HyperSaaS
BackendWorkspaces & Teams

Invitations

Invite users to workspaces and teams via email.

Invitation Model

class Invitation(BaseModel):
    workspace = models.ForeignKey(Workspace, null=True, blank=True)
    team = models.ForeignKey(Team, null=True, blank=True)
    inviter = models.ForeignKey(User, related_name="sent_invitations")
    invitee = models.ForeignKey(User, null=True, blank=True, related_name="received_invitations")
    email = models.EmailField()
    role = models.CharField(choices=ROLE_CHOICES, default="member")
    is_accepted = models.BooleanField(default=False)

An invitation targets either a workspace or a team (not both). If the invitee doesn't have an account yet, only the email field is populated.

Invitations are the only way into a workspace or team.

Who Can Invite

TargetWho
A workspaceIts owner or an admin
A teamThe workspace's owner or admins, or the team's owner or admins

Team roles count only while their holder is still a member of the workspace. The same people can resend, cancel or change the role of a pending invitation; having sent it isn't enough on its own. Apart from its role, a pending invitation can't be changed.

API Endpoints

MethodEndpointDescription
GET/api/invitations/Invitations addressed to your account, and pending ones for workspaces and teams you manage
POST/api/invitations/Create invitation
GET/api/invitations/{id}/Retrieve invitation
PATCH/api/invitations/{id}/Change a pending invitation's role
DELETE/api/invitations/{id}/Cancel invitation
POST/api/invitations/{id}/resend/Resend invitation email
POST/api/invitations/{invitation_id}/accept/Accept invitation

Send Invitation

POST /api/invitations/
{
  "email": "colleague@example.com",
  "workspace": "workspace-uuid",
  "role": "member"
}

The invitation email names who sent it and links to the invitation in the frontend.

Accept Invitation

POST /api/invitations/{invitation_id}/accept/

Only the person it's addressed to can accept it: the linked account, or an account whose email matches the invitation's (case-insensitive). Anyone else gets 403.

  • Workspace invitation: creates a WorkspaceMembership with the invitation's role.
  • Team invitation: adds the person to the team with the invitation's role, and to the team's workspace as a member if they aren't one already.

The invitation is then marked accepted and can't be accepted again.

On this page