Verify invitation token
AUTHENTICATED BY X-API-Key, not by a bearer token. auth.APIKeyMiddleware REPLACES the usual chain on this route, so there is no user context, no RBAC check and no licence check — and the refusals are common.api_key_required / common.invalid_api_key rather than common.unauthorized / common.rbac_no_rec_access. An OPTIONS request skips the key check entirely. Validate invitation token and return invitation type for activation flow (public endpoint, API key only)
Authorization
apiKeyAuth Service API key for the eight pre-authentication user routes. auth.APIKeyMiddleware REPLACES the bearer chain on those routes rather than wrapping it: there is no user context, no RBAC check and no licence check on them.
In: header
Query Parameters
Invitation token from email link
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/v1/users/verify-invitation?token=string"{
"valid": true,
"invite_type": "regular",
"can_activate": true,
"expires_at": "2019-08-24T14:15:22Z"
}{
"status": 400,
"message": "Invalid user input",
"code": "users_m.invalid_user_input",
"class": "validation"
}{
"status": 401,
"message": "common.api_key_required",
"code": "common.api_key_required",
"class": "business"
}{
"status": 403,
"message": "common.invalid_api_key",
"code": "common.invalid_api_key",
"class": "business"
}{
"status": 429,
"message": "Too many activation attempts. Please try again in 842 seconds",
"code": "users_m.activation_rate_limit_exceeded",
"class": "temporary",
"retryable": true
}{
"status": 500,
"message": "Internal server error",
"code": "common.server_error",
"class": "business"
}{
"overall_status": "unhealthy",
"message": "Service is shutting down",
"timestamp": "2026-08-27T15:04:05Z"
}