Skip to content

Invite someone to the organization

POST
/api/v1/org/invitations
curl --request POST \
--url https://api.aletheia-ops.com/api/v1/org/invitations \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "email": "example", "role_id": "example" }'
Media typeapplication/json

Invites an email with a pre-assigned role

object
email
required
string
role_id
required
string
Examplegenerated
{
"email": "example",
"role_id": "example"
}

Created

Media typeapplication/json

Returned once, carrying the raw copy-link token/URL

object
invitation

A pending invitation

object
id
string
email
string
role_id
string
invited_by
string
state
string
expires_at
string format: date-time
created_at
string format: date-time
token
string
url
string
Examplegenerated
{
"invitation": {
"id": "example",
"email": "example",
"role_id": "example",
"invited_by": "example",
"state": "example",
"expires_at": "2026-04-15T12:00:00Z",
"created_at": "2026-04-15T12:00:00Z"
},
"token": "example",
"url": "example"
}

The request is malformed or fails validation.

Media typeapplication/json
object
code
required

Stable, machine-readable identifier. Branch on this.

string
message
required

Human-readable explanation. Safe to display; do not parse.

string
Examples
{
"code": "validation_failed",
"message": "name: must not be blank"
}

No valid credential was presented, or it has expired.

Media typeapplication/json
object
code
required

Stable, machine-readable identifier. Branch on this.

string
message
required

Human-readable explanation. Safe to display; do not parse.

string
Examples
{
"code": "unauthorized",
"message": "authentication required"
}

Authenticated, but not permitted to perform this action.

Media typeapplication/json
object
code
required

Stable, machine-readable identifier. Branch on this.

string
message
required

Human-readable explanation. Safe to display; do not parse.

string
Examples
{
"code": "forbidden",
"message": "you do not have permission to perform this action"
}

The request conflicts with the current state.

Media typeapplication/json
object
code
required

Stable, machine-readable identifier. Branch on this.

string
message
required

Human-readable explanation. Safe to display; do not parse.

string
Examples
{
"code": "email_taken",
"message": "an account with this email already exists"
}

An unexpected failure. Diagnostic detail is logged server-side and deliberately not returned. Quote the X-Request-Id response header when reporting one.

Media typeapplication/json
object
code
required

Stable, machine-readable identifier. Branch on this.

string
message
required

Human-readable explanation. Safe to display; do not parse.

string
Examples
Exampleinternal_error
{
"code": "internal_error",
"message": "internal server error"
}