> ## Documentation Index
> Fetch the complete documentation index at: https://docs.privy.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Freezing users

> Temporarily block a user from logging in to your app without deleting their account

Privy allows your app to freeze a user via their Privy user ID. Freezing is reversible. It suspends a user's access without deleting their account, linked accounts, or embedded wallets.

When your app freezes a user, Privy:

* Blocks the user from logging in to your app
* Revokes all of the user's active sessions
* Prevents the user from refreshing their access token
* Keeps the user's Privy ID, linked accounts, and embedded wallets unchanged

When your app unfreezes the user, the user can log in again. Privy does not restore revoked sessions, so the user must log in again.

<Note>
  Access tokens issued before the freeze remain valid until they expire. If your backend verifies
  access tokens itself, token verification alone does not enforce a freeze.
</Note>

## Freezing versus other controls

| Control | Identifies the user by | Reversible | Revokes active sessions |
| - | - | - | - |
| Freeze | Privy user ID | Yes | Yes |
| [Denylist](/user-management/users/managing-users/denylist) | Email, phone number, or wallet address | Yes | No |
| [Delete](/user-management/users/managing-users/deleting-users) | Privy user ID | No | Yes |

Freeze a user to pause their access, such as during an investigation of suspicious activity. Use the denylist to stop an identifier from logging in or creating accounts.

## Freezing a user

<View title="REST API" icon="terminal">
  Make a `POST` request to:

  ```bash theme={"system"}
  https://api.privy.io/v1/users/<user-id>/freeze
  ```

  Replace `<user-id>` with the user's Privy ID, in the format `did:privy:XXXXXX`.

  Authenticate with your app ID and app secret. Send an empty JSON body:

  ```bash theme={"system"}
  curl --request POST "https://api.privy.io/v1/users/<user-id>/freeze" \
  -u "<your-privy-app-id>:<your-privy-app-secret>" \
  -H "privy-app-id: <your-privy-app-id>" \
  -H 'Content-Type: application/json' \
  -d '{}'
  ```

  A successful request returns a `200` status code:

  ```json theme={"system"}
  {
    "success": true
  }
  ```
</View>

<View title="Dashboard" icon="react">
  To freeze a user via the dashboard:

  1. Navigate to the [Users page](https://dashboard.privy.io/?page=users\&tab=all-users)
  2. Select the user
  3. Click the **Revoke session** icon beside the user's status
  4. Keep **Additionally, freeze access to this account** selected (it is selected by default)
  5. Click `Revoke session`

  <Note>
    The **Revoke session** icon only appears when the user has an active session. To freeze a user without an active session, use the REST API.
  </Note>
</View>

## Unfreezing a user

<View title="REST API" icon="terminal">
  Make a `DELETE` request to the same path:

  ```bash theme={"system"}
  curl --request DELETE "https://api.privy.io/v1/users/<user-id>/freeze" \
  -u "<your-privy-app-id>:<your-privy-app-secret>" \
  -H "privy-app-id: <your-privy-app-id>" \
  -H 'Content-Type: application/json' \
  -d '{}'
  ```

  A successful request returns a `200` status code with `{"success": true}`.
</View>

<View title="Dashboard" icon="react">
  To unfreeze a user via the dashboard:

  1. Navigate to the [Users page](https://dashboard.privy.io/?page=users\&tab=all-users)
  2. Select the frozen user
  3. Click `Restore access`
</View>

## Behavior and errors

* **Idempotent requests**: Repeating a freeze or unfreeze request returns a `200` status code. Freezing an already frozen user keeps the original freeze time. Your app can safely retry either request.
* **Unknown users**: The API returns a `404` status code if the user does not exist or belongs to another app.
* **Authentication**: Missing or invalid app credentials return a `401` status code.
* **Server errors**: Retry a freeze request that returns a `5xx` status code. The user may already be frozen.
* **Activity logs**: Each freeze or unfreeze appears in your organization's Activity logs in the Privy dashboard and is attributed to an app secret.

See the API reference for [freezing](/api-reference/users/freeze) and [unfreezing](/api-reference/users/unfreeze) users.
