Ga naar inhoud

Create an invite

POST
/api/v1/onboarding/invites
curl --request POST \
--url https://example.com/api/v1/onboarding/invites \
--header 'Content-Type: application/json' \
--cookie bl_authority_session=<bl_authority_session> \
--data '{ "name": "example", "roles": [ "example" ], "expires_at": "2026-04-15T12:00:00Z", "code": "example" }'

An invite pre-approves roles; signing and review still follow. It can be used once.

Media typeapplication/json
object
name
required

Who the invite is for.

string
roles
required

The roles it pre-approves.

Array<string>
expires_at
string | null format: date-time
code

Default: a random INVITE-… code.

string | null

Example generated

{
"name": "example",
"roles": [
"example"
],
"expires_at": "2026-04-15T12:00:00Z",
"code": "example"
}

OK.

Media typeapplication/json
object
code
required
string
name
required

Who the invite is for.

string
roles
required

The roles it pre-approves.

Array<string>
expires_at
string | null format: date-time
used_by

The DID that used it.

string | null
created_at

Absent in the answer to creating one.

string | null format: date-time

Example generated

{
"code": "example",
"name": "example",
"roles": [
"example"
],
"expires_at": "2026-04-15T12:00:00Z",
"used_by": "example",
"created_at": "2026-04-15T12:00:00Z"
}

An unknown role.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

No valid session, DPoP-bound token or API key.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

The caller lacks the role this operation needs; or a change with the session cookie came from a page of another site (cross_site_request, decisions #83).

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}

The code exists.

Media typeapplication/json

The body of every failed call to a management API.

object
error
required
object
code
required

Stable, machine-readable: invalid_request, unauthenticated, forbidden, not_found, conflict, upstream_unavailable, unavailable, internal, or a more specific code of the operation.

string
message
required

For people; may change between versions.

string

Example

{
"error": {
"code": "not_found",
"message": "unknown negotiation"
}
}