Add a user through a recipient-bound membership invitation
Creates a 24-hour, one-time invitation. Email delivery permits recipient-bound activation of a new identity and never returns the token. Email-disabled legacy manual delivery returns a token usable only by an existing identity. Neither response confirms delivery. Company permission: `createMembershipInvitation`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.
bearerAuthAuthorizationBearer <token>Obtained from POST /api/v1/auth/login, on the tenant's own subdomain. Presenting it on another tenant's subdomain is a 403.
application/json- body
email*stringemail0 <= length <= 320roles*array<>1 <= items <= 5Legacy manual invitation created; raw token returned once
*/*- response
expiresAt?stringdate-timeinvitationId?stringuuidtoken?stringRaw one-time token only for legacy manual delivery; null when email dispatch is selected
curl -X POST 'https://api.monetaryai.uz/api/v1/membership-invitations' \ -H 'Content-Type: application/json' \ -d '{ "email": "user@example.com", "roles": [ "string" ]}'{ "expiresAt": "2019-08-24T14:15:22Z", "invitationId": "550a4884-8473-4f2e-a6cf-551c16767d59", "token": "string"}Accept an invitation or activate an invited identity POST
Proves an existing identity's current password, or creates a new identity with a chosen password only for an email-only invitation. Token consumption and membership roles are atomic. For identities with email 2FA, returns a 202 challenge without tokens; complete /auth/login with the current password, challengeId and emailed code on this tenant host. For Google Authenticator users, returns 202 channel=TOTP; complete login on this tenant with password and totpCode or recoveryCode. Otherwise issues the session atomically.
Revoke a pending membership invitation POST
Revokes one invitation in the caller's tenant without revealing invitations in another tenant. Company permission: `revokeMembershipInvitation`. Defaults: ADMIN. Current company role permissions and active membership are checked on every request; signed legacy role claims alone do not authorize this operation.