> ## Documentation Index
> Fetch the complete documentation index at: https://chainpatrol.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Delete Detection Config

> Delete one detection config so it stops scanning. Other configs sharing the same source keep running. Deleting the last config for a source that is enabled by default is not permanent, since automation re-creates it; disable it through /detection/configs/update instead.

## Overview

Soft-delete one org-scoped threat detection config by `configId` so it stops
scanning. Other configs sharing the same source keep running.

Only configs owned by your organization can be deleted through this endpoint;
global configs stay staff-only.

## When to use

* Remove a config you no longer need.
* Retire one variant of a multi-config source without touching the others.

Deleting the *last* config for a source that is enabled by default for your
organization is **not permanent**: automation re-creates a default config for
that source on its next run. To stop such a source durably, call
[Update Detection Config](/docs/external-api/detection-configs-update) with
`status` set to `DISABLED` instead — automation will not override that.

## How it works

* Look up the `configId` with [List Detection Configs](/docs/external-api/detection-configs-list).
* The config's `deletedAt` and `updatedAt` are set, and a history row is written
  with unchanged status so default-sync jobs don't treat the deletion as a
  status change.


## OpenAPI

````yaml POST /detection/configs/delete
openapi: 3.0.3
info:
  title: ChainPatrol External API - OpenAPI 3.0
  description: ChainPatrol External API documentation
  version: 2.0.0
servers:
  - url: https://app.chainpatrol.io/api/v2
security: []
tags:
  - name: asset
  - name: report
externalDocs:
  url: https://chainpatrol.com/docs
paths:
  /detection/configs/delete:
    post:
      tags:
        - detection
      summary: Delete threat detection config
      description: >-
        Delete one detection config so it stops scanning. Other configs sharing
        the same source keep running. Deleting the last config for a source that
        is enabled by default is not permanent, since automation re-creates it;
        disable it through /detection/configs/update instead.
      operationId: detectionConfigsDelete
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                slug:
                  type: string
                  minLength: 1
                  description: >-
                    Organization slug. Defaults to the organization your API key
                    is scoped to, so you only need this when authenticating with
                    a key that spans organizations.
                configId:
                  type: integer
                  minimum: 0
                  exclusiveMinimum: true
                  description: ID of the config to delete, from `/detection/configs/list`
              required:
                - configId
              description: >-
                Delete a threat detection config


                Deletes one detection config so it stops scanning. Deleting a
                config that shares a source with others leaves the others
                running.


                Deleting the *last* config for a source that is enabled by
                default for your organization is not permanent: automation
                re-creates a default config for that source on its next run. To
                stop such a source durably, set `status` to `DISABLED` through
                `/detection/configs/update` instead, which automation will not
                override.
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                  id:
                    type: number
                    description: ID of the deleted config
                required:
                  - success
                  - id
                description: Deleted detection config
        '400':
          description: Invalid input data
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.BAD_REQUEST'
        '401':
          description: Authorization not provided
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.UNAUTHORIZED'
        '403':
          description: Insufficient access
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.FORBIDDEN'
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error.INTERNAL_SERVER_ERROR'
      security:
        - ApiKey: []
components:
  schemas:
    error.BAD_REQUEST:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Invalid input data
        code:
          type: string
          description: The error code
          example: BAD_REQUEST
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Invalid input data error (400)
      description: The error information
      example:
        code: BAD_REQUEST
        message: Invalid input data
        issues: []
    error.UNAUTHORIZED:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Authorization not provided
        code:
          type: string
          description: The error code
          example: UNAUTHORIZED
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Authorization not provided error (401)
      description: The error information
      example:
        code: UNAUTHORIZED
        message: Authorization not provided
        issues: []
    error.FORBIDDEN:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Insufficient access
        code:
          type: string
          description: The error code
          example: FORBIDDEN
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Insufficient access error (403)
      description: The error information
      example:
        code: FORBIDDEN
        message: Insufficient access
        issues: []
    error.INTERNAL_SERVER_ERROR:
      type: object
      properties:
        message:
          type: string
          description: The error message
          example: Internal server error
        code:
          type: string
          description: The error code
          example: INTERNAL_SERVER_ERROR
        issues:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
            required:
              - message
          description: An array of issues that were responsible for the error
          example: []
      required:
        - message
        - code
      title: Internal server error error (500)
      description: The error information
      example:
        code: INTERNAL_SERVER_ERROR
        message: Internal server error
        issues: []
  securitySchemes:
    ApiKey:
      type: apiKey
      in: header
      name: X-API-KEY
      description: >-
        Your API key. This is required by most endpoints to access our API
        programatically. Reach out to us at
        [support@chainpatrol.io](mailto:support@chainpatrol.io?subject=Re:%20API%20Key%20for%20SDK&body=Company:%20%0AName:%20%0APurpose:%20)
        to get an API key for your use.

````