Skip to main content
POST
Add user to organization
Requires the IAM action workspace:AddUser. See WORKSPACE permissions for the full list, what each one covers, and an example policy.

Authorizations

Authorization
string
header
required

An OAuth 2.0 bearer token, sent as Authorization: Bearer <token>. This is the recommended way to authenticate.

Get one by exchanging a service account's access key pair at POST /v1/oauth/token with grant_type=client_credentials. It is the standard client-credentials grant, so any OAuth-aware library will obtain and refresh it for you.

Tokens last an hour by default. The same access key pair is separately your AWS SigV4 credential for the S3-compatible object endpoint, which speaks nothing else.

Headers

Idempotency-Key
string

Optional client-generated key that makes a create replay-safe. Retrying a request with the same key returns the original outcome verbatim instead of creating a duplicate resource. Reusing a key with a different request body is rejected (422); a request whose key is still being processed returns 409. Records are honored for 24 hours. Use a UUID or similarly unique token.

Maximum string length: 255

Body

application/json
email
string<email>
required

Email of the user to add

Example:

"john.doe@acme.com"

tags
object
Example:
groups
string[]

Groups to assign when the invitation is accepted. Each reference is validated in the caller organization before the invitation is created.

Group UUID, immutable name in the authenticated organization, or organization-qualified Workspace CRN. Groups contain users only.

Response

Invitation created and emailed

invitation
object
required
status
enum<string>
required

Always invited — adding a user always goes through an invitation the invitee has to accept, whether or not they already have a platform account.

Available options:
invited
Example:

"invited"