Invitations
Invite users to workspaces and teams via email.
Invitation Model
class Invitation(BaseModel):
workspace = models.ForeignKey(Workspace, null=True, blank=True)
team = models.ForeignKey(Team, null=True, blank=True)
inviter = models.ForeignKey(User, related_name="sent_invitations")
invitee = models.ForeignKey(User, null=True, blank=True, related_name="received_invitations")
email = models.EmailField()
role = models.CharField(choices=ROLE_CHOICES, default="member")
is_accepted = models.BooleanField(default=False)An invitation targets either a workspace or a team (not both). If the invitee doesn't have an account yet, only the email field is populated.
Invitations are the only way into a workspace or team.
Who Can Invite
| Target | Who |
|---|---|
| A workspace | Its owner or an admin |
| A team | The workspace's owner or admins, or the team's owner or admins |
Team roles count only while their holder is still a member of the workspace. The same people can resend, cancel or change the role of a pending invitation; having sent it isn't enough on its own. Apart from its role, a pending invitation can't be changed.
API Endpoints
| Method | Endpoint | Description |
|---|---|---|
| GET | /api/invitations/ | Invitations addressed to your account, and pending ones for workspaces and teams you manage |
| POST | /api/invitations/ | Create invitation |
| GET | /api/invitations/{id}/ | Retrieve invitation |
| PATCH | /api/invitations/{id}/ | Change a pending invitation's role |
| DELETE | /api/invitations/{id}/ | Cancel invitation |
| POST | /api/invitations/{id}/resend/ | Resend invitation email |
| POST | /api/invitations/{invitation_id}/accept/ | Accept invitation |
Send Invitation
POST /api/invitations/{
"email": "colleague@example.com",
"workspace": "workspace-uuid",
"role": "member"
}The invitation email names who sent it and links to the invitation in the frontend.
Accept Invitation
POST /api/invitations/{invitation_id}/accept/Only the person it's addressed to can accept it: the linked account, or an account whose email matches the invitation's (case-insensitive). Anyone else gets 403.
- Workspace invitation: creates a
WorkspaceMembershipwith the invitation's role. - Team invitation: adds the person to the team with the invitation's role, and to the team's workspace as a member if they aren't one already.
The invitation is then marked accepted and can't be accepted again.