agency-board

POST /v1/agency/boards/{boardId}/invites

Mint a copy-paste link to this board.

All agency-board endpoints

Authentication

Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/agency/boards/{boardId}/invites \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{  }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Returns a link you can paste into anything — a chat, an email you write yourself, a document. **No email is sent by us**, which is the point. A `viewer` link is read-only and needs **no Zinn® account**: whoever opens it sees exactly what the client sees, and can write nothing. Any other role seats the person on the board and therefore requires them to sign in first. ⛔ `token` appears in **this response only**. It cannot be read back later. ⛔ For a seat-bearing role this refuses unless the caller could grant that seat's organisation role themselves. The check has to happen here rather than at redemption, because by then the person redeeming is a stranger and there is no principal whose privileges could bound the grant.

Parameters

NameTypeRequiredWhat it is
boardId (path)UuidYesProject board ID (UUIDv7).

Request body

NameTypeRequiredWhat it is
roleAgencyBoardInviteRoleNo
labelstringNo
expires_in_daysintegerNo
max_usesintegerNoOmit for an unlimited link.

Response

NameTypeRequiredWhat it is
idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
board_idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
roleAgencyBoardInviteRoleYesWhat a share link grants. `viewer` is **link-only**: it creates no board seat and no organisation membership, because it grants no identity — it is read-through-the-token, which…
tokenstringNoThe full link token. ⛔ **Present on the create response and NOWHERE ELSE.** Only its SHA-256 digest is stored, so nothing can re-derive it — a screen that needs it must keep it…
token_prefixstringYesThe first few characters, so a manager with three links open can tell them apart. Far too short to shorten the search space of the secret part.
labelstringNoA note the manager typed. Never shown to the recipient.
member_org_idstringNoThe organisation a seat from this link belongs to. `null` for `viewer`, which seats nobody.
expires_atstringYesWhen the link stops admitting **new** people. ⛔ Expiry does not evict anybody who already joined — a colleague who joined in March must not lose the board in April because the s…
max_usesintegerNo`null` is unlimited. `1` makes the link single-use.
usesintegerYesSeats created through this link. A repeat visit by somebody already on the board does **not** count, so a client who bookmarks the link cannot exhaust it.
revoked_atstringNo
last_used_atstringNo
created_atstringYes
is_livebooleanYesWhether the link may admit somebody new right now — not revoked, not expired, not exhausted. Computed, so a caller never has to re-implement all three conditions.

Errors this endpoint can return

401 · 403 · 404 · 422