/api/v1/invites
auth: jwt (administrator)Create a one-time invite. Generates a UUID token, stores `invite:{uuid}` in Redis with TTL INVITE_TTL_SECONDS (default 72h) holding { email, roles, organizationId=businessId, invitedBy=actorUserId }, and sends an invite email. On email failure the Redis token is deleted to avoid orphans.
handlers: InvitesController.create
| name | required | default | description |
|---|---|---|---|
email bodystring (email) | yes | — | Invitee email address. |
roles bodyUserRole[] | yes | — | Roles to assign on registration (min 1). |
APIResponseDataObject<InviteDTO>APIErrorAPIErrorAPIErrorAPIError/api/v1/invites/:token
auth: noneValidate an invite token and return its metadata so the registration page can pre-fill the email and show the role(s). Public — invite recipients have no account yet.
handlers: InvitesController.validate
| name | required | default | description |
|---|---|---|---|
token pathuuid | yes | — | Invite token from the email link. |
APIResponseDataObject<InviteDTO>APIError