# \-X DELETE returns 204; Client/Platform doesn't Update

**URL:** <https://hub.mender.io/t/x-delete-returns-204-client-platform-doesnt-update/7802>\
**Category:** General Discussions\
**Tags:** api\
**Created:** [May 30, 2025, 4:04pm UTC](https://hub.mender.io/t/x-delete-returns-204-client-platform-doesnt-update/7802 "2025-05-30T16:04:47Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![jj\_menderio](https://avatars.discourse-cdn.com/v4/letter/j/ed8c4c/32.png) [@jj\_menderio](https://hub.mender.io/u/jj_menderio)\
**Post date:** [May 30, 2025, 4:04pm UTC](https://hub.mender.io/t/x-delete-returns-204-client-platform-doesnt-update/7802/1 "2025-05-30T16:04:47Z")

</div>

Working with the API via Bash scripting.

Using the following code to Dismiss (delete) a device

```auto
  local url="$BASE_URL/api/management/v1/inventory/devices/$device_id"
  local tmp_response=$(mktemp)

  log "INFO" "Trying to dismiss device $device_id (auth: $auth_id)"

  local status_code=$(curl -s -o "$tmp_response" -w "%{http_code}" -X DELETE "$url" \
    -H "Content-Type: application/json" \
    -H "Authorization: Bearer $MENDER_TOKEN" )

```

The mktemp is for logging purposes

Created logging which returns the following:

```auto
[INFO] [Trying to dismiss device [device-id] (auth: [auth-id])]
[INFO] [✅ Request succeeded: HTTP 204]

```

Device does not update. The GUI does not reflect this change.

Tried multiple times over the course of a day, with same results.

Logs on the device itself also do not update when sending the DELETE request

Can go into the GUI and Dismiss from there, and the device moves from “Accepted” to “Noauth” to “Pending” within a minute.

Logs on device do update when Dismissing via the GUI

From another Bash script, I can accept the device, which is also successful, and the GUI and device info updates almost immediately, but attempting to Dismiss (delete) from CLI still doesn’t take.

For insight, logs on device do not update when sending an Accept request from the API

Is there something I am missing here? Am I using the API wrong or the wrong part of the API to do this?

---

<div class="post-metadata">

**Author:** ![TheYoctoJester](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/theyoctojester/32/1444_2.png) [@TheYoctoJester](https://hub.mender.io/u/TheYoctoJester)\
**Post date:** [June 2, 2025, 7:35pm UTC](https://hub.mender.io/t/x-delete-returns-204-client-platform-doesnt-update/7802/2 "2025-06-02T19:35:57Z")

</div>

Hi @jj_menderio,

I think you’re basically on the right track. However there is one thing to note here. There is a difference between “dismissing” and “decommissioning” a device. The former deletes a specific certificate which the device has provided for authentication, while the latter completely removes the device from the fleet. The API endpoint is [Mender API docs](https://docs.mender.io/api/#management-api-device-authentication-decommission-device).

Note though, that decommissioning a device will only work in a meaningful way if the device also has been disabled and stopped its connection attempts to the backend, otherwise it will just reappear as pending upon the next cycle.

Greetz,  
Josef

---

<div class="post-metadata">

**Author:** ![jj\_menderio](https://avatars.discourse-cdn.com/v4/letter/j/ed8c4c/32.png) [@jj\_menderio](https://hub.mender.io/u/jj_menderio)\
**Post date:** [June 3, 2025, 5:35pm UTC](https://hub.mender.io/t/x-delete-returns-204-client-platform-doesnt-update/7802/3 "2025-06-03T17:35:47Z")

</div>

Thank you for taking the time to respond.

Could you tell me how “dismissing” and “decommissioning” relate/differ and function within the context of the DELETE command of the API?

Could you also expand upon that to help me understand if I am using DELETE in the correct way, and if so, why I am experiencing no update though I am receiving a successful 204?

---

<div class="post-metadata">

**Author:** ![TheYoctoJester](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/theyoctojester/32/1444_2.png) [@TheYoctoJester](https://hub.mender.io/u/TheYoctoJester)\
**Post date:** [June 4, 2025, 8:12am UTC](https://hub.mender.io/t/x-delete-returns-204-client-platform-doesnt-update/7802/4 "2025-06-04T08:12:55Z")

</div>

Hi @jj_menderio,

So for the API side:

- “dismissing” means that an auth(entication) set is removed. The endpoint is [Mender API docs](https://docs.mender.io/api/#management-api-device-authentication-reject-authentication)
- “decommissioning” means that the device and all of its auth sets are removed. The endpoint is [Mender API docs](https://docs.mender.io/api/#management-api-device-authentication-decommission-device)

Concerning the changes being visible in the UI, my guess is that when you trigger a change there, then the web UI refreshes relatively soon, whereas without interaction and the changes happening through the API the next refresh might take some time.

What do you mean by “logs on the device do update”? My understanding is that those should reflect the change upon next polling cycle in both cases.

Greetz,  
Josef

---

<div class="post-metadata">

**Author:** ![jj\_menderio](https://avatars.discourse-cdn.com/v4/letter/j/ed8c4c/32.png) [@jj\_menderio](https://hub.mender.io/u/jj_menderio)\
**Post date:** [June 5, 2025, 3:56pm UTC](https://hub.mender.io/t/x-delete-returns-204-client-platform-doesnt-update/7802/5 "2025-06-05T15:56:39Z")

</div>

> …whereas without interaction and the changes happening through the API the next refresh might take some time.

Would you think 8+ hours might be too long of a time to wait?

What if I told you rebooting the device and restarting the mender process also didn’t update the UI nor the API pull requests (as in, after receiving the 204 Confirmation, and waiting, and rebooting the device, and restarting the process, the API GET commands still show the Device as Accepted)?

> What do you mean by “logs on the device do update”? My understanding is that those should reflect the change upon next polling cycle in both cases.

When tailing journalctl for mender updates, logs will appear when Dismissing via the Web based GUI.  
Logs do not update when a DELETE command is sent via the API, nor do they appear when submitting a GET command via the API to update the “status” to “accepted”.

---

<div class="post-metadata">

**Author:** ![jj\_menderio](https://avatars.discourse-cdn.com/v4/letter/j/ed8c4c/32.png) [@jj\_menderio](https://hub.mender.io/u/jj_menderio)\
**Post date:** [June 5, 2025, 4:09pm UTC](https://hub.mender.io/t/x-delete-returns-204-client-platform-doesnt-update/7802/6 "2025-06-05T16:09:27Z")

</div>

Also, thank you for those links, as it helps provide clarity, and looking at them makes me think we have different understandings:

- What you list as Dismissing, I understand it as [Decommissioning](https://docs.mender.io/api/#management-api-device-authentication-decommission-device)
  - `curl -X DELETE https://hosted.mender.io/api/management/v2/devauth/devices/{id}`

- What you listed as Decommissioning, I understand it as [Rejecting](https://docs.mender.io/api/#management-api-device-authentication-reject-authentication)
  - `curl -X DELETE https://hosted.mender.io/api/management/v2/devauth/devices/{id}/auth/{aid} `

And if my understanding is correct of those two previous, this is my understanding of [Dismissing](https://docs.mender.io/api/#management-api-device-inventory-delete-device-inventory)

```auto
curl -X DELETE https://hosted.mender.io/api/management/v1/inventory/devices/{id} 

```

---

<div class="post-metadata">

**Author:** ![TheYoctoJester](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/theyoctojester/32/1444_2.png) [@TheYoctoJester](https://hub.mender.io/u/TheYoctoJester)\
**Post date:** [June 5, 2025, 7:33pm UTC](https://hub.mender.io/t/x-delete-returns-204-client-platform-doesnt-update/7802/7 "2025-06-05T19:33:51Z")

</div>

Hi @jj_menderio

> [@jj\_menderio](#):
>
> Would you think 8+ hours might be too long of a time to wait?

Nope that’s definitely too long. I would expect it to show the change within 5-10 minutes.

> [@jj\_menderio](#):
>
> What if I told you rebooting the device and restarting the mender process also didn’t update the UI nor the API pull requests (as in, after receiving the 204 Confirmation, and waiting, and rebooting the device, and restarting the process, the API GET commands still show the Device as Accepted)?

Then I can just conclude that there is something else that we’re not seeing yet unfortunately, sorry.

Greetz,  
Josef

---

<div class="post-metadata">

**Author:** ![alfrunes](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/alfrunes/32/703_2.png) [@alfrunes](https://hub.mender.io/u/alfrunes)\
**Post date:** [June 6, 2025, 11:06am UTC](https://hub.mender.io/t/x-delete-returns-204-client-platform-doesnt-update/7802/8 "2025-06-06T11:06:55Z")

</div>

Hi @jj_menderio 👋

> And if my understanding is correct of those two previous, this is my understanding of [Dismissing](https://docs.mender.io/api/#management-api-device-inventory-delete-device-inventory)
> 
> ```auto
> curl -X DELETE https://hosted.mender.io/api/management/v1/inventory/devices/{id} 
> 
> ```

This assumption is not correct. The above API is clearing the `inventory` attributes from a device, that is, the data submitted by the device to the inventory APIs. The other two `devauth` APIs are managing the device’s authentication data (think of it as the device’s certificate, it consist of the data identifying the device and an asymmetric key proving ownership).

As I can see there are some misuse of the term “rejecting” in the API documentation, let me see if I can rephrase it:

- `Rejecting a device is calling the [Set Authentication Status](https://docs.mender.io/api/#management-api-device-authentication-set-authentication-status) API with status `rejected`
- Decommissioning a device is calling the [Decommission Device](https://docs.mender.io/api/#management-api-device-authentication-decommission-device) API
- Dismissing a device is calling the [~~Reject~~ (remove) authentication](https://docs.mender.io/api/#management-api-device-authentication-reject-authentication) API

---

<div class="post-metadata">

**Author:** ![jj\_menderio](https://avatars.discourse-cdn.com/v4/letter/j/ed8c4c/32.png) [@jj\_menderio](https://hub.mender.io/u/jj_menderio)\
**Post date:** [June 6, 2025, 4:10pm UTC](https://hub.mender.io/t/x-delete-returns-204-client-platform-doesnt-update/7802/9 "2025-06-06T16:10:32Z")

</div>

Thank you for jumping in and providing more clarity.

And yes, the docs are a bit confusing regarding rejecting, decommissioning, and dismissing.

For further clarification, if I want to “Dismiss” a device, I would follow the last Bullet:

> Dismissing a device is calling the [~~Reject~~ (remove) authentication](https://docs.mender.io/api/#management-api-device-authentication-reject-authentication) API

This should allow me to remove a device from Accepted without removing it’s history, and then later re-Accept it when desired.

Is that accurate?

---

<div class="post-metadata">

**Author:** ![alfrunes](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/alfrunes/32/703_2.png) [@alfrunes](https://hub.mender.io/u/alfrunes)\
**Post date:** [June 10, 2025, 7:22am UTC](https://hub.mender.io/t/x-delete-returns-204-client-platform-doesnt-update/7802/10 "2025-06-10T07:22:51Z")

</div>

Exactly! 👍

---

<div class="post-metadata">

**Author:** ![jj\_menderio](https://avatars.discourse-cdn.com/v4/letter/j/ed8c4c/32.png) [@jj\_menderio](https://hub.mender.io/u/jj_menderio)\
**Post date:** [June 10, 2025, 4:04pm UTC](https://hub.mender.io/t/x-delete-returns-204-client-platform-doesnt-update/7802/11 "2025-06-10T16:04:35Z")

</div>

Thank you!
