true
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}{
"error": {
"code": "UNAUTHORIZED",
"message": "Authentication is required.",
"correlationId": "req_01K0MANAGEMENT401"
}
}{
"error": {
"code": "INTEGRATION_MODULE_REQUIRED",
"message": "The automation API module is required.",
"details": {
"module": "automation_api",
"feature": "public_api"
},
"correlationId": "req_01K0MANAGEMENT402"
}
}{
"error": {
"code": "FORBIDDEN",
"message": "The caller lacks the required role or API-key scope.",
"correlationId": "req_01K0MANAGEMENT403"
}
}{
"error": {
"code": "NOT_FOUND",
"message": "The requested resource was not found.",
"correlationId": "req_01K0MANAGEMENT404"
}
}{
"error": {
"code": "CONFLICT",
"message": "The requested change conflicts with current resource state.",
"correlationId": "req_01K0MANAGEMENT409"
}
}{
"error": {
"code": "VALIDATION_ERROR",
"message": "The request payload is invalid.",
"details": {
"field": "name"
},
"correlationId": "req_01K0MANAGEMENT422"
}
}{
"error": {
"code": "RATE_LIMITED",
"message": "Too many requests.",
"correlationId": "req_01K0MANAGEMENT429"
}
}{
"error": {
"code": "string",
"message": "string",
"fields": {
"property1": "string",
"property2": "string"
},
"details": {},
"correlationId": "string"
}
}curl --request DELETE \
'https://api.convor.io/api/notes/11111111-1111-4111-8111-111111111111/22222222-2222-4222-8222-222222222222' \
--header 'Accept: application/json' \
--header 'Authorization: Bearer convor_sk_...'const response = await fetch("https://api.convor.io/api/notes/11111111-1111-4111-8111-111111111111/22222222-2222-4222-8222-222222222222", {
method: "DELETE",
headers: {
"Accept": "application/json",
"Authorization": "Bearer convor_sk_..."
},
});
const contentType = response.headers.get("content-type") ?? "";
const data = response.status === 204
? null
: contentType.includes("json")
? await response.json()
: contentType.startsWith("text/")
? await response.text()
: await response.blob();
if (!response.ok) {
const message = typeof data === "object" && data !== null
&& "error" in data && typeof data.error === "object"
&& data.error !== null && "message" in data.error
? String(data.error.message)
: "Convor API request failed (" + response.status + ")";
throw new Error(message);
}
console.log(data);Was this page helpful?
Delete a message
Soft-deletes one non-deleted message in a conversation. The message is marked with `deletedAt` and is no longer returned by normal message reads. Visitor callers can access only their own conversations and can delete only visitor messages they authored. Deleting an already-deleted message is an idempotent success. The endpoint publishes a `message_deleted` realtime event, fires a `message.deleted` webhook, and returns a simple success flag. Authenticate with an organization API key sent in `X-API-Key` or as a Bearer token and carrying the exact `conversations:write` scope. API-key access also requires the Automation & API module (`automation_api`). Authorized dashboard sessions remain supported where the route already permits them. The request is isolated to the authenticated organization. Resource and site/project identifiers must belong to that organization; out-of-scope identifiers are not disclosed. Retry behavior: Repeating the same request converges on the same resource state, but a retry may return a conflict or not-found response after the first request succeeds.
Edit a message
Updates the content of one non-deleted message and returns the full message. Edits are allowed only during the 5-minute grace period after message creation. Visitor callers can access only their own conversations and can edit only visitor messages they authored. The endpoint sanitizes the content, preserves up to 20 prior versions in edit history, refreshes search indexing, publishes a `message_edited` realtime event, and fires a `message.updated` webhook. Authenticate with an organization API key sent in `X-API-Key` or as a Bearer token and carrying the exact `conversations:write` scope. API-key access also requires the Automation & API module (`automation_api`). Authorized dashboard sessions remain supported where the route already permits them. The request is isolated to the authenticated organization. Resource and site/project identifiers must belong to that organization; out-of-scope identifiers are not disclosed. Editing records a revision and publishes the route's documented realtime update; callers should not assume that repeating an edit creates no additional revision metadata. Retry behavior: Repeating the same request converges on the same resource state, but a retry may return a conflict or not-found response after the first request succeeds.