agency-board
POST /v1/agency/boards/{boardId}/invites
Mint a copy-paste link to this board.
認証
ベアラー トークンとして API キーを送信します。このエンドポイントでは仕様に特定の権限が記載されていないため、キーに必要な最小限の権限を付与し、推測するのではなくレスポンスを確認してください。
このエンドポイントは組織IDを受け付けません。お使いのキーによって所属する組織がすでに特定されており、レスポンスはその組織にスコープされます。
試してみる
アングルブラケット内のすべてをご自身の値に置き換え、キーのプレースホルダーをご利用中のダッシュボードのキーに置き換えてください。
curl -X POST https://api.zinndigital.com/v1/agency/boards/{boardId}/invites \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ }'ログインしていますか?ダッシュボード内のAPIコンソールでは、実際の組織IDやお客様ご自身のキーが自動入力され、ライブAPIに対してリクエストが実行されるため、実際のレスポンスを確認することができます。 API コンソールでこのエンドポイントを開く
詳細
Returns a link you can paste into anything — a chat, an email you write yourself, a document. **No email is sent by us**, which is the point. A `viewer` link is read-only and needs **no Zinn® account**: whoever opens it sees exactly what the client sees, and can write nothing. Any other role seats the person on the board and therefore requires them to sign in first. ⛔ `token` appears in **this response only**. It cannot be read back later. ⛔ For a seat-bearing role this refuses unless the caller could grant that seat's organisation role themselves. The check has to happen here rather than at redemption, because by then the person redeeming is a stranger and there is no principal whose privileges could bound the grant.
パラメータ
| 名前 | タイプ | 必須 | これがその内容です |
|---|---|---|---|
boardId (path) | Uuid | はい | Project board ID (UUIDv7). |
リクエスト本文
| 名前 | タイプ | 必須 | これがその内容です |
|---|---|---|---|
role | AgencyBoardInviteRole | いいえ | — |
label | string | いいえ | — |
expires_in_days | integer | いいえ | — |
max_uses | integer | いいえ | Omit for an unlimited link. |
返信
| 名前 | タイプ | 必須 | これがその内容です |
|---|---|---|---|
id | Uuid | はい | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
board_id | Uuid | はい | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
role | AgencyBoardInviteRole | はい | What a share link grants. `viewer` is **link-only**: it creates no board seat and no organisation membership, because it grants no identity — it is read-through-the-token, which… |
token | string | いいえ | The full link token. ⛔ **Present on the create response and NOWHERE ELSE.** Only its SHA-256 digest is stored, so nothing can re-derive it — a screen that needs it must keep it… |
token_prefix | string | はい | The first few characters, so a manager with three links open can tell them apart. Far too short to shorten the search space of the secret part. |
label | string | いいえ | A note the manager typed. Never shown to the recipient. |
member_org_id | string | いいえ | The organisation a seat from this link belongs to. `null` for `viewer`, which seats nobody. |
expires_at | string | はい | When the link stops admitting **new** people. ⛔ Expiry does not evict anybody who already joined — a colleague who joined in March must not lose the board in April because the s… |
max_uses | integer | いいえ | `null` is unlimited. `1` makes the link single-use. |
uses | integer | はい | Seats created through this link. A repeat visit by somebody already on the board does **not** count, so a client who bookmarks the link cannot exhaust it. |
revoked_at | string | いいえ | — |
last_used_at | string | いいえ | — |
created_at | string | はい | — |
is_live | boolean | はい | Whether the link may admit somebody new right now — not revoked, not expired, not exhausted. Computed, so a caller never has to re-implement all three conditions. |
このエンドポイントが返すエラー
401 · 403 · 404 · 422