# List invitations

`GET https://evohub.io/api/v1/invitations`

Part of the [Organization API](https://docs-dev.evohub.io/organization.md) reference · operationId `listInvitations`.

Every invitation the organization has sent, with its status. The invitation token is left out (`""`).

**Permission (API-key scope):** `identity:user:invite`.

## Authorization

Any one of:

- `bearerAuth` (identity:user:invite)
- `apiKeyHeader` (identity:user:invite)

Where:

- `bearerAuth`: HTTP Bearer — An EvoHub API key (`evohub_…`) as a bearer token.
- `apiKeyHeader`: API key in the header `X-API-Key` — An EvoHub API key (`evohub_…`).

## Responses

### 200 — The invitations.

Content type: `application/json`

Type: `object`

- `data` (array of Invitation, required)
  - `id` (string, required)
  - `org_id` (string, required)
  - `email` (string (email), required)
  - `role` (string, required, one of `admin`, `member`, `viewer`)
  - `role_ids` (array of string | null): Roles held on arrival.
  - `team_ids` (array of string | null): Teams joined on arrival.
  - `token` (string): The secret the invitation email carries. Always empty (`""`) in a response to the organization; only the email carries it.
  - `status` (string, required, one of `pending`, `accepted`, `declined`, `expired`)
  - `invited_by` (string, required)
  - `expires_at` (string (date-time), required): Seven days after it was sent (or last resent).
  - `accepted_at` (string (date-time))
  - `created_at` (string (date-time), required)
- `success` (boolean, required, value `true`)

### 401 — No API key was sent, or it is unknown, revoked or expired (`UNAUTHORIZED`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 403 — The key lacks the scope this endpoint needs (`FORBIDDEN`).

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 429 — Too many requests (`RATE_LIMITED`). Wait `Retry-After` seconds.

Headers:

- `Retry-After` (integer): Seconds to wait.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

### 500 — Something went wrong on EvoHub's side (`INTERNAL_ERROR`). Retry later.

Content type: `application/json`

Type: `Error`

- `error` (object, required)
  - `code` (string, required): Machine-readable code. Branch on this.
  - `message` (string, required): Human-readable explanation.
  - `request_id` (string): The response's `X-Request-ID`; quote it to support.

## Example request

```bash
curl -X GET 'https://evohub.io/api/v1/invitations' \
  -H 'Authorization: Bearer <TOKEN>'
```
