Create an invite
const url = 'https://example.com/api/v1/onboarding/invites';const options = { method: 'POST', headers: { cookie: 'bl_authority_session=<bl_authority_session>', 'Content-Type': 'application/json' }, body: '{"name":"example","roles":["example"],"expires_at":"2026-04-15T12:00:00Z","code":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/api/v1/onboarding/invites \ --header 'Content-Type: application/json' \ --cookie bl_authority_session=<bl_authority_session> \ --data '{ "name": "example", "roles": [ "example" ], "expires_at": "2026-04-15T12:00:00Z", "code": "example" }'An invite pre-approves roles; signing and review still follow. It can be used once.
Authorizations
Section titled “Authorizations”Request Bodyrequired
Section titled “Request Bodyrequired”object
Who the invite is for.
The roles it pre-approves.
Default: a random INVITE-… code.
Example generated
{ "name": "example", "roles": [ "example" ], "expires_at": "2026-04-15T12:00:00Z", "code": "example"}Responses
Section titled “Responses”OK.
object
Who the invite is for.
The roles it pre-approves.
The DID that used it.
Absent in the answer to creating one.
Example generated
{ "code": "example", "name": "example", "roles": [ "example" ], "expires_at": "2026-04-15T12:00:00Z", "used_by": "example", "created_at": "2026-04-15T12:00:00Z"}An unknown role.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}No valid session, DPoP-bound token or API key.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}The code exists.
The body of every failed call to a management API.
object
object
Stable, machine-readable: invalid_request, unauthenticated,
forbidden, not_found, conflict, upstream_unavailable,
unavailable, internal, or a more specific code of the operation.
For people; may change between versions.
Example
{ "error": { "code": "not_found", "message": "unknown negotiation" }}