Organization API › Invitations
Invite someone
Emails an invitation to join the organization, valid for seven days. role
is the standing (default member); role_ids and team_ids are what the
person gets on arrival. The key must hold every permission those carry, and
only an administrator invites an administrator.
An invitation names who sent it, so it needs a personal key: an
organization key gets 403 NOT_A_PERSON. The answer's token is empty
(""): the email is the only place the invitation's secret goes.
Permission (API-key scope): identity:user:invite.
Authorization
bearerAuth(identity:user:invite)apiKeyHeader(identity:user:invite)
Request body required
emailstring (email) requiredrolestringrole_idsarray of stringteam_idsarray of string
Responses
201
The invitation.
dataInvitation requiredShow Invitation properties
idstring requiredorg_idstring requiredemailstring (email) requiredrolestring requiredrole_idsarray of string | nullRoles held on arrival.team_idsarray of string | nullTeams joined on arrival.tokenstringThe secret the invitation email carries. Always empty ("") in a response to the organization; only the email carries it.statusstring requiredinvited_bystring requiredexpires_atstring (date-time) requiredSeven days after it was sent (or last resent).accepted_atstring (date-time)created_atstring (date-time) required
successboolean required
400
Not JSON (INVALID_BODY), no email (VALIDATION_FAILED), or role is not admin, member or viewer (VALIDATION_ERROR).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
401
No API key was sent, or it is unknown, revoked or expired (UNAUTHORIZED).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
403
The key lacks the scope or a permission the invitation grants (FORBIDDEN), an administrator is being invited (ADMIN_ONLY), or it is an organization key (NOT_A_PERSON).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
404
A role or team named does not exist (NOT_FOUND).
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
409
The address already has a pending invitation (INVITATION_PENDING); resend it instead.
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
429
Too many requests (RATE_LIMITED). Wait Retry-After seconds.
Retry-AfterintegerSeconds to wait.
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
500
Something went wrong on EvoHub's side (INTERNAL_ERROR). Retry later.
errorobject requiredcodestring requiredMachine-readable code. Branch on this.messagestring requiredHuman-readable explanation.request_idstringThe response'sX-Request-ID; quote it to support.
Example request
curl -X POST 'https://evohub.io/api/v1/invitations' \
-H 'Content-Type: application/json' \
-H 'Authorization: Bearer <TOKEN>' \
-d '{
"role": "member",
"email": "deniz@acme.example",
"role_ids": [
"role_8e1f2a3b-4c5d-4e6f-8a9b-0c1d2e3f4a5b"
],
"team_ids": [
"team_2f9c4b7e-1a3d-4c5e-9f7a-0b2d4e6f8a1c"
]
}'