Invite User
const url = 'https://example.com/iam/v1/users:invite';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"email":"example","name":"example","surname":"example","scope_type":"example","scope_id":"example","role_id":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/iam/v1/users:invite \ --header 'Content-Type: application/json' \ --data '{ "email": "example", "name": "example", "surname": "example", "scope_type": "example", "scope_id": "example", "role_id": "example" }'Atomically creates an invited user and, when a scope is supplied, their first binding at it — in one transaction — and returns the one-time activation token the caller relays to the invitee out of band. The backend never builds a link: it does not host the redemption page, so composing a URL here would force per-tier origin configuration. The client composes the link from the token.
The scope is optional. Supplied, the caller is authorized at that scope and the new account starts with access. Omitted, the request resolves at the platform scope, so only a platform administrator may create an account that begins with no access at all.
Request Body required
Section titled “Request Body required ”InviteUserRequest
Request message for InviteUser. The scope travels in the body, not the path: authorization reads the request fields, so the two forms are equivalent to the evaluator and the body keeps the endpoint addressed by its own resource.
object
The email address of the user to invite.
The given name of the invited user.
The family name of the invited user.
The scope type the caller is acting at: ORGANISATION, WORKSPACE, or GROUP.
Omit all three of scope_type/scope_id/role_id to create an account with no access; that request resolves at the platform scope.
The unique identifier of the scope.
The role to grant on invitation.
Example generated
{ "email": "example", "name": "example", "surname": "example", "scope_type": "example", "scope_id": "example", "role_id": "example"}Responses
Section titled “ Responses ”OK
InviteUserResponse
Response message for InviteUser: the recorded operation plus the one-time activation credential.
object
The recorded invite operation.
object
Operation ID
Unique identifier for this operation.
Resource ID
The ID of the resource affected by this operation. May be empty for async operations where the resource does not yet exist.
Resource Type
The type of resource (e.g., “com.qibdo.cloud.iam:user”).
Operation Type
The kind of mutation that was requested.
Status
Current lifecycle state of the operation.
Insert Time
When the operation was first created.
Start Time
When the operation started executing.
End Time
When the operation completed (either successfully or with errors).
Errors
Business rule errors encountered during the operation.
Operation Error
A structured error returned inside an operation when a business rule fails.
object
Error Code
Numeric identifier following the S_SSS_EEE convention.
Description
Human-readable explanation of the error.
Reason
Machine-readable error identifier in UPPER_SNAKE form - the same dispatch
key google.rpc.ErrorInfo.reason carries on the synchronous error plane.
Warnings
Non-fatal notices about the operation.
Operation Warning
A non-fatal notice attached to an operation.
object
Warning Code
Numeric identifier following the S_SSS_EEE convention.
Description
Human-readable explanation of the warning.
Progress
Percentage of completion (0-100).
Scope Type
The category of scope the operation ran in or was triggered from. SCOPE_TYPE_UNSPECIFIED when the operation is not scoped.
Scope ID
The resource this operation was scoped to - for example, when scope_type is SCOPE_TYPE_WORKSPACE this is the workspace id. Empty for SCOPE_TYPE_PLATFORM, which has no scoped resource, and when unscoped.
Principal ID
Who performed or triggered the operation, whether a person or a machine account. Always populated: platform-driven work records the reserved system principal, so every audit record names an actor.
Trace ID
W3C trace id, for correlating this operation with the traces and log lines of the request that caused it. Empty when the operation ran with no trace context - a scheduled or event-driven action rather than a request.
Revocation Cause
Discriminator for REVOKE operations only (UNSPECIFIED for every other operation_type). See RevocationCause for the available causes. Lives in the per-context extension zone (100+); 16..99 belong to the canonical operation envelope shared by every bounded context.
The cleartext activation token, returned exactly once and never stored.
optional is load-bearing: inviting a person who is already ACTIVE grants the
new binding without issuing a token, and a bare string cannot distinguish that
from an empty token.
When the activation token stops being usable. Absent whenever the token is.
Example
{ "operation": { "operation_type": "IAM_OPERATION_TYPE_UNSPECIFIED", "status": "IAM_OPERATION_STATUS_UNSPECIFIED", "scope_type": "SCOPE_TYPE_UNSPECIFIED", "cause": "REVOCATION_CAUSE_UNSPECIFIED" }}default
Section titled “default ”Default error response
The Status type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by gRPC. Each Status message contains three pieces of data: error code, error message, and error details. You can find out more about this error model and how to work with it in the API Design Guide.
object
The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].
A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.
A list of messages that carry the error details. There is a common set of message types for APIs to use.
Contains an arbitrary serialized message along with a @type that describes the type of the serialized message.
object
The type of the serialized message.
Example generated
{ "code": 1, "message": "example", "details": [ { "@type": "example" } ]}