# Add a member to a team

`POST https://evohub.io/api/v1/teams/{id}/members`

Part of the [Organization API](https://docs-dev.evohub.io/organization.md) reference · operationId `addTeamMember`.

Adds a member of the organization to the team, or changes their place in it.
A seat in a team is every role the team holds, so the key must hold every
permission those roles carry (`FORBIDDEN`, naming the first it lacks), and a
team holding the Admin role takes an administrator (`ADMIN_ONLY`).

**Permission (API-key scope):** `identity:team:write`.

## Authorization

Any one of:

- `bearerAuth` (identity:team:write)
- `apiKeyHeader` (identity:team:write)

Where:

- `bearerAuth`: HTTP Bearer — An EvoHub API key (`evohub_…`) as a bearer token.
- `apiKeyHeader`: API key in the header `X-API-Key` — An EvoHub API key (`evohub_…`).

## Path parameters

- `id` (string, required): The id of the member (`usr_…`), team (`team_…`), role (`role_…`), invitation (`inv_…`) or organization (`org_…`) the path names.

## Request body (required)

Content type: `application/json`

Type: `object`

- `user_id` (string, required)
- `role` (TeamMemberRole, one of `admin`, `member`, `viewer`, default `member`)

## Responses

### 201 — Added.

Content type: `application/json`

Type: `object`

- `data` (object, required)
  - `status` (string, value `member_added`)
- `success` (boolean, required, value `true`)

### 400 — Not JSON (`INVALID_BODY`), or `user_id` is missing (`VALIDATION_FAILED`).

Content type: `application/json`

Type: `ValidationError`

- `error` (object, required)
  - `code` (string, required, value `VALIDATION_FAILED`)
  - `message` (string, required)
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.
  - `details` (array of object, required)
    - `field` (string)
    - `message` (string)

### 401 — No API key was sent, or it is unknown, revoked or expired (`UNAUTHORIZED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 403 — The key lacks the scope (`FORBIDDEN`); the change would grant a permission the key does not hold (`FORBIDDEN`, naming it); or only an administrator may do it (`ADMIN_ONLY`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 404 — No such team, or the person is not a member of the organization (`NOT_FOUND`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 429 — Too many requests (`RATE_LIMITED`). Wait `Retry-After` seconds.

Headers:

- `Retry-After` (integer): Seconds to wait.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 500 — Something went wrong on EvoHub's side (`INTERNAL_ERROR`). Retry later.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

## Example request

```bash
curl -X POST 'https://evohub.io/api/v1/teams/string/members' \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Bearer <TOKEN>' \
  -d '{
  "role": "member",
  "user_id": "usr_7a3c9e10-b2d4-4f6a-8c1e-5d7f9a0b2c3e"
}'
```
