# (NEW!) Remove Rights Association Remove a rights-management association between two objects, along with any downstream relationships that are only justified by that association. This replaces the client-side relationship traversal previously performed by the Rights Management UI — the caller supplies the two objects participating in the association, and the backend determines and removes the applicable relationship set. Supported Associations: - Project Agreement — removes the direct relationship and any downstream relationships justified solely by it. The Project and Agreement objects are not deleted. Relationships still justified by another valid association are preserved. Works regardless of which object is primary. - Agreement Entity — removes the direct relationship and any downstream relationships justified solely by it. The Agreement and Entity objects are not deleted. Relationships still justified by another valid association are preserved. Works regardless of which object is primary. - Agreement -> Right — a Right is contained by its Agreement, so removing this association soft-deletes the Right using the existing Right deletion behavior. Any other object-type pair is unsupported and returns 400. Relationship types such as child, derivative, and placed-graphic are out of scope for this endpoint. Business Rules: - customerId and the requesting user's identity are read exclusively from the authenticated ID token — they are never accepted from the request body. - All relationship reads and deletes are scoped to the authenticated customer. Cross-customer objects or relationships are never returned, traversed, or modified. - This operation is idempotent — retrying a removal after the applicable relationships have already been removed succeeds without corrupting data or failing solely because those relationships are already absent. The user submitting the request must have WRITE authorization for Rights Management. Endpoint: POST /rights/associations/removal Version: 1.5 Security: ApiKeyAuth, BasicAuth ## Header parameters: - `X-API-Key` (string, required) Customer-specific API key required to invoke API. - `Authorization` (string, required) Provided by Authentication Token creation operation. - `Content-Type` (string, required) Enum: "application/json" ## Request fields (application/json): - `primary` (object, required) One of the two objects participating in the association. - `primary.objectId` (string, required) Unique ID of the object. Example: "6543a6a0-4b5d-4a54-94a8-e6c7733fe92c" - `primary.objectType` (string, required) Type of the object. Enum: "RM - Agreement", "RM - Project", "RM - Entity", "RM - Right" - `secondary` (object, required) The other of the two objects participating in the association. ## Response 200 fields (application/json): - `status` (string) Enum: "success" - `removed` (object) - `removed.relationships` (array) All relationships removed by the operation, including any downstream relationships justified solely by the removed association. - `removed.relationships.primaryId` (string) Object ID on the primary side of the removed relationship. Example: "6543a6a0-4b5d-4a54-94a8-e6c7733fe92c" - `removed.relationships.secondaryId` (string) Object ID on the secondary side of the removed relationship. Example: "42ac8e81-8113-49fd-977b-a2001ad3d7c8" - `removed.relationships.linkType` (string) The type of relationship that was removed. Example: "rm-project-agreement" - `removed.objects` (array) Objects removed as a consequence of the association removal. Empty for Project Agreement and Agreement Entity removals. Contains the soft-deleted Right for Agreement -> Right removals. - `removed.objects.id` (string) Unique ID of the removed object. Example: "9b1f3c2a-1234-4a54-94a8-e6c7733fe92c" - `removed.objects.objectType` (string) Type of the removed object. Example: "RM - Right" - `removed.objects.status` (string) Lifecycle status of the object after removal. Enum: "deleted" - `removed.objects.lastUpdatedEpoch` (integer) Unix timestamp (ms) of the soft-delete. Example: 1773070355217 - `removed.objects.lastUpdatedDate` (string) ISO 8601 date of the soft-delete. Example: "2026-03-09T15:32:35.217Z" ## Response 400 fields (application/json): - `status` (string) Example: "error" - `message` (string) ## Response 401 fields (application/json): - `status` (string) Example: "error" - `message` (string) ## Response 403 fields (application/json): - `status` (string) Example: "error" - `message` (string) ## Response 404 fields (application/json): - `status` (string) Example: "error" - `message` (string) ## Response 422 fields (application/json): - `status` (string) Example: "error" - `message` (string)