# Delete a point entry

`DELETE https://api.cademi.com.br/api/v3/users/{user_id}/scores/{score_id}`

Operation ID: `users.scores.delete` · API v3

Permanently deletes a manual point entry from the user's points ledger, such as one created by `POST /users/{user_id}/score-adjustments` or added in the dashboard. A `reason` is required in the request body, and the deletion is recorded as a progress adjustment with its reason and author.

The user's balance changes by the negative of the entry's points, and a `score.deleted` event is published. Points earned automatically (lessons, courses, certificates, questions, comments and exams) cannot be deleted and return `422` with the `score_not_removable` error code.

Required permissions: `scores.delete`.

## Parameters

| Name | In | Type | Required | Description |
|---|---|---|---|---|
| `user_id` | path | string | yes | Public ID of the user, prefixed with usr_. |
| `score_id` | path | string | yes | Public ID of the score, prefixed with sco_. |
| `Idempotency-Key` | header | string | no | Client-generated key that makes the request safe to retry. Must be 1 to 128 characters from [A-Za-z0-9.:-]. Optional on this operation; when sent, a malformed key returns idempotencykey_invalid, and repeating the request with the same key and the same body returns the stored result with Idempotent-Replayed: true. |
| `X-Client-Request-Id` | header | string | no | Optional client-generated identifier of the request, up to 64 characters from [A-Za-z0-9._-]. Echoed back in the response and recorded in the request log; it never replaces the server-generated X-Request-Id. |

## Request body

Content type: `application/json`, required.

| Field | Type | Required | Description |
|---|---|---|---|
| `reason` | string | yes |  |

## Responses

### 204

The point entry was deleted successfully.

### 400

The request could not be read. Returns malformedjson when the body is not a JSON object, jsontoodeep when it is nested more than 16 levels deep, and invalidutf8 when it is not valid UTF-8. On updates and deletions, also returns ifmatchinvalid when the If-Match header is neither * nor a value in the ETag format.

Body: Error.

### 401

The credential is missing, malformed, expired, or revoked.

Body: Error.

### 403

The current credentials do not have the permission required by this operation.

Body: Error.

### 404

The point entry was not found, does not belong to this user, or is not accessible with the current credentials.

Body: Error.

### 406

The Accept header does not allow a JSON response. Returns the not_acceptable error code.

Body: Error.

### 409

A request with the same Idempotency-Key cannot be completed now. Returns idempotencyinprogress while the original request is still being processed (retry later), resultuncertain when the outcome of the original request could not be confirmed, and secretnotreplayable or resultnot_replayable when its stored result cannot be returned again.

Body: Error.

### 422

The request body or query parameters failed validation (validationfailed), or the request was rejected with another error code that uses the same status, such as unknownfield or idempotencykeyreused.

Body: ValidationFailed.

### 429

The request rate limit was exceeded.

Body: RateLimitError.

Full schema: https://cademi.dev/openapi/v3.json
