Skip to content
qibdo qibdo
v1
API version
  • v1
Theme
Book a demo

Invite User

POST
/iam/v1/users:invite
curl --request POST \
--url https://example.com/iam/v1/users:invite \
--header 'Content-Type: application/json' \
--data '{ "email": "example", "name": "example", "surname": "example", "scope_type": "example", "scope_id": "example", "role_id": "example" }'

Atomically creates an invited user and, when a scope is supplied, their first binding at it — in one transaction — and returns the one-time activation token the caller relays to the invitee out of band. The backend never builds a link: it does not host the redemption page, so composing a URL here would force per-tier origin configuration. The client composes the link from the token.

The scope is optional. Supplied, the caller is authorized at that scope and the new account starts with access. Omitted, the request resolves at the platform scope, so only a platform administrator may create an account that begins with no access at all.

Media type application/json

InviteUserRequest

Request message for InviteUser. The scope travels in the body, not the path: authorization reads the request fields, so the two forms are equivalent to the evaluator and the body keeps the endpoint addressed by its own resource.

object
email
required

The email address of the user to invite.

string
name
required

The given name of the invited user.

string
surname
required

The family name of the invited user.

string
scope_type

The scope type the caller is acting at: ORGANISATION, WORKSPACE, or GROUP.

Omit all three of scope_type/scope_id/role_id to create an account with no access; that request resolves at the platform scope.

string
scope_id

The unique identifier of the scope.

string
role_id

The role to grant on invitation.

string
Example generated
{
"email": "example",
"name": "example",
"surname": "example",
"scope_type": "example",
"scope_id": "example",
"role_id": "example"
}

OK

Media type application/json

InviteUserResponse

Response message for InviteUser: the recorded operation plus the one-time activation credential.

object
operation

The recorded invite operation.

object
id

Operation ID

Unique identifier for this operation.

stringOutput only
resource_id

Resource ID

The ID of the resource affected by this operation. May be empty for async operations where the resource does not yet exist.

stringOutput only
resource_type

Resource Type

The type of resource (e.g., “com.qibdo.cloud.iam:user”).

stringOutput only
operation_type

Operation Type

The kind of mutation that was requested.

string format: enum Output only
Allowed values: IAM_OPERATION_TYPE_UNSPECIFIED IAM_OPERATION_TYPE_CREATE IAM_OPERATION_TYPE_UPDATE IAM_OPERATION_TYPE_DELETE IAM_OPERATION_TYPE_AUTHENTICATE IAM_OPERATION_TYPE_CHANGE_PASSWORD IAM_OPERATION_TYPE_REVOKE IAM_OPERATION_TYPE_GRANT IAM_OPERATION_TYPE_INVITE IAM_OPERATION_TYPE_DEACTIVATE IAM_OPERATION_TYPE_REACTIVATE IAM_OPERATION_TYPE_ACTIVATE IAM_OPERATION_TYPE_UPLOAD_AVATAR IAM_OPERATION_TYPE_CLEAR_AVATAR IAM_OPERATION_TYPE_INSPECT_ACCESS IAM_OPERATION_TYPE_RESET_PASSWORD IAM_OPERATION_TYPE_COMPLETE_PASSWORD_RESET IAM_OPERATION_TYPE_REGENERATE_ACTIVATION_TOKEN
status

Status

Current lifecycle state of the operation.

string format: enum Output only
Allowed values: IAM_OPERATION_STATUS_UNSPECIFIED IAM_OPERATION_STATUS_PENDING IAM_OPERATION_STATUS_RUNNING IAM_OPERATION_STATUS_DONE IAM_OPERATION_STATUS_ERROR
insert_time

Insert Time

When the operation was first created.

string format: date-time Output only
start_time

Start Time

When the operation started executing.

string format: date-time Output only
end_time

End Time

When the operation completed (either successfully or with errors).

string format: date-time Output only
errors

Errors

Business rule errors encountered during the operation.

Array<object>Output only

Operation Error

A structured error returned inside an operation when a business rule fails.

object
code

Error Code

Numeric identifier following the S_SSS_EEE convention.

integer format: uint32 Output only
description

Description

Human-readable explanation of the error.

stringOutput only
reason

Reason

Machine-readable error identifier in UPPER_SNAKE form - the same dispatch key google.rpc.ErrorInfo.reason carries on the synchronous error plane.

stringOutput only
warnings

Warnings

Non-fatal notices about the operation.

Array<object>Output only

Operation Warning

A non-fatal notice attached to an operation.

object
code

Warning Code

Numeric identifier following the S_SSS_EEE convention.

integer format: uint32 Output only
description

Description

Human-readable explanation of the warning.

stringOutput only
progress

Progress

Percentage of completion (0-100).

integer format: int32 Output only
scope_type

Scope Type

The category of scope the operation ran in or was triggered from. SCOPE_TYPE_UNSPECIFIED when the operation is not scoped.

string format: enum Output only
Allowed values: SCOPE_TYPE_UNSPECIFIED SCOPE_TYPE_WORKSPACE SCOPE_TYPE_GROUP SCOPE_TYPE_ORGANISATION SCOPE_TYPE_PLATFORM
scope_id

Scope ID

The resource this operation was scoped to - for example, when scope_type is SCOPE_TYPE_WORKSPACE this is the workspace id. Empty for SCOPE_TYPE_PLATFORM, which has no scoped resource, and when unscoped.

stringOutput only
principal_id

Principal ID

Who performed or triggered the operation, whether a person or a machine account. Always populated: platform-driven work records the reserved system principal, so every audit record names an actor.

stringOutput only
trace_id

Trace ID

W3C trace id, for correlating this operation with the traces and log lines of the request that caused it. Empty when the operation ran with no trace context - a scheduled or event-driven action rather than a request.

stringOutput only
cause

Revocation Cause

Discriminator for REVOKE operations only (UNSPECIFIED for every other operation_type). See RevocationCause for the available causes. Lives in the per-context extension zone (100+); 16..99 belong to the canonical operation envelope shared by every bounded context.

string format: enum Output only
Allowed values: REVOCATION_CAUSE_UNSPECIFIED REVOCATION_CAUSE_SELF REVOCATION_CAUSE_TARGETED REVOCATION_CAUSE_ADMIN_TARGETED REVOCATION_CAUSE_SESSION_CAP_EXCEEDED REVOCATION_CAUSE_PASSWORD_RESET
activation_token

The cleartext activation token, returned exactly once and never stored.

optional is load-bearing: inviting a person who is already ACTIVE grants the new binding without issuing a token, and a bare string cannot distinguish that from an empty token.

stringOutput only
expire_time

When the activation token stops being usable. Absent whenever the token is.

string format: date-time Output only
Example
{
"operation": {
"operation_type": "IAM_OPERATION_TYPE_UNSPECIFIED",
"status": "IAM_OPERATION_STATUS_UNSPECIFIED",
"scope_type": "SCOPE_TYPE_UNSPECIFIED",
"cause": "REVOCATION_CAUSE_UNSPECIFIED"
}
}

Default error response

Media type application/json

The Status type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by gRPC. Each Status message contains three pieces of data: error code, error message, and error details. You can find out more about this error model and how to work with it in the API Design Guide.

object
code

The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].

integer format: int32
message

A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.

string
details

A list of messages that carry the error details. There is a common set of message types for APIs to use.

Array<object>

Contains an arbitrary serialized message along with a @type that describes the type of the serialized message.

object
@type

The type of the serialized message.

string
key
additional properties
any
Example generated
{
"code": 1,
"message": "example",
"details": [
{
"@type": "example"
}
]
}