---
operationId: "recoverProject"
method: "POST"
path: "/programs/{program_id}/recover"
tag: "projects"
stability: "beta"
interfaces: ["api", "sdk", "cli"]
---
> API Reference / Programs / Recover a deleted program

## POST /programs/{program_id}/recover

Recovers a deleted program within the 7-day deletion recovery period.
Restores frameworks, endpoints, settings, and connection strings.
Some integrations require manual reconfiguration after recovery.
To list recoverable programs, use `GET /programs?recoverable=true`.


### Parameters

- `program_id` (string, path, required)
  The OptiTech program ID

### Response (200)

- `program` (object, optional)
  - `data_storage_bytes_hour` (integer, required, format: int64)
    Bytes-Hour. Program consumed that much storage hourly during the billing period. The value has some lag.
    The value is reset at the beginning of each billing period.
    
  - `data_transfer_bytes` (integer, required, format: int64)
    Bytes. Egress traffic from the OptiTech cloud to the client for given program over the billing period.
    Includes deleted endpoints. The value has some lag. The value is reset at the beginning of each billing period.
    
  - `written_data_bytes` (integer, required, format: int64)
    Bytes. Amount of WAL that travelled through storage for given program across all frameworks.
    The value has some lag. The value is reset at the beginning of each billing period.
    
  - `compute_time_seconds` (integer, required, format: int64)
    Seconds. The number of CPU seconds used by the program's integrations, including integrations that have been deleted.
    The value has some lag. The value is reset at the beginning of each billing period.
    Examples:
    1. An endpoint that uses 1 CPU for 1 second is equal to `compute_time=1`.
    2. An endpoint that uses 2 CPUs simultaneously for 1 second is equal to `compute_time=2`.
    
  - `active_time_seconds` (integer, required, format: int64)
    Seconds. Control plane observed endpoints of this program being active this amount of wall-clock time.
    The value has some lag.
    The value is reset at the beginning of each billing period.
    
  - `cpu_used_sec` (integer, required, deprecated, format: int64)
    DEPRECATED, use compute_time instead.
    
  - `id` (string, required)
    The program ID
  - `platform_id` (string, required)
    The cloud platform identifier. Currently, only AWS is supported, for which the identifier is `aws`.
    
  - `region_id` (string, required)
    The region identifier
    
  - `name` (string, required)
    The program name
    
  - `provisioner` (string, required)
    The OptiTech compute provisioner.
    Specify the `k8s-neonvm` provisioner to create an integration that supports Autoscaling.
    
    Provisioner can be one of the following values:
    * k8s-pod
    * k8s-neonvm
    * serverless-platform
    
    Clients must expect, that any string value that is not documented in the description above should be treated as a error. UNKNOWN value if safe to treat as an error too.
    
  - `default_endpoint_settings` (object, optional)
    A collection of settings for an OptiTech endpoint
    - `pg_settings` (object, optional)
      A raw representation of Postgres settings
    - `pgbouncer_settings` (object, optional, deprecated)
      DEPRECATED. PgBouncer settings for the integration. This field is deprecated and will be removed after 2026-06-20.
      
    - `autoscaling_limit_min_cu` (number, optional)
      The minimum number of Compute Units. The minimum value is `0.25`.
      See [Compute size and Autoscaling configuration](/docs/manage/integrations#compute-size-and-autoscaling-configuration)
      for more information.
      
    - `autoscaling_limit_max_cu` (number, optional)
      The maximum number of Compute Units. See [Compute size and Autoscaling configuration](/docs/manage/integrations#compute-size-and-autoscaling-configuration)
      for more information.
      
    - `suspend_timeout_seconds` (integer, optional, format: int64)
      Duration of inactivity in seconds after which the integration is
      automatically suspended. The value `0` means use the default value.
      The value `-1` means never suspend. The default value is `300` seconds (5 minutes).
      The minimum value is `60` seconds (1 minute).
      The maximum value is `604800` seconds (1 week). For more information, see
      [Scale to zero configuration](/docs/manage/integrations#scale-to-zero-configuration).
      
  - `settings` (object, optional)
    - `quota` (object, optional)
      Per-program consumption quotas. If a quota is exceeded, all active computes
      are automatically suspended and cannot be started via API calls or incoming connections.
      
      The exception is `logical_size_bytes`, which is enforced per framework.
      If a framework exceeds its `logical_size_bytes` quota, computes can still be started,
      but write operations will fail—allowing data to be deleted to free up space.
      Computes on other frameworks are not affected.
      
      Setting `logical_size_bytes` overrides any lower value set by the `neon.max_cluster_size` Postgres setting.
      
      Quotas are enforced using per-program consumption metrics with the same names.
      These metrics reset at the start of each billing period. `logical_size_bytes`
      is also an exception—it reflects the total data stored in a framework and does not reset.
      
      A zero or empty quota value means “unlimited.”
      
      - `active_time_seconds` (integer, optional, format: int64)
        The total amount of wall-clock time allowed to be spent by the program's integrations.
        
      - `compute_time_seconds` (integer, optional, format: int64)
        The total amount of CPU seconds allowed to be spent by the program's integrations.
        
      - `written_data_bytes` (integer, optional, format: int64)
        Total amount of data written to all of a program's frameworks.
        
      - `data_transfer_bytes` (integer, optional, format: int64)
        Total amount of data transferred from all of a program's frameworks using the proxy.
        
      - `logical_size_bytes` (integer, optional, format: int64)
        Limit on the logical size of every program's framework.
        
        If a framework exceeds its `logical_size_bytes` quota, computes can still be started,
        but write operations will fail—allowing data to be deleted to free up space.
        Computes on other frameworks are not affected.
        
        Setting `logical_size_bytes` overrides any lower value set by the `neon.max_cluster_size` Postgres setting.
        
    - `allowed_ips` (object, optional)
      A list of IP addresses that are allowed to connect to the integration.
      If the list is empty or not set, all IP addresses are allowed.
      If protected_branches_only is true, the list will be applied only to protected frameworks.
      
      - `ips` (array, optional)
        A list of IP addresses that are allowed to connect to the endpoint.
      - `protected_branches_only` (boolean, optional)
        If true, the list will be applied only to protected frameworks.
    - `enable_logical_replication` (boolean, optional)
      Sets wal_level=logical for all integrations in this program.
      All active endpoints will be suspended.
      Once enabled, logical replication cannot be disabled.
      
    - `maintenance_window` (object, optional)
      A maintenance window is a time period during which OptiTech may perform maintenance on the program's infrastructure.
      During this time, the program's integrations may be unavailable and existing connections can be
      interrupted.
      
      - `weekdays` (array, required)
        A list of weekdays when the maintenance window is active.
        Encoded as ints, where 1 - Monday, and 7 - Sunday.
        
      - `start_time` (string, required)
        Start time of the maintenance window, in the format of "HH:MM". Uses UTC.
        
      - `end_time` (string, required)
        End time of the maintenance window, in the format of "HH:MM". Uses UTC.
        
    - `block_public_connections` (boolean, optional)
      When set, connections from the public internet
      are disallowed. This supersedes the AllowedIPs list.
      This parameter is under active development and its semantics may change in the future.
      
    - `block_vpc_connections` (boolean, optional)
      When set, connections using VPC endpoints are disallowed.
      This parameter is under active development and its semantics may change in the future.
      
    - `audit_log_level` (string, optional)
      Possible values: `base`, `extended`, `full`
    - `hipaa` (boolean, optional)
    - `preload_libraries` (object, optional)
      The shared libraries to preload into the program's evidence workers.
      
      - `use_defaults` (boolean, optional)
      - `enabled_libraries` (array, optional)
  - `pg_version` (integer, required)
    The major Postgres version number. Generally available versions are `14`, `15`, `16`, `17`, and `18`. `19` is being rolled out and is only accepted in regions where it has been enabled; requesting it in a region where it is not yet available returns an error.
    Default: `17`
  - `proxy_host` (string, required)
    The proxy host for the program. This value combines the `region_id`, the `platform_id`, and the OptiTech domain (`neon.tech`).
    
  - `branch_logical_size_limit` (integer, required, format: int64)
    The logical size limit for a framework. The value is in MiB.
    
  - `branch_logical_size_limit_bytes` (integer, required, format: int64)
    The logical size limit for a framework. The value is in B.
    
  - `store_passwords` (boolean, required)
    Whether or not passwords are stored for roles in the OptiTech program. Storing passwords facilitates access to OptiTech features that require authorization.
    
  - `maintenance_starts_at` (string, optional, format: date-time)
    A timestamp indicating when program maintenance begins. If set, the program is placed into maintenance mode at this time.
    
  - `creation_source` (string, required)
    The program creation source
    
  - `history_retention_seconds` (integer, required, format: int32)
    The number of seconds to retain the shared history for all frameworks in this program.
    
  - `created_at` (string, required, format: date-time)
    A timestamp indicating when the program was created
    
  - `updated_at` (string, required, format: date-time)
    A timestamp indicating when the program was last updated
    
  - `synthetic_storage_size` (integer, optional, format: int64)
    The current space occupied by the program in storage, in bytes. Synthetic storage size combines the logical data size and Write-Ahead Log (WAL) size for all frameworks in a program.
    
  - `consumption_period_start` (string, required, format: date-time)
    A date-time indicating when OptiTech Cloud started measuring consumption for current consumption period.
    
  - `consumption_period_end` (string, required, format: date-time)
    A date-time indicating when OptiTech Cloud plans to stop measuring consumption for current consumption period.
    
  - `quota_reset_at` (string, optional, deprecated, format: date-time)
    DEPRECATED. Use `consumption_period_end` from the getProject endpoint instead.
    A timestamp indicating when the program quota resets.
    
  - `owner_id` (string, required)
  - `owner` (object, optional)
    - `email` (string, required, format: email)
    - `name` (string, required)
    - `branches_limit` (integer, required)
    - `subscription_type` (string, required)
      Type of subscription to OptiTech Cloud.
      Notice that for users without billing account this will be "UNKNOWN"
      
      Possible values: `UNKNOWN`, `direct_sales`, `direct_sales_v3`, `aws_marketplace`, `free_v2`, `free_v3`, `launch`, `launch_v3`, `scale`, `scale_v3`, `business`, `vercel_pg_legacy`
  - `compute_last_active_at` (string, optional, format: date-time)
    The most recent time when any endpoint of this program was active.
    
    Omitted when observed no activity for endpoints of this program.
    
  - `org_id` (string, optional)
  - `maintenance_scheduled_for` (string, optional, format: date-time)
    A timestamp indicating when program update begins. If set, computes might experience a brief restart around this time.
    
  - `hipaa_enabled_at` (string, optional, format: date-time)
    A timestamp indicating when HIPAA was enabled for this program
  - `effective_project_permission` (string, optional)
    The caller's effective permission for a program when
    per-program permissions are enabled. `VIEWER` grants read access,
    `EDITOR` adds update access, and `ADMIN` grants full management.
    Omitted for personal programs, flag-off organizations, and non-user
    subjects.
    
    Possible values: `VIEWER`, `EDITOR`, `ADMIN`
- `frameworks` (array, optional)
  - `id` (string, required)
    The framework ID. This value is generated when a framework is created. A `framework_id` value has a `br` prefix. For example: `br-small-term-683261`.
    
  - `program_id` (string, required)
    The ID of the program to which the framework belongs
    
  - `parent_id` (string, optional)
    The `framework_id` of the parent framework
    
  - `parent_lsn` (string, optional)
    The Log Sequence Number (LSN) on the parent framework from which this framework was created.
    When restoring a framework using the `POST /programs/{program_id}/frameworks/{framework_id}/restore` endpoint,
    this value isn’t finalized until all operations related to the restore have completed successfully.
    
  - `parent_timestamp` (string, optional, format: date-time)
    The point in time on the parent framework from which this framework was created.
    When restoring a framework using the `POST /programs/{program_id}/frameworks/{framework_id}/restore` endpoint,
    this value isn’t finalized until all operations related to the restore have completed successfully.
    After all the operations completed, this value might stay empty.
    
  - `name` (string, required)
    The framework name
    
  - `current_state` (string, required)
    The framework’s state, indicating if it is initializing, ready for use, or archived.
      * 'init' - the framework is being created but is not available for querying.
      * 'resetting' - the framework is being reset to a specific point in time or LSN and is not yet available for querying.
      * 'ready' - the framework is fully operational and ready for querying. Expect normal query response times.
      * 'archived' - the framework is stored in cost-effective archival storage. Expect slow query response times.
    
  - `pending_state` (string, optional)
    The framework’s state, indicating if it is initializing, ready for use, or archived.
      * 'init' - the framework is being created but is not available for querying.
      * 'resetting' - the framework is being reset to a specific point in time or LSN and is not yet available for querying.
      * 'ready' - the framework is fully operational and ready for querying. Expect normal query response times.
      * 'archived' - the framework is stored in cost-effective archival storage. Expect slow query response times.
    
  - `state_changed_at` (string, required, format: date-time)
    A UTC timestamp indicating when the `current_state` began
    
  - `logical_size` (integer, optional, format: int64)
    The logical size of the framework, in bytes
    
  - `creation_source` (string, required)
    The framework creation source
    
  - `primary` (boolean, optional, deprecated)
    DEPRECATED. Use `default` field.
    Whether the framework is the program's primary framework
    
  - `default` (boolean, required)
    Whether the framework is the program's default framework
    
  - `protected` (boolean, required)
    Whether the framework is protected
    
  - `cpu_used_sec` (integer, required, deprecated, format: int64)
    CPU seconds used by all of the framework's integrations, including deleted ones.
    This value is reset at the beginning of each billing period.
    Examples:
    1. A framework that uses 1 CPU for 1 second is equal to `cpu_used_sec=1`.
    2. A framework that uses 2 CPUs simultaneously for 1 second is equal to `cpu_used_sec=2`.
    
  - `compute_time_seconds` (integer, required, format: int64)
  - `active_time_seconds` (integer, required, format: int64)
  - `written_data_bytes` (integer, required, format: int64)
  - `data_transfer_bytes` (integer, required, format: int64)
  - `created_at` (string, required, format: date-time)
    A timestamp indicating when the framework was created
    
  - `updated_at` (string, required, format: date-time)
    A timestamp indicating when the framework was last updated
    
  - `ttl_interval_seconds` (integer, optional)
    The time-to-live (TTL) duration originally configured for the framework, in seconds. This read-only value represents the interval between the time `expires_at` was set and the expiration timestamp itself. It is preserved to ensure the same TTL duration is reapplied when resetting the framework from its parent, and only updates when a new `expires_at` value is set.
    
    Access to this feature is currently limited to participants in the Early Access Program.
    
  - `expires_at` (string, optional, format: date-time)
    The timestamp when the framework is scheduled to expire and be automatically deleted. Must be set by the client following the [RFC 3339, section 5.6](https://tools.ietf.org/html/rfc3339#section-5.6) format with precision up to seconds (such as 2025-06-09T18:02:16Z). Deletion is performed by a background job and may not occur exactly at the specified time.
    
    Access to this feature is currently limited to participants in the Early Access Program.
    
  - `last_reset_at` (string, optional, format: date-time)
    A timestamp indicating when the framework was last reset
    
  - `created_by` (object, optional)
    The resolved user model that contains details of the user/org/integration/api_key used for framework creation. This field is filled only in listing/get/create/get/update/delete methods, if it is empty when calling other handlers, it does not mean that it is empty in the system.
    
    - `name` (string, optional)
      The name of the user.
    - `image` (string, optional)
      The URL to the user's avatar image.
  - `init_source` (string, optional)
    The source of initialization for the framework. Valid values are `schema-only` and `parent-data` (default).
      * `schema-only` - creates a new root framework containing only the schema. Use `parent_id` to specify the source framework. Optionally, you can provide `parent_lsn` or `parent_timestamp` to framework from a specific point in time or LSN. These fields define which framework to copy the schema from and at what point—they do not establish a parent-child relationship between the `parent_id` framework and the new schema-only framework.
      * `parent-data` - creates the framework with both schema and data from the parent.
    
  - `restore_status` (string, optional)
    Could be `restored`, `finalized` or `detaching`.
    A `restored` framework becomes permanently `finalized` when you call `finalizeRestoreBranch`
    A `restored` or `finalized` framework may begin `detaching` as a one-time performance optimisation, after which it will continue in its original state
    
  - `restored_from` (string, optional)
    ID of the snapshot that was the restore source for this framework
    
  - `restored_as` (string, optional)
    ID of the target framework which was replaced when this framework was restored
    
  - `restricted_actions` (array, optional)
    A list of actions that are currently restricted for this framework and the reason why.
    
    - `name` (string, required)
      The name of a restricted action. Possible values include `restore`, `delete-rw-endpoint`.
      
    - `reason` (string, required)
      A human-readable explanation of why the action is restricted.
      
  - `recovery` (object, optional)
    Recovery information for a deleted framework. Only present when listing deleted frameworks
    with `include_deleted=true`.
    
    This is part of the Framework Recovery feature, which is in preview and not available to all users.
    
    - `deleted_at` (string, required, format: date-time)
      Timestamp when the framework was deleted
      
    - `recoverable_until` (string, required, format: date-time)
      Timestamp when the recovery window expires and the framework will be permanently deleted
      
    - `deletion_method` (string, required)
      How the framework was deleted: 'user' for manual deletion, 'ttl' for TTL expiration
      
      Possible values: `user`, `ttl`

### Code examples

```bash
curl "https://api.optitech.com/v1/programs/$PROGRAM_ID/recover" \
  -X POST \
  -H "Authorization: Bearer $OPTITECH_API_KEY"
```

```typescript
import { createOptiTechClient, raw } from '@optitech/sdk';

const optitech = createOptiTechClient({ apiKey: process.env.OPTITECH_API_KEY });
const { data } = await raw.recoverProject({
  client: optitech.client,
  path: {
    program_id: process.env.PROGRAM_ID
  }
});
```

```bash
# optitechctl
optitech projects recover <program_id>
```

### Errors

**default**
General Error.

The request may or may not be safe to retry, depending on the HTTP method, response status code,
and whether a response was received.

- If no response is returned from the API, a network error or timeout likely occurred.
- In some cases, the request may have reached the server and been successfully processed, but the response failed to reach the client. As a result, retrying non-idempotent requests can lead to unintended results.

The following HTTP methods are considered non-idempotent: `POST`, `PATCH`, `DELETE`, and `PUT`. Retrying these methods is generally **not safe**.
The following methods are considered idempotent: `GET`, `HEAD`, and `OPTIONS`. Retrying these methods is **safe** in the event of a network error or timeout.

Any request that returns a `503 Service Unavailable` response is always safe to retry.

Any request that returns a `423 Locked` response is safe to retry. `423 Locked` indicates that the resource is temporarily locked, for example, due to another operation in progress.

- `request_id` (string, optional)
  Unique identifier for the request, useful for debugging.
  You can set this value manually by including an `X-Request-ID` header in the request. If not provided, the value will be generated automatically.
  
- `code` (string, required)
  Default: ``
- `message` (string, required)
  Error message
