# Close all positions and orders

`POST /accounts/{accountId}/close-all`

Cancels every active order on the account and then closes every open position at market.

- Responds `204` with no body; the resulting fills appear in the position history and in the account events.
- Send an `x-idempotency-key` header to make the call replay-safe: inside the replay window stated on that header, the same key on the same route replays the stored response (marked with `X-Idempotency-Cached: true` and `X-Idempotency-Timestamp`) instead of acting again, and a second call arriving while the first one is still running gets `409` (`idempotency_key_in_flight`).

## Authorization

bearer: http · bearer (required). Personal API key, prefixed with `usk_`.

## Parameters

- path: accountId (string · uuid; required). Trader account identifier. Must belong to the caller.

Type: string · uuid

format: uuid

- header: x-idempotency-key (string; optional). Idempotency key — any opaque string, a uuid v4 works well. Repeating the call with the same key on this route within 1 minute replays the stored response instead of acting again; a replay carries `X-Idempotency-Cached: true` and `X-Idempotency-Timestamp`. Omit the header to opt out.

Type: string

Example: "9f1c2b7e-5a3d-4f61-9b0e-2c7d4a8e1f35"

## Example · cURL

```bash
curl --request POST 'https://api.upscale.trade/accounts/{accountId}/close-all' \
  --header 'Accept: application/json' \
  --header 'Authorization: Bearer YOUR_API_KEY'
```

## Example · JavaScript

```javascript
const response = await fetch("https://api.upscale.trade/accounts/{accountId}/close-all", {
  method: "POST",
  headers: {
    "Accept": "application/json",
    "Authorization": "Bearer YOUR_API_KEY"
  },
});
console.log(response.status, await response.text());
```

## Example · Python

```python
import requests

response = requests.request(
    "POST",
    "https://api.upscale.trade/accounts/{accountId}/close-all",
    headers={"Accept":"application/json","Authorization":"Bearer YOUR_API_KEY"},
    timeout=30,
)
print(response.status_code, response.text)
```

## Response 401

**401**  — Unauthorized

## Response 403

**403**  — The account belongs to another user (`account_access_denied`), or the request is authenticated with an API key while `api_trading` is disabled on the account (`api_trading_not_enabled`).

## Response 404

**404**  — No account with this identifier.

## Response 409

**409**  — Another call with the same `x-idempotency-key` is still running (`idempotency_key_in_flight`). Retry once it finishes.

## Response 429

**429**  — Rate limit of the API key exceeded (`api_key_rate_limit_exceeded`). `Retry-After` says when to come back; the body carries the bucket (`read` / `write`), the window that tripped, its limit and `retryAt`.