> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ns.rocks/llms.txt
> Use this file to discover all available pages before exploring further.

# Export account data

> Dormant during the private-beta key-only e2e. This route returns
`feature_unavailable` unless `NULLSPACE_SELF_SERVE_AUTH_ENABLED=true`
is set. When enabled, it returns a JSON export of the user's account,
personal team, key metadata, quota usage, and machine metadata.




## OpenAPI

````yaml /openapi.yaml get /v1/account/export
openapi: 3.1.0
info:
  title: Nullspace API
  version: 0.1.0
  description: |
    Cloud machine platform for AI agents. Create on-demand microVMs,
    execute commands, manage files, automate desktop environments,
    and stream output over WebSocket.
  license:
    name: Apache-2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
servers:
  - url: https://api.13-215-85-171.sslip.io
    description: Private beta
  - url: https://nullspace.example
    description: Self-hosted single-host owned-domain
  - url: http://localhost
    description: Self-hosted single-host localhost/no-domain via Caddy
  - url: http://localhost:3000
    description: Local development direct API
security:
  - bearerAuth: []
tags:
  - name: Health
    description: Public process-liveness check (no auth required)
  - name: Machines
    description: Machine lifecycle, execution, and process management
  - name: Files
    description: Filesystem operations within a machine
  - name: Git
    description: First-class structured git operations within a machine
  - name: Desktop
    description: Desktop automation (mouse, keyboard, screenshots)
  - name: Recording
    description: Screen recording management
  - name: PTY
    description: Pseudo-terminal session management
  - name: Templates
    description: Machine template management
  - name: Agent Deployments
    description: Named, versioned agent deployment control plane
  - name: Volumes
    description: Persistent volume control plane and attached volume actions
  - name: WebSocket
    description: Streaming execution and PTY over WebSocket
  - name: Monitor
    description: In-repo WebSocket stream for machine health, metrics, and process updates
  - name: API Keys
    description: Runtime API key metadata and dormant self-serve key management
  - name: Account
    description: Dormant Supabase-session account profile, export, and deletion routes
  - name: Admin
    description: Supabase-session operator console APIs for account support
  - name: Auth
    description: Dormant self-serve Auth proxy routes gated by deployment config
  - name: Code
    description: Stateful code execution via Jupyter kernels (Code Interpreter)
  - name: Internal Operations
    description: Operator-only internal API surfaces; not part of the public SDK contract
paths:
  /v1/account/export:
    get:
      tags:
        - Account
      summary: Export account data
      description: |
        Dormant during the private-beta key-only e2e. This route returns
        `feature_unavailable` unless `NULLSPACE_SELF_SERVE_AUTH_ENABLED=true`
        is set. When enabled, it returns a JSON export of the user's account,
        personal team, key metadata, quota usage, and machine metadata.
      operationId: exportAccount
      responses:
        '200':
          description: Account export JSON
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccountExportResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/EmailNotVerified'
        '503':
          $ref: '#/components/responses/AuthProxyUnavailable'
      security:
        - sessionAuth: []
components:
  schemas:
    AccountExportResponse:
      type: object
      description: Full account data export assembled from the control-plane store.
      required:
        - user
        - team
        - quota_tier
        - quota_usage
        - api_keys
        - machines
      properties:
        user:
          $ref: '#/components/schemas/AccountUser'
        team:
          $ref: '#/components/schemas/Team'
        quota_tier:
          $ref: '#/components/schemas/QuotaTier'
        quota_usage:
          type: array
          items:
            $ref: '#/components/schemas/TeamQuotaUsage'
        api_keys:
          type: array
          items:
            $ref: '#/components/schemas/AccountExportApiKey'
        machines:
          type: array
          description: >-
            Raw machine rows projected from the control-plane store with columns
            id, template, status, metadata, started_at, destroyed_at,
            created_at, updated_at.
          items:
            type: object
            additionalProperties: true
            description: >-
              Deliberately open: raw row projection whose metadata column is
              free-form user metadata and whose column set tracks control-plane
              migrations.
    AccountUser:
      type: object
      required:
        - id
        - email
        - tier
        - quota_tier_id
        - is_operator
        - created_at
        - updated_at
      properties:
        id:
          type: string
          format: uuid
        email:
          type: string
          format: email
        name:
          type: string
          nullable: true
        display_name:
          type: string
          nullable: true
        avatar_url:
          type: string
          nullable: true
        tier:
          type: string
        quota_tier_id:
          type: string
        email_verified_at:
          type: string
          format: date-time
          nullable: true
        is_operator:
          type: boolean
        soft_deleted_at:
          type: string
          format: date-time
          nullable: true
        delete_scheduled_at:
          type: string
          format: date-time
          nullable: true
        abuse_flags:
          type: object
          additionalProperties: true
          description: >-
            Server-accumulated abuse-detection flags (for example signup_ip,
            signup_ip_cluster, flagged_at). Key set evolves with detection
            heuristics; deliberately open.
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
    Team:
      type: object
      required:
        - id
        - name
        - slug
        - owner_user_id
        - quota_tier_id
        - created_at
        - updated_at
      properties:
        id:
          type: string
          format: uuid
        name:
          type: string
        slug:
          type: string
        owner_user_id:
          type: string
          format: uuid
        quota_tier_id:
          type: string
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
        soft_deleted_at:
          type: string
          format: date-time
          nullable: true
    QuotaTier:
      type: object
      required:
        - id
        - display_name
        - max_concurrent_machines
        - daily_machine_creates
        - daily_gb_hours
      properties:
        id:
          type: string
        display_name:
          type: string
        max_concurrent_machines:
          type: integer
        daily_machine_creates:
          type: integer
        daily_gb_hours:
          type: number
    TeamQuotaUsage:
      type: object
      required:
        - team_id
        - usage_date
        - machine_creates
        - gb_hours
        - updated_at
      properties:
        team_id:
          type: string
          format: uuid
        usage_date:
          type: string
          format: date
        machine_creates:
          type: integer
        gb_hours:
          type: number
        updated_at:
          type: string
          format: date-time
    AccountExportApiKey:
      type: object
      description: >-
        Raw API key row included in the account export. Unlike ApiKeyInfo this
        is the unprojected row (key_prefix rather than prefix, plus owner ids);
        every field is always present, with null for unset values.
      required:
        - id
        - user_id
        - team_id
        - key_prefix
        - name
        - is_active
        - created_at
        - last_used_at
        - scope
        - revoked_at
        - expires_at
        - rotation_parent_key_id
      properties:
        id:
          type: string
          format: uuid
        user_id:
          type: string
          format: uuid
          nullable: true
        team_id:
          type: string
          format: uuid
          nullable: true
        key_prefix:
          type: string
        name:
          type: string
          nullable: true
        is_active:
          type: boolean
        created_at:
          type: string
          format: date-time
          nullable: true
        last_used_at:
          type: string
          format: date-time
          nullable: true
        scope:
          type: string
          nullable: true
        revoked_at:
          type: string
          format: date-time
          nullable: true
        expires_at:
          type: string
          format: date-time
          nullable: true
        rotation_parent_key_id:
          type: string
          format: uuid
          nullable: true
    ErrorResponse:
      type: object
      required:
        - error
        - code
      properties:
        error:
          type: string
          description: Human-readable error message
        code:
          type: string
          description: Machine-readable error code
          enum:
            - invalid_request
            - machine_not_found
            - snapshot_not_found
            - template_not_found
            - template_build_not_found
            - template_name_claim_not_found
            - machine_not_ready
            - unauthorized
            - auth_failed
            - auth_locked
            - auth_proxy_error
            - auth_proxy_unavailable
            - invalid_auth_redirect
            - invalid_oauth_provider
            - captcha_required
            - captcha_failed
            - captcha_unavailable
            - disposable_email
            - signup_rate_limited
            - oauth_rate_limited
            - email_action_rate_limited
            - database_error
            - email_not_verified
            - account_deleted
            - operator_required
            - account_not_found
            - account_not_soft_deleted
            - account_hard_delete_active_resources
            - file_upload_error
            - build_error
            - exec_timeout
            - exec_failed
            - file_error
            - not_implemented
            - capacity_exceeded
            - QUOTA_EXCEEDED
            - feature_unavailable
            - snapshot_in_use
            - no_eligible_runtime_host
            - same_host_required
            - incompatible_snapshot
            - rebuild_required
            - rate_limit_exceeded
            - transition_in_progress
            - transition_conflict
            - agent_deployment_not_found
            - agent_deployment_version_not_found
            - agent_run_not_found
            - agent_service_instance_not_found
            - agent_deployment_name_conflict
            - agent_deployment_idempotency_mismatch
            - agent_deployment_invalid_config
            - agent_deployment_invalid_state
            - volume_beta_restriction
            - volume_invalid_mount_path
            - volume_overlapping_mounts
            - volume_backend_capability_unsupported
            - volume_quota_exceeded
            - volume_mount_credential_issue_failed
            - volume_backend_unavailable
            - volume_stale_revision
            - volume_busy
            - volume_read_only
            - volume_limit_exceeded
            - internal_error
        error_detail:
          $ref: '#/components/schemas/ErrorDetail'
        request_id:
          type: string
          description: Request correlation ID returned in the `x-request-id` header
        build_id:
          type: string
          description: Template build ID when the error is associated with a tracked build
    ErrorDetail:
      oneOf:
        - $ref: '#/components/schemas/TemplateFailureDetail'
        - $ref: '#/components/schemas/UploadFailureDetail'
    TemplateFailureDetail:
      type: object
      required:
        - code
        - message
        - phase
        - retryable
        - suggested_action
      properties:
        code:
          type: string
          enum:
            - unauthorized
            - file_upload_error
            - build_error
            - internal_error
        message:
          type: string
        phase:
          $ref: '#/components/schemas/TemplateFailurePhase'
        retryable:
          type: boolean
        suggested_action:
          type: string
        step_index:
          type: integer
        attempt:
          type: integer
        max_attempts:
          type: integer
        cache_subject:
          type: string
        build_id:
          type: string
        request_id:
          type: string
          description: >-
            Present on terminal request-originated failures and blocking error
            responses.
        details:
          type: object
          additionalProperties: true
          description: >-
            Stable failure metadata. Includes a `reason` key plus phase-specific
            fields such as `blob_id`, `path`, digest/size mismatch values,
            `command`, or `alias`.
    UploadFailureDetail:
      type: object
      required:
        - reason
        - message
        - retryable
      properties:
        reason:
          $ref: '#/components/schemas/UploadFailureReason'
        message:
          type: string
        retryable:
          type: boolean
        upload_id:
          type: string
        request_id:
          type: string
        path:
          type: string
          description: >-
            Normalized absolute machine path associated with the failed upload
            when available.
        part_number:
          type: integer
          format: uint32
        details:
          type: object
          additionalProperties: true
          description: >-
            Additional failure diagnostics; keys depend on the failure reason,
            deliberately open.
    TemplateFailurePhase:
      type: string
      enum:
        - auth
        - preflight
        - blob_upload
        - prepare
        - build_step
        - readiness
        - snapshot
        - finalize
        - interrupted
    UploadFailureReason:
      type: string
      enum:
        - insufficient_staging_space
        - size_limit_exceeded
        - invalid_part_checksum
        - part_out_of_range
        - part_size_mismatch
        - whole_checksum_mismatch
        - upload_expired
        - upload_aborted
        - upload_already_completed
        - target_conflict
        - directory_extract_invalid_path
        - directory_extract_invalid_symlink
        - directory_extract_unsupported_entry
        - missing_parts
  responses:
    Unauthorized:
      description: Missing or invalid bearer credential
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            unauthorized:
              summary: Missing or invalid bearer credential
              value:
                error: Missing or invalid bearer credential
                code: unauthorized
                request_id: req_123
    EmailNotVerified:
      description: Supabase session exists but the email address is not verified.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            emailNotVerified:
              summary: Verified email required
              value:
                error: Verify your email before using self-serve API routes
                code: email_not_verified
                request_id: req_123
    AuthProxyUnavailable:
      description: Self-serve Auth proxy is not configured or temporarily unavailable.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: API key passed as Bearer token
    sessionAuth:
      type: http
      scheme: bearer
      description: Supabase Auth access token passed as Bearer token

````