Skip to content

`POST /v1/invitations/accept`.

POST
/v1/invitations/accept
curl --request POST \
--url https://api.updawg.net/v1/invitations/accept \
--header 'Content-Type: application/json' \
--data '{ "token": "example" }'

Not under /orgs/{org}, because the caller is not in one yet — that is what they are doing. Which organization it is comes from the token.

Media typeapplication/json
object
token
required
string
Examplegenerated
{
"token": "example"
}

Joined.

Media typeapplication/json
object
org
required
string
role
required
string
Allowed values: viewer operator admin owner
Example
{
"role": "viewer"
}

The token is unknown, used, expired or for somebody else — one answer for all four.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

No session.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

Refused: no CSRF token or not this session’s, or not permitted for this role.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

Unknown, expired, already taken up or withdrawn — one answer for all four, so that somebody holding a guess cannot find out which part of it was right.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}

⚠️ The invitation is for a different address. The one distinction that is safe to make, because whoever is asking is holding a token that was mailed to that address — and a refusal that does not name it is one nobody can act on.

Media typeapplication/json
object
detail
string | null
status
required
integer format: int32
title
required
string
type
required
string
Examplegenerated
{
"detail": "example",
"status": 1,
"title": "example",
"type": "example"
}