Clear all memories for the current user, or everything if nuclear=true.
WARNING: This deletes memories. Cannot be undone. If nuclear=true, deletes EVERYTHING (graph + cache + vectors) for dev/cleanup.
SEC-ROUTE-AUTHZ-1 H10: the nuclear path wipes the entire deployment (all tenants), so it requires the superadmin role. The ordinary scoped clear (own memories only) stays open to any authenticated user.
The role check says WHO may wipe, never WHICH deployment gets wiped, which
is how the service security suite erased a developer host's shared graph on
2026-08-21. assert_nuclear_allowed adds the missing target control: the
nuclear path additionally requires SMARTMEMORY_ALLOW_NUCLEAR_CLEAR=true AND
a target graph that is not in SMARTMEMORY_NUCLEAR_PROTECTED_GRAPHS. See
memory_service/api/nuclear_guard.py.
Query Parameters
Response Body
application/json
application/json
curl -X DELETE "https://example.com/memory/clear-all"null{
"detail": [
{
"loc": [
"string"
],
"msg": "string",
"type": "string",
"input": null,
"ctx": {}
}
]
}