Accept Team Invitation
Handler: AcceptTeamInvitation. The signed-in user accepts their own pending team invitation for this customer. Requires a membership link with status 'invited' held by the caller; a missing or removed link is refused (403 common.permission_denied). Activates the link and the pre-assigned customer role — the moment access is granted. Idempotent: an already-accepted invitation returns 200. Returns { customer_id }.
Authorization
bearerAuth JWT token obtained from /v1/authenticate endpoint
In: header
Path Parameters
id path parameter
Customer UUID.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/v1/customers/497f6eca-6276-4993-bfeb-53cbbbba6f08/teams/accept"{
"customer_id": "160c0c4b-9966-4dc1-a916-8407eb10d74e"
}{
"status": 400,
"message": "Bad request"
}{
"status": 401,
"message": "Unauthorized"
}{
"status": 403,
"message": "Forbidden"
}{
"status": 404,
"message": "Not found"
}{
"status": 500,
"message": "Internal server error"
}Verifies a signatory invitation token and returns the invitee details. Password setup tokens are returned only when the invitee must complete password setup before signing in.
Handler: InviteTeamMember. Creates a pending membership (link status 'invited', role pre-assigned inactive), sends the invitation email and in-app notification. Re-inviting a pending or removed member refreshes the invitation; inviting a member who already accepted is refused with 409 customers_m.team_member_already_active (their membership is never reset). Caller must hold the customer's admin role or be a global operator (read-all on customers). Returns { message }.