KintsugiKintsugi

Invite a user to an organization

POST/users/invites

Invite a user to the organization by email. If the email already belongs to a Kintsugi user, they are added to the organization directly and the response outcome is ADDED with the new user; otherwise an invitation is sent and outcome is INVITED with the pending invite. Idempotent on the email: if they are already a member, or already have an invitation outstanding, the existing one is returned unchanged with a 200 instead of 201, and their role is not modified. Use PATCH /users/{userId} to change a role. Requires a user credential (an API key is rejected) that is an Owner or Admin of the organization. Select a client organization with Organization-Id, or omit it for the partner firm team. Only an Owner can assign the Owner role (403). Applies to organizations using Kintsugi-managed sign-in; an organization federated to its own identity provider manages invitations there.

Authorization

AuthorizationstringRequired

A signed-in user's session token, sent as Authorization: Bearer <token>. It authorizes the organizations that user can reach. Operations that manage people accept only this credential; operations on data also accept an API key.

Headers

Api-Versiondate

Release date, as YYYY-MM-DD. Defaults to 2026-07-21.

Organization-Idstring

Target client organization. Omit to manage the partner firm team when the bearer is an Owner or Admin of exactly one portfolio.

Connection-Idstring

Target connection id; resolves to its organization.

Entity-Idstring

Platform entity id; resolves to a connection's organization.

Entity-Sourcestring

Optional source to disambiguate an Entity-Id.

Body

emailstringRequired

Email address of the user to invite or add to the organization.

rolePublicUserRoleEnumRequired

Primary role to grant the user in the organization.

Available options:OWNERADMINMEMBER
additionalRolesstring[]

Optional additional role names to assign alongside the primary role.

Response

outcomePublicInviteOutcomeEnumRequired

INVITED when the result is an invitation, ADDED when an existing user holds membership directly. Branch on this rather than on which of invite / user is populated. Whether it was newly created is the response status: 201 created, 200 already existed.

Available options:INVITEDADDED
inviteOrgInviteRequired

The invitation when outcome is INVITED; null otherwise.

userOrgUserRequired

The member when outcome is ADDED; null otherwise.

200

The user was already a member of the organization, or already had an invitation outstanding. The existing one was returned unchanged; nothing was created and no role was modified.

201

Successful Response

400

The request was invalid.

401

Authentication failed or was missing.

403

The credential is not permitted for this request.

404

The requested resource was not found.

422

The request failed validation.

503

A service this request depends on was unavailable. Retry the request.

cURL
POST /users/invites
-H "Authorization: Bearer ***"
-H "Api-Version: 2026-07-21"
{
"email": "jane.doe@example.com",
"role": "OWNER",
"additionalRoles": [
"additional role"
]
}
Response
{
"outcome": "INVITED",
"invite": {
"id": "3f6c2b1e-8a4d-4c2e-9b1f-2d7e5a6c9f10",
"organizationId": "orgn_2mNpQr7Ls8f3k",
"email": "jane.doe@example.com",
"role": "OWNER",
"status": "ACTIVE",
"createdAt": "2026-07-28T12:00:00Z",
"expiresAt": "2026-07-28T12:00:00Z"
},
"user": {
"id": "3f6c2b1e-8a4d-4c2e-9b1f-2d7e5a6c9f10",
"organizationId": "orgn_2mNpQr7Ls8f3k",
"email": "jane.doe@example.com",
"role": "OWNER",
"status": "ACTIVE",
"firstName": "Jane",
"lastName": "Doe",
"createdAt": "2026-07-28T12:00:00Z"
}
}
Invite a user to an organization (2026-07-21) | Kintsugi API Reference