agency-board
POST /v1/agency/boards/{boardId}/invites
Mint a copy-paste link to this board.
אימות
שלח מפתח API כטוקן Bearer. נקודת קצה זו אינה מציינת הרשאת ספציפית במפרט, לכן הקצה למפתח שלך את המינימום הנדרש ובדוק את התגובה במקום להניח הנחות.
נקודת קצה זו אינה דורשת מזהה ארגון. המפתח שלך כבר מזהה את הארגון שאליו הוא שייך, והתגובה מוגבלת אליו בלבד.
נסה זאת
החלף כל דבר בסוגריים זוויתיים בערכים משלך, ואת מציין מיקום המפתח במפתח מלוח הבקרה שלך.
curl -X POST https://api.zinndigital.com/v1/agency/boards/{boardId}/invites \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ }'מחובר? קונסולת ה-API בלוח הבקרה שלך מזינה את מזהה הארגון האמיתי שלך ואת המפתח שלך, ומריצה את הבקשה מול ה-API הפיזי כך שתוכל לראות את התגובה בפועל. פתח נקודת קצה זו במסוף ה-API
פרטים
Returns a link you can paste into anything — a chat, an email you write yourself, a document. No email is sent by us, which is the point. A viewer link is read-only and needs no Zinn® account: whoever opens it sees exactly what the client sees, and can write nothing. Any other role seats the person on the board and therefore requires them to sign in first. ⛔ token appears in this response only. It cannot be read back later. ⛔ For a seat-bearing role this refuses unless the caller could grant that seat's organisation role themselves. The check has to happen here rather than at redemption, because by then the person redeeming is a stranger and there is no principal whose privileges could bound the grant.
פרמטרים
| שם | סוג | נדרש | מה זה |
|---|---|---|---|
boardId (path) | Uuid | כן | Project board ID (UUIDv7). |
גוף הבקשה
| שם | סוג | נדרש | מה זה |
|---|---|---|---|
role | AgencyBoardInviteRole | לא | — |
label | string | לא | — |
expires_in_days | integer | לא | — |
max_uses | integer | לא | Omit for an unlimited link. |
תשובה
| שם | סוג | נדרש | מה זה |
|---|---|---|---|
id | Uuid | כן | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
board_id | Uuid | כן | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
role | AgencyBoardInviteRole | כן | What a share link grants. viewer is link-only: it creates no board seat and no organisation membership, because it grants no identity — it is read-through-the-token, which… |
token | string | לא | The full link token. ⛔ Present on the create response and NOWHERE ELSE. Only its SHA-256 digest is stored, so nothing can re-derive it — a screen that needs it must keep it… |
token_prefix | string | כן | The first few characters, so a manager with three links open can tell them apart. Far too short to shorten the search space of the secret part. |
label | string | לא | A note the manager typed. Never shown to the recipient. |
member_org_id | string | לא | The organisation a seat from this link belongs to. null for viewer, which seats nobody. |
expires_at | string | כן | When the link stops admitting new people. ⛔ Expiry does not evict anybody who already joined — a colleague who joined in March must not lose the board in April because the… |
max_uses | integer | לא | null is unlimited. 1 makes the link single-use. |
uses | integer | כן | Seats created through this link. A repeat visit by somebody already on the board does not count, so a client who bookmarks the link cannot exhaust it. |
revoked_at | string | לא | — |
last_used_at | string | לא | — |
created_at | string | כן | — |
is_live | boolean | כן | Whether the link may admit somebody new right now — not revoked, not expired, not exhausted. Computed, so a caller never has to re-implement all three conditions. |
שגיאות שנקודה קצה זו עשויה להחזיר
401 · 403 · 404 · 422