Skip to content
Proud to collaborate with Microsoft for Startups

identity.end-user.invite ​

Mail an admin-provisioned end-user their access to an app

Mail an admin-provisioned end-user their access to an app.

Issues a single-use invite token (purpose="invite") and sends the internal end_user_invite email. A password-setting token is issued when the global account has no password. A redeem token is also issued when a password exists but the email is unverified — /authorize cannot use that password until the mailbox is proven. If they already have a verified password, the email tells them to sign in instead and no token is created.

Inputs:

  • actor, organization_uuid, identity_app_uuid (required)
  • one of end_user_uuid or email (required) to identify the target
  • app_organization_uuid (optional — names the workspace in the email)
  • resend (optional bool — marks the email as a reminder)
  • expires_in_hours (optional, default 72)

Outputs (terminal state_data):

  • end_user_uuid, email, credential_required, invite_issued, expires_at
  • email_dispatched, email_workflow_ref, dispatch_error The invite token itself is never returned.

Overview ​

PropertyValue
Workflow typeLinear
LibraryApp-identity
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
actorstringYes——
organization_uuiduuidYes——
identity_app_uuiduuidYes——
end_user_uuiduuidNo——
emailemailNo——
app_organization_uuiduuidNo——
resendbooleanNo——
expires_in_hoursintegerNo——

Output Schema ​

FieldTypeRequiredDefaultDescription
identity_app_uuiduuidNo——
end_user_uuiduuidNo——
emailemailNo——
credential_requiredbooleanNo——
invite_issuedbooleanNo——
expires_atdatetimeNo——
email_dispatchedbooleanNo——
email_workflow_refstringNo——
dispatch_errorstringNo——
app_namestringNo——
workspace_namestringNo——
rolestringNo——
resendbooleanNo——
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
reasonstringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—executeIssue the invite token
dispatchingNoNo—dispatchSend the invite email
completedNoYesYes—Invite processed
failedNoYesNo—Invite failed

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutedispatching—
dispatchingdispatchcompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "identity.end-user.invite",
  "initial_data": {
    "actor": "value",
    "organization_uuid": "value",
    "identity_app_uuid": "value"
  }
}