# Disable the SFTP account

Page: https://sandbox.myclaimhouse.com/docs/api/disableSftpAccount

`POST /api/v1/sftp-account/disable`

Refuses every new login at once, with the password or a key. A session already open stays open until the client disconnects or has been idle 15 minutes. Files already in the folders stay where they are, and nothing dropped in IN or TEST/IN is taken until the account is enabled. Send an empty JSON object as the body. Needs an Idempotency-Key header and a key with the submit permission.

Needs a key with `submit` permission.

## Request

### Headers

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `Idempotency-Key` | string | Yes | Makes the request safe to repeat: a request with the same key and body returns the first answer (the reply has an idempotent-replayed header), and the same key with a different request is refused. 1 to 255 printable characters; a UUID is a good choice. At least 1 character. At most 255 characters. Matches `^[\x21-\x7e]{1,255}$`. |

## Response

The account as it is now. Status `200`.

| Name | Type | Description |
| --- | --- | --- |
| `id` | string | An ID that starts with sftp_. |
| `object` | string | Always `sftp_account`. |
| `status` | string | A disabled account is refused at login; its files stay where they are. One of: `active`, `disabled`. |
| `username` | string | The user name to log in with. |
| `host` | value | The host to connect to; null in an environment that has no SFTP host. |
| `port` | integer or null | The port to connect to; null in an environment that has no SFTP host. At least -9007199254740991. |
| `host_key_fingerprint` | value | The SHA256 fingerprint of the server's host key: check it the first time you connect. Null in an environment that has no SFTP host. |
| `folders` | object | The folders of the account. A file dropped in a folder under TEST is a test file; the folder is the mode. |
| `folders.test` | object |  |
| `folders.test.in` | string | Always `TEST/IN`. |
| `folders.test.out` | string | Always `TEST/OUT`. |
| `folders.live` | object |  |
| `folders.live.in` | string | Always `IN`. |
| `folders.live.out` | string | Always `OUT`. |
| `keys` | array of object | The public keys that may log in, at most 5. At most 5 items. |
| `keys[].id` | string | An ID that starts with sfk_. |
| `keys[].object` | string | Always `sftp_key`. |
| `keys[].label` | string | The name you gave the key. At most 64 characters. |
| `keys[].fingerprint` | string | The key's SHA256 fingerprint, as ssh-keygen -l shows it. |
| `keys[].added_at` | string (date-time) |  |
| `last_login_at` | string (date-time) or null |  |
| `last_file_at` | string (date-time) or null | When the last file dropped on the account was taken. |
| `created_at` | string (date-time) |  |

## Errors

| HTTP status | Code | What it means |
| --- | --- | --- |
| 401 | `UNAUTHORIZED` | A valid API key is required. Send it as "Authorization: Bearer <key>". |
| 403 | `PERMISSION_DENIED` | This API key is not allowed to do that. |
| 404 | `NOT_FOUND` | Not found. |
| 422 | `INVALID_REQUEST` | The request is not valid. |
| 400 | `IDEMPOTENCY_KEY_REQUIRED` | POST and PATCH requests need an Idempotency-Key header. |
| 422 | `IDEMPOTENCY_KEY_REUSED` | That Idempotency-Key was already used with a different request. |
| 409 | `IDEMPOTENCY_KEY_IN_USE` | A request with that Idempotency-Key is still running. Retry shortly. |
| 413 | `PAYLOAD_TOO_LARGE` | The request body is larger than 1 MB. |
| 504 | `TIMEOUT` | The request took too long to finish. It may still have taken effect: look it up before sending it again with a new Idempotency-Key. What it made is found with GET /api/v1/eligibility?request_id=<this request_id>, and the same filter on /api/v1/claims and /api/v1/attachments (a key with read permission). |
| 500 | `INTERNAL` | Something went wrong on our side. Quote the request ID if you contact us. |

## Example

### Example request

```bash
curl -X POST "https://sandbox.myclaimhouse.com/api/v1/sftp-account/disable" \
  -H "Authorization: Bearer $CLAIMHOUSE_KEY" \
  -H "Idempotency-Key: $(uuidgen)" \
  -H "Content-Type: application/json" \
  -d '{}'
```

### Example response: 200

```json
{
  "id": "sftp_01JM000000E00800000000008G",
  "object": "sftp_account",
  "status": "disabled",
  "username": "example-dental-group",
  "host": "sftp.example.com",
  "port": 22,
  "host_key_fingerprint": "SHA256:3rJq0nX1m2Yw8dVf5uQ7bT9kLz4cE6hA1sPoGvNxYdI",
  "folders": {
    "test": {
      "in": "TEST/IN",
      "out": "TEST/OUT"
    },
    "live": {
      "in": "IN",
      "out": "OUT"
    }
  },
  "keys": [
    {
      "id": "sfk_01JM000000E00800000000008H",
      "object": "sftp_key",
      "label": "Billing server",
      "fingerprint": "SHA256:Nn0vBzE3Lx9sT2kqYw7dPfH5cRj8uAm1GoVtXiQ4eZs",
      "added_at": "2026-09-24T15:05:00+00:00"
    }
  ],
  "last_login_at": "2026-09-24T21:00:00+00:00",
  "last_file_at": "2026-09-24T21:01:00+00:00",
  "created_at": "2026-09-24T15:00:00+00:00"
}
```
