Delete a subscription
Soft-deletes a subscription scoped to the authenticated tenant. The operation is idempotent: an absent, already-deleted, or cross-tenant id is a no-op that still answers 204 (no existence oracle).
Authorizations
A bearer JWT issued by plugin-auth (lib-auth). The tenant identity is resolved from the validated token claims; the /v1 surface never reads a tenant from the body, path, or query. Machine callers obtain a token via the plugin-auth client-credentials flow. The /admin surface authorizes against an operator scope and carries no tenant context.
Headers
A client-chosen unique key that makes this mutation at-most-once. A mutation sent without it is rejected before any write with 400 missing_idempotency_key. Reusing the same key with an identical request replays the original response byte-for-byte (with X-Idempotency-Replayed: true); reusing it with a different request body returns 409 idempotency_conflict. To re-drive a corrected request, mint a new key.
Path Parameters
The unique identifier of the subscription (UUIDv7).
Response
The subscription was deleted (or was already absent).

