Issues an invitation and emails its redemption link to the invited party.
POST
/api/developer-portal/invitations
deprecated
Requires: DeveloperPortal.Invitations, DeveloperPortal.Invitations.Create, merchant scope.
The invited party must already be an active user of the acting merchant. The returned invitation carries no token; the link travels only in the email. If the email cannot be sent, the invitation is revoked before the call returns. Issues are rate limited per merchant, and a spent budget answers 429 until the window rolls over.
Example request
Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.
The request body is a DeveloperPortalInvitationCreateDto. See the Request body section below for its fields.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
suppressNulls
required |
query | boolean | If true, omit properties with null values. |
X-Acting-Merchant-Id
required |
header | string (uuid) | The merchant to act for. Optional: when absent, the caller's own merchant scope answers. A caller whose identity carries no merchant scope, such as an administrator, must send it. The selection is authorized on every operation; a merchant the caller may not act for is refused. |
Request body
application/json
, required
| Field | Type | Description |
|---|---|---|
invitedIdentityUserId
required |
string (uuid) | The existing identity user to invite. Must already be an active merchant user of the caller's merchant, which the picker guarantees and the issue path asserts anyway. |
email
required |
string | Where to send the invitation. Blank sends it to the invited user's own registered address. nullablemax length 256 |
role
required |
all of DeveloperPortalRole | The portal capability a redemption will grant. |
This request body has no documented fields.
Responses
200 OK
Body: DeveloperPortalInvitationDto
Each item has these fields.
| Field | Type | Description |
|---|---|---|
id
required |
string (uuid) | |
creationTime
required |
string (date-time) | The date and time when this entity was created. |
creatorId
required |
string (uuid) | The ID of the user who created this entity. nullable |
lastModificationTime
required |
string (date-time) | The date and time when this entity was last modified. nullable |
lastModifierId
required |
string (uuid) | The ID of the user who last modified this entity. nullable |
isDeleted
required |
boolean | Indicates whether this entity has been deleted. |
deleterId
required |
string (uuid) | The ID of the user who deleted this entity, if it is deleted. nullable |
deletionTime
required |
string (date-time) | The date and time when this entity was deleted, if it is deleted. nullable |
merchantId
required |
string (uuid) | The merchant the invitation offers access to, or `null` when it offers access to a reseller. Exactly one of this and `resellerId` is set. nullable |
resellerId
required |
string (uuid) | The reseller the invitation offers access to, or `null` when it offers access to a merchant. Exactly one of this and `merchantId` is set. nullable |
email
required |
string | The address the invitation was emailed to. nullable |
invitedIdentityUserId
required |
string (uuid) | The identity user the invitation is for, and the only one who can redeem it. nullable |
role
required |
all of DeveloperPortalRole | The portal capability a redemption will grant. nullable |
expiresAt
required |
string (date-time) | When the invitation stops being redeemable, in UTC. The contract stays UTC in and UTC out; display surfaces convert it to the viewer's time zone. nullable |
status
required |
all of DeveloperPortalInvitationStatus | The lifecycle state, already resolved against the clock by the reader. nullable |
issuedByUserId
required |
string (uuid) | The back-office user who issued the invitation. nullable |
redeemedAt
required |
string (date-time) | When the invitation was redeemed, in UTC, or `null` if it never was. nullable |
revokedAt
required |
string (date-time) | When the invitation was revoked, in UTC, or `null` if it never was. nullable |
concurrencyStamp
required |
string | Optimistic-concurrency token. nullable |
user
required |
all of DeveloperPortalUserSummaryDto | The identity half of the invited party: who they are, and whether they already hold a back-office role. `null` when the reader did not enrich the row. |
This response has no documented body fields.
403 Forbidden
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
401 Unauthorized
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
400 Bad Request
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
404 Not Found
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
501 Not Implemented
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
500 Internal Server Error
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
default The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
429 The request was refused because a rate limit was exceeded. Wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling.
Body: RateLimitProblemDetails
Each item has these fields.
| Field | Type | Description |
|---|---|---|
type
required |
string | The problem type identifier. Always the same value: the failure is the status code itself, so there is no sub-type for a caller to branch on. nullable |
title
required |
string | A short, human-readable summary of the problem type. nullable |
status
required |
integer (int32) | The HTTP status code, repeated in the body as the problem-details format defines. |
detail
required |
string | A human-readable explanation of this occurrence of the problem. nullable |
retryAfterSeconds
required |
integer (int32) | How long to wait before retrying, in whole seconds, carrying the same figure as the `Retry-After` header. Always at least one: a value of zero would invite an immediate retry that is certain to be rejected again. |
This response has no documented body fields.
Errors
A failed request returns the platform error envelope. The
error reference lists every value
error.code can carry and shows the four response shapes.