API

Receive links.

A receive link lets someone without an account send files into a folder you can write. These calls manage the link. The sender's page is not called with an API key.

Receive links need the portal feature. Custom questions on a link need the automation feature. See the API reference for the key and for errors.

Your receive links, and the limits that apply to a new one.

Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

A receive link is an address you give to people who have no account, so they can send files straight into one of your folders. Receive links are part of the portal feature. An administrator sees every link on the server; everyone else sees their own, newest first. policy says whether a link may never expire, how many days a new one lasts by default, and whether this license includes custom form fields.

Success. 200.

FieldTypeMeaning
linksarray of objectsrequired

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
namestringrequiredThe name.
messagestringrequired
rootIdstringrequiredThe id.
rootNamestringrequiredThe storage location's name.
pathstringrequiredWhere the files land, relative to the storage location.
spaceIdstringoptionalThe space the owner picked. Absent on a link made before spaces.
spaceNamestringrequiredThe space's name. Empty, and left out, when there is no space.
spacePathstringrequiredpath as it reads inside the space. This is what the owner picks.
expiresAtstringoptionalA time, as RFC 3339.
hasPasscodebooleanrequired
requireEmailbooleanrequiredAn email address.
verifyEmailbooleanrequiredAn email address.
maxBytesPerSubmissionintegeroptional
maxFilesintegeroptional
allowedTypesstringrequired
maxBytesTotalintegeroptional
oneTimebooleanrequired
subfolderbooleanrequired
subfolderTemplatestringrequired
notifyOwnerbooleanrequired
formFieldsarray of objectsrequired

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
labelstringrequired
kindobjectrequired
requiredbooleanoptional
choicesarray of stringoptional
statestringrequiredWhere this record is in its life.
bytesReceivedintegerrequired
submissionCountintegerrequired
ownerIdstringrequiredThe id.
ownerEmailstringrequiredAn email address.
createdAtstringrequiredA time, as RFC 3339.
urlstringoptionalThe address to give out, present only in the reply that creates the link. Only a hash of the token is kept, so it cannot be shown again.
policyobjectrequired

It is an object:

FieldTypeMeaning
allowNeverExpiresbooleanrequired
defaultExpiryDaysintegerrequired
formFieldsIncludedbooleanrequiredWhether custom form fields are included in this license.
{
  "links": [
    {
      "id": "k7Qm2sLp9vX4aB1c",
      "name": "Rush delivery",
      "message": "The cut is in the folder.",
      "rootId": "k7Qm2sLp9vX4aB1c",
      "rootName": "example",
      "path": "projects/rush",
      "spaceName": "example",
      "spacePath": "projects/rush",
      "hasPasscode": true,
      "requireEmail": true,
      "verifyEmail": true,
      "allowedTypes": "example",
      "oneTime": true,
      "subfolder": true,
      "subfolderTemplate": "example",
      "notifyOwner": true,
      "formFields": [
        {
          "id": "k7Qm2sLp9vX4aB1c",
          "label": "example",
          "kind": {},
          "required": true,
          "choices": [
            "example"
          ]
        }
      ],
      "state": "active",
      "bytesReceived": 1,
      "submissionCount": 1,
      "ownerId": "k7Qm2sLp9vX4aB1c",
      "ownerEmail": "[email protected]",
      "createdAt": "2026-10-05T18:00:00Z"
    }
  ],
  "policy": {
    "allowNeverExpires": true,
    "defaultExpiryDays": 1,
    "formFieldsIncluded": true
  }
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "unauthenticated",
    "message": "sign in to continue"
  }
}

POST /api/v1/receive-links

Make a receive link.

Who. Any user with a key that has the write scope. A key with the admin scope includes the others. The key needs a license that includes the REST API. This call can also answer 402 when form fields were sent and this server's license does not include automation.

The reply is the only time the link's address is shown, in url: only a hash of the token is kept, so a lost address means making a new link. The destination must be a folder that already exists and that the owner may write to; the link acts with its owner's rights. Leaving out expiresInDays uses the administrator's default, and null means never, which the administrator has to allow. Custom form fields need the automation feature.

Request body. JSON.

A field the server does not know is refused with 400.

FieldTypeMeaning
namestringoptionalThe name.
messagestringoptional
rootIdstringoptionalA storage location. Kept for older callers. A person picks a space.
spaceIdstringoptionalA space. The path is then relative to that space, not the location.
pathstringoptionalA path relative to the space or the storage location, with / between folders and no leading slash.
expiresInDaysintegeroptional
passcodestringoptional
requireEmailbooleanoptionalAn email address.
verifyEmailbooleanoptionalAn email address.
maxBytesPerSubmissionintegeroptional
maxFilesintegeroptional
allowedTypesstringoptional
maxBytesTotalintegeroptional
oneTimebooleanoptional
subfolderbooleanoptional
subfolderTemplatestringoptional
notifyOwnerbooleanoptional
formFieldsarray of FormFieldoptional

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
labelstringrequired
kindobjectrequired
requiredbooleanoptional
choicesarray of stringoptional
statestringoptionalWhere this record is in its life.
{
  "name": "Rush delivery",
  "message": "The cut is in the folder.",
  "rootId": "k7Qm2sLp9vX4aB1c",
  "spaceId": "k7Qm2sLp9vX4aB1c",
  "path": "projects/rush",
  "expiresInDays": 1,
  "passcode": "example",
  "requireEmail": true
}

Success. 200.

FieldTypeMeaning
idstringrequiredThe id.
namestringrequiredThe name.
messagestringrequired
rootIdstringrequiredThe id.
rootNamestringrequiredThe storage location's name.
pathstringrequiredWhere the files land, relative to the storage location.
spaceIdstringoptional, left out when emptyThe space the owner picked. Absent on a link made before spaces.
spaceNamestringrequiredThe space's name. Empty, and left out, when there is no space.
spacePathstringrequiredpath as it reads inside the space. This is what the owner picks.
expiresAtstringoptionalA time, as RFC 3339.
hasPasscodebooleanrequired
requireEmailbooleanrequiredAn email address.
verifyEmailbooleanrequiredAn email address.
maxBytesPerSubmissionintegeroptional
maxFilesintegeroptional
allowedTypesstringrequired
maxBytesTotalintegeroptional
oneTimebooleanrequired
subfolderbooleanrequired
subfolderTemplatestringrequired
notifyOwnerbooleanrequired
formFieldsarray of objectsrequired

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
labelstringrequired
kindobjectrequired
requiredbooleanoptional
choicesarray of stringoptional
statestringrequiredWhere this record is in its life.
bytesReceivedintegerrequired
submissionCountintegerrequired
ownerIdstringrequiredThe id.
ownerEmailstringrequiredAn email address.
createdAtstringrequiredA time, as RFC 3339.
urlstringoptional, left out when emptyThe address to give out, present only in the reply that creates the link. Only a hash of the token is kept, so it cannot be shown again.
{
  "id": "k7Qm2sLp9vX4aB1c",
  "name": "Rush delivery",
  "message": "The cut is in the folder.",
  "rootId": "k7Qm2sLp9vX4aB1c",
  "rootName": "example",
  "path": "projects/rush",
  "spaceName": "example",
  "spacePath": "projects/rush",
  "hasPasscode": true,
  "requireEmail": true,
  "verifyEmail": true,
  "allowedTypes": "example",
  "oneTime": true,
  "subfolder": true,
  "subfolderTemplate": "example",
  "notifyOwner": true,
  "formFields": [
    {
      "id": "k7Qm2sLp9vX4aB1c",
      "label": "example",
      "kind": {},
      "required": true,
      "choices": [
        "example"
      ]
    }
  ],
  "state": "active",
  "bytesReceived": 1,
  "submissionCount": 1,
  "ownerId": "k7Qm2sLp9vX4aB1c",
  "ownerEmail": "[email protected]",
  "createdAt": "2026-10-05T18:00:00Z"
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestno name, no folder, or a folder that is not there; a passcode under 6 characters; a limit below 1; a file type that is not one; more than 20 questions; a link that never expires when the administrator requires an expiry; or a `state`, which a new link cannot have
402licence_requiredform fields were sent and this server's license does not include automation
404not_foundno such storage location, or a folder the owner may not write to
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
{
  "error": {
    "code": "bad_request",
    "message": "no name, no folder, or a folder that is not there; a passcode under 6 characters; a limit below 1; a file type that is not one; more than 20 questions; a link that never expires when the administrator requires an expiry; or a `state`, which a new link cannot have"
  }
}

Change a receive link, or switch it off and on.

Who. Any user with a key that has the write scope. A key with the admin scope includes the others. The key needs a license that includes the REST API. This call can also answer 402 when form fields were sent and this server's license does not include automation.

Send only what changes. Pointing the link at another folder checks the owner's rights there again. state may be active or disabled; to end a link, delete it. A link that has ended cannot be switched back on. The address is not shown again. Custom form fields need the automation feature. Anyone but the owner or an administrator is answered as if the link did not exist.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Request body. JSON.

A field the server does not know is refused with 400.

FieldTypeMeaning
namestringoptionalThe name.
messagestringoptional
rootIdstringoptionalA storage location. Kept for older callers. A person picks a space.
spaceIdstringoptionalA space. The path is then relative to that space, not the location.
pathstringoptionalA path relative to the space or the storage location, with / between folders and no leading slash.
expiresInDaysintegeroptional
passcodestringoptional
requireEmailbooleanoptionalAn email address.
verifyEmailbooleanoptionalAn email address.
maxBytesPerSubmissionintegeroptional
maxFilesintegeroptional
allowedTypesstringoptional
maxBytesTotalintegeroptional
oneTimebooleanoptional
subfolderbooleanoptional
subfolderTemplatestringoptional
notifyOwnerbooleanoptional
formFieldsarray of FormFieldoptional

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
labelstringrequired
kindobjectrequired
requiredbooleanoptional
choicesarray of stringoptional
statestringoptionalWhere this record is in its life.
{
  "name": "Rush delivery",
  "message": "The cut is in the folder.",
  "rootId": "k7Qm2sLp9vX4aB1c",
  "spaceId": "k7Qm2sLp9vX4aB1c",
  "path": "projects/rush",
  "expiresInDays": 1,
  "passcode": "example",
  "requireEmail": true
}

Success. 200.

FieldTypeMeaning
idstringrequiredThe id.
namestringrequiredThe name.
messagestringrequired
rootIdstringrequiredThe id.
rootNamestringrequiredThe storage location's name.
pathstringrequiredWhere the files land, relative to the storage location.
spaceIdstringoptional, left out when emptyThe space the owner picked. Absent on a link made before spaces.
spaceNamestringrequiredThe space's name. Empty, and left out, when there is no space.
spacePathstringrequiredpath as it reads inside the space. This is what the owner picks.
expiresAtstringoptionalA time, as RFC 3339.
hasPasscodebooleanrequired
requireEmailbooleanrequiredAn email address.
verifyEmailbooleanrequiredAn email address.
maxBytesPerSubmissionintegeroptional
maxFilesintegeroptional
allowedTypesstringrequired
maxBytesTotalintegeroptional
oneTimebooleanrequired
subfolderbooleanrequired
subfolderTemplatestringrequired
notifyOwnerbooleanrequired
formFieldsarray of objectsrequired

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
labelstringrequired
kindobjectrequired
requiredbooleanoptional
choicesarray of stringoptional
statestringrequiredWhere this record is in its life.
bytesReceivedintegerrequired
submissionCountintegerrequired
ownerIdstringrequiredThe id.
ownerEmailstringrequiredAn email address.
createdAtstringrequiredA time, as RFC 3339.
urlstringoptional, left out when emptyThe address to give out, present only in the reply that creates the link. Only a hash of the token is kept, so it cannot be shown again.
{
  "id": "k7Qm2sLp9vX4aB1c",
  "name": "Rush delivery",
  "message": "The cut is in the folder.",
  "rootId": "k7Qm2sLp9vX4aB1c",
  "rootName": "example",
  "path": "projects/rush",
  "spaceName": "example",
  "spacePath": "projects/rush",
  "hasPasscode": true,
  "requireEmail": true,
  "verifyEmail": true,
  "allowedTypes": "example",
  "oneTime": true,
  "subfolder": true,
  "subfolderTemplate": "example",
  "notifyOwner": true,
  "formFields": [
    {
      "id": "k7Qm2sLp9vX4aB1c",
      "label": "example",
      "kind": {},
      "required": true,
      "choices": [
        "example"
      ]
    }
  ],
  "state": "active",
  "bytesReceived": 1,
  "submissionCount": 1,
  "ownerId": "k7Qm2sLp9vX4aB1c",
  "ownerEmail": "[email protected]",
  "createdAt": "2026-10-05T18:00:00Z"
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requesta value that is not allowed, `state` set to `ended`, or a folder that is not there
402licence_requiredform fields were sent and this server's license does not include automation
404not_foundno such link, or it is not this caller's, or a folder the owner may not write to
409conflictthe link has ended; make a new one
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
{
  "error": {
    "code": "bad_request",
    "message": "a value that is not allowed, `state` set to `ended`, or a folder that is not there"
  }
}

End a receive link.

Who. Any user with a key that has the delete scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

The link stops taking files at once and cannot be turned back on. The record stays, so what it received still has a name and a folder. Ending a link that has already ended is not an error.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Success. 200.

FieldTypeMeaning
idstringrequiredThe id.
namestringrequiredThe name.
messagestringrequired
rootIdstringrequiredThe id.
rootNamestringrequiredThe storage location's name.
pathstringrequiredWhere the files land, relative to the storage location.
spaceIdstringoptional, left out when emptyThe space the owner picked. Absent on a link made before spaces.
spaceNamestringrequiredThe space's name. Empty, and left out, when there is no space.
spacePathstringrequiredpath as it reads inside the space. This is what the owner picks.
expiresAtstringoptionalA time, as RFC 3339.
hasPasscodebooleanrequired
requireEmailbooleanrequiredAn email address.
verifyEmailbooleanrequiredAn email address.
maxBytesPerSubmissionintegeroptional
maxFilesintegeroptional
allowedTypesstringrequired
maxBytesTotalintegeroptional
oneTimebooleanrequired
subfolderbooleanrequired
subfolderTemplatestringrequired
notifyOwnerbooleanrequired
formFieldsarray of objectsrequired

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
labelstringrequired
kindobjectrequired
requiredbooleanoptional
choicesarray of stringoptional
statestringrequiredWhere this record is in its life.
bytesReceivedintegerrequired
submissionCountintegerrequired
ownerIdstringrequiredThe id.
ownerEmailstringrequiredAn email address.
createdAtstringrequiredA time, as RFC 3339.
urlstringoptional, left out when emptyThe address to give out, present only in the reply that creates the link. Only a hash of the token is kept, so it cannot be shown again.
{
  "id": "k7Qm2sLp9vX4aB1c",
  "name": "Rush delivery",
  "message": "The cut is in the folder.",
  "rootId": "k7Qm2sLp9vX4aB1c",
  "rootName": "example",
  "path": "projects/rush",
  "spaceName": "example",
  "spacePath": "projects/rush",
  "hasPasscode": true,
  "requireEmail": true,
  "verifyEmail": true,
  "allowedTypes": "example",
  "oneTime": true,
  "subfolder": true,
  "subfolderTemplate": "example",
  "notifyOwner": true,
  "formFields": [
    {
      "id": "k7Qm2sLp9vX4aB1c",
      "label": "example",
      "kind": {},
      "required": true,
      "choices": [
        "example"
      ]
    }
  ],
  "state": "active",
  "bytesReceived": 1,
  "submissionCount": 1,
  "ownerId": "k7Qm2sLp9vX4aB1c",
  "ownerEmail": "[email protected]",
  "createdAt": "2026-10-05T18:00:00Z"
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
404not_foundno such link, or it is not this caller's
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "not_found",
    "message": "not found"
  }
}

What a receive link has received, newest first.

Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Up to 500 sends, each with its files, the sender's answers and the folder it was put in. scanState is pending, scanning, clean, blocked or notScanned.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Success. 200.

FieldTypeMeaning
submissionsarray of objectsrequired

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
linkIdstringrequiredThe id.
senderEmailstringrequiredAn email address.
senderNamestringrequired
emailVerifiedbooleanrequired
formValuesobjectrequired
folderstringrequired
bytesintegerrequiredSize in bytes.
fileCountintegerrequired
statestringrequiredWhere this record is in its life.
scanStatestringrequired
startedAtstringrequiredA time, as RFC 3339.
finishedAtstringoptionalA time, as RFC 3339.
filesarray of objectsrequired

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
pathstringrequiredA path relative to the space or the storage location, with / between folders and no leading slash.
finalPathstringoptional
bytesintegerrequiredSize in bytes.
checksumstringoptional
scanResultstringoptional
scanDetailstringoptional
{
  "submissions": [
    {
      "id": "k7Qm2sLp9vX4aB1c",
      "linkId": "k7Qm2sLp9vX4aB1c",
      "senderEmail": "[email protected]",
      "senderName": "example",
      "emailVerified": true,
      "formValues": {},
      "folder": "example",
      "bytes": 1048576,
      "fileCount": 1,
      "state": "active",
      "scanState": "example",
      "startedAt": "2026-10-05T18:00:00Z",
      "files": [
        {
          "id": "k7Qm2sLp9vX4aB1c",
          "path": "projects/rush",
          "finalPath": "projects/rush",
          "bytes": 1048576,
          "checksum": "example",
          "scanResult": "example",
          "scanDetail": "example"
        }
      ]
    }
  ]
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
404not_foundno such link, or it is not this caller's
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "not_found",
    "message": "not found"
  }
}

POST /api/v1/receive-links/{id}/submissions/{submission_id}/receipt

Email a sender their receipt again.

Who. Any user with a key that has the write scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Built from what is stored, for a send that is complete or blocked. Unlike the receipt at the end of a send, a failure here is the answer: the caller asked for the mail and is told why it did not go.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe receive link.
submission_idpathstringrequiredThe send.

Request body. None.

Success. 200.

FieldTypeMeaning
sentTostringrequired
{
  "sentTo": "example"
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestthe sender gave no email address
404not_foundno such link, or it has no such finished send
409conflictemail is not switched on or its settings are not complete, or the mail server refused the message; the message says why
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "the sender gave no email address"
  }
}

POST /api/v1/receive-links/{id}/block

Stop one email address sending through a link.

Who. Any user with a key that has the write scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

The address is lowercased and refused from then on. Any send it has open on this link is abandoned, so a sender found halfway through an upload cannot finish. Other links are not affected.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Request body. JSON.

A field the server does not know is refused with 400.

FieldTypeMeaning
emailstringrequiredAn email address.
{
  "email": "[email protected]"
}

Success. 200.

FieldTypeMeaning
blockedstringrequired
{
  "blocked": "example"
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestnot an email address
404not_foundno such link, or it is not this caller's
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "not an email address"
  }
}

Invitations

Who a receive link was emailed to, and whether they opened it.

Who. Any user with a key that has the read scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Success. 200.

FieldTypeMeaning
invitesarray of objectsrequired

Each item is an object:

FieldTypeMeaning
idstringrequiredThe id.
emailstringrequiredAn email address.
createdAtstringrequiredA time, as RFC 3339.
sentAtstringoptionalA time, as RFC 3339.
openedAtstringoptionalA time, as RFC 3339.
openCountintegerrequired
revokedbooleanrequired
{
  "invites": [
    {
      "id": "k7Qm2sLp9vX4aB1c",
      "email": "[email protected]",
      "createdAt": "2026-10-05T18:00:00Z",
      "sentAt": "2026-10-05T18:00:00Z",
      "openedAt": "2026-10-05T18:00:00Z",
      "openCount": 1,
      "revoked": true
    }
  ]
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
404not_foundno such link, or it is not this caller's
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "not_found",
    "message": "not found"
  }
}

POST /api/v1/receive-links/{id}/invites

Email a receive link to people, each with a link of their own.

Who. Any user with a key that has the write scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Each address gets a personal link. Opening it proves the address the way a sign-in link does, so the person is not asked for their address or a code, and what they send is put under their name. The personal token is random, only its hash is kept, and it stops working when the link ends or the invitation is withdrawn. Uses the receive.invite email template; the optional note is kept to its first 1,000 characters. Up to 50 addresses a call and 200 an hour per owner. Each address is answered on its own, so one that is not valid, is blocked on this link, or could not be emailed does not stop the rest.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe resource's id.

Request body. JSON.

A field the server does not know is refused with 400.

FieldTypeMeaning
emailsarray of stringrequired
notestringoptional
{
  "emails": [
    "[email protected]"
  ],
  "note": "The cut is in the folder."
}

Success. 200.

FieldTypeMeaning
invitesarray of objectsrequired

Each item is an object:

FieldTypeMeaning
emailstringrequiredAn email address.
sentbooleanrequired
errorstringoptional
{
  "invites": [
    {
      "email": "[email protected]",
      "sent": true,
      "error": "example"
    }
  ]
}

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
400bad_requestno addresses, or more than 50
404not_foundno such link, or it is not this caller's
409conflictthe link has ended or is switched off, this server has no hostname, email is not set up, or too many invitations were sent this hour
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "bad_request",
    "message": "no addresses, or more than 50"
  }
}

Withdraw one person's invitation.

Who. Any user with a key that has the write scope. A key with the admin scope includes the others. The key needs a license that includes the REST API.

Their personal link stops working at once. The receive link itself, and everyone else's invitation, are untouched. Answers 204.

Parameters.

NameInTypeMeaning
idpathstringrequiredThe receive link.
invite_idpathstringrequiredThe invitation.

Success. 204.

The reply has no body.

Errors. The body always has the shape in Errors. Match on code.

StatuscodeWhen
404not_foundno such link or invitation, or it is not this caller's
401unauthenticatedno key, or a key that is unknown, expired, revoked, or owned by a disabled account
403forbiddenthe key is valid but does not have the scope, or an administrator route was called by someone who is not an administrator
402licence_requiredthe license does not include the REST API
{
  "error": {
    "code": "not_found",
    "message": "not found"
  }
}