Accept an invitation or activate an invited identity
Proves an existing identity's current password, or creates a new identity with a chosen password only for an email-only invitation. Token consumption and membership roles are atomic. For identities with email 2FA, returns a 202 challenge without tokens; complete /auth/login with the current password, challengeId and emailed code on this tenant host. For Google Authenticator users, returns 202 channel=TOTP; complete login on this tenant with password and totpCode or recoveryCode. Otherwise issues the session atomically.
application/json- body
password*stringCurrent or new password, at most 72 UTF-8 bytes
password0 <= length <= 72token*stringRaw one-time invitation token
0 <= length <= 512Membership created and token pair issued
application/json- response
accessToken?stringShort-lived bearer JWT
refreshToken?stringOne-time opaque refresh token
curl -X POST 'https://api.monetaryai.uz/api/v1/auth/membership-invitations/accept' \ -H 'Content-Type: application/json' \ -d '{ "password": "pa$$word", "token": "string"}'{ "accessToken": "string", "refreshToken": "string"}List own active refresh sessions GET
Returns family identifiers, creation, refresh-expiry, User-Agent, IP and last login/refresh activity for the authenticated active membership in this tenant. No tokens or hashes. User-Agent is untrusted client metadata; IP is the container remote address. Current is determined by the signed session_id claim (legacy tokens have no current marker). Stable newest-first pagination.
Add a user through a recipient-bound membership invitation POST
Creates a 24-hour, one-time invitation. Email delivery permits recipient-bound activation of a new identity and never returns the token. Email-disabled legacy manual delivery returns a token usable only by an existing identity. Neither response confirms delivery. Company permission: `createMembershipInvitation`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.