Delete a withdrawal address (soft deletion; no step-up authentication)
On behalf of a member ·
x-on-behalf-of required
Soft deletion, not physical removal: sets a deletion flag while historical withdrawal orders can still reference the row. Orders also contain an address snapshot, so their details are unaffected.
Step-up authentication is deliberately omitted: deletion improves safety. Obstructing it only penalizes legitimate users without stopping attackers, whose goal is to add their own address, a step already protected by step-up authentication and a cooling period.
Idempotency middleware is also deliberately omitted. Deleting the same address again returns 404 without side effects.
The same address can be added again after deletion, but it creates a new record, and the 24-hour cooling period starts over.
Path Parameters
| Field | Type | Required | Description |
|---|---|---|---|
id |
string | Required | Address ID, with or without the wad_ prefix. |
Request Headers
| Field | Type | Required | Description |
|---|---|---|---|
x-on-behalf-of |
string | Required | The member whose address to delete. |
Response
200Deleted
{
"deleted": true
}404
not_found: nonexistent, not owned by this member, or already deleted.
All three return the same response.
member_not_found: member does not exist, belongs to another merchant, or is suspended.Request
curl -X DELETE 'https://api.zinfra.vip/v1/withdraw-addresses/{id}' \
-H 'x-auth-token: Bearer $TOKEN' \
-H 'x-on-behalf-of: $MEMBER_ID'const res = await fetch("https://api.zinfra.vip/v1/withdraw-addresses/{id}", {
method: "DELETE",
headers: {
"x-auth-token": "Bearer $TOKEN",
"x-on-behalf-of": "$MEMBER_ID",
},
});
// Keep monetary amounts as strings, never numbers.
const data = await res.json();import requests
res = requests.delete(
"https://api.zinfra.vip/v1/withdraw-addresses/{id}",
headers={
"x-auth-token": "Bearer $TOKEN",
"x-on-behalf-of": "$MEMBER_ID",
},
)
# Use Decimal(str(...)) for amounts, not float.
data = res.json()req, _ := http.NewRequest("DELETE", "https://api.zinfra.vip/v1/withdraw-addresses/{id}",
nil)
req.Header.Set("x-auth-token", "Bearer $TOKEN")
req.Header.Set("x-on-behalf-of", "$MEMBER_ID")
res, err := http.DefaultClient.Do(req)
// Decode amount fields as string, not float64.HttpRequest req = HttpRequest.newBuilder()
.uri(URI.create("https://api.zinfra.vip/v1/withdraw-addresses/{id}"))
.header("x-auth-token", "Bearer $TOKEN")
.header("x-on-behalf-of", "$MEMBER_ID")
.method("DELETE", HttpRequest.BodyPublishers.noBody())
.build();
// Use String / BigDecimal for amounts, not double.$ch = curl_init('https://api.zinfra.vip/v1/withdraw-addresses/{id}');
curl_setopt_array($ch, [
CURLOPT_CUSTOMREQUEST => 'DELETE',
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'x-auth-token: Bearer $TOKEN',
'x-on-behalf-of: $MEMBER_ID',
],
]);
$res = curl_exec($ch);
// Use bcmath / strings for amounts, not floatval.
200
{
"deleted": true
}