Skip to main content
POST
Create Invitation

Authorizations

Authorization
string
header
required

Your API key (ta_live_…) from Settings → API keys, sent as Authorization: Bearer <key>. Keep it on a server: it can message every customer you have. A key is full, build or read-only; a request its level does not allow is refused with 403.

Headers

Thinnest-Workspace
string

Developers only: the customer workspace this request acts in — its org_… id from POST /customers. Leave it out to act in your own workspace.

Example:

"org_3fKq9TzQ1mN8vB2xR7cLpA"

Body

application/json
email
string<email>
required

The address to invite. Lower-cased.

Maximum string length: 254
Example:

"anjali@sunrisedental.in"

role
enum<string>
default:member

The role they will have. owner is refused with 403: invite owners from the console.

Available options:
admin,
member
Example:

"member"

Response

A pending invitation to this address was refreshed and sent again.

id
string
required

The invitation's id (inv_…).

Example:

"inv_2d3f5a7c-9e1b-4d6f-8a2c-4e6a8c0e2f57"

email
string<email>
required

Who is invited, lower-cased.

Example:

"anjali@sunrisedental.in"

role
enum<string>
required

The role they will have.

Available options:
owner,
admin,
member
Example:

"member"

status
enum<string>
required

pending until it is accepted or revoked. A pending invitation past expiresAt no longer works.

Available options:
pending,
accepted,
revoked
Example:

"pending"

expiresAt
string<date-time>
required

When its link stops working: 14 days after it was last sent.

Example:

"2026-10-20T10:40:00.000Z"

createdAt
string<date-time>
required
Example:

"2026-10-06T10:40:00.000Z"