List pending invitations
Returns every still-pending invitation for the active organization, newest first. Existence of the row IS the pending state; accepted invitations are deleted on first sign-in.
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
List pending invitations › Responses
OK
Invite a user to the organization
Sends a Keycloak-hosted invitation email to the supplied address and records the role names to apply on acceptance. Re-inviting the same address replaces the previous pending role intent. Empty role_names defaults to no_access.
Headers
Idempotency-KeyUnique key that makes this POST safe to retry: repeats with the same key replay the first response instead of re-executing. Replays are scoped to the retrying principal (same API key / user) and kept for 24 hours. Required on every POST.
Client-generated idempotency key (e.g. a UUID).
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Invite a user to the organization › Responses
Created
Revoke a pending invitation
Cancels a pending invitation: deletes the kontier row and best-effort removes the matching Keycloak org-invitation so the action token in the user's inbox stops working. Already-accepted invitations don't exist as rows - remove the user via the membership API instead.
path Parameters
idInvitation UUID
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Revoke a pending invitation › Responses
No Content
Get the current organization profile
Returns the organization profile resolved from the caller's auth context (name, slug, default locale, etc.).
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Get the current organization profile › Responses
OK
Update the current organization profile
Updates editable fields on the caller's organization profile. The default_locale must be one of the supported invoicing languages (en, de, fr, es, it, pt, nl, ja).
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Update the current organization profile › Request Body
business_addresscompany_size_tierdefault_countrydefault_currencydefault_date_formatdefault_first_day_of_weekdefault_languagedefault_localedefault_number_formatdefault_timezonelegal_namemain_emailnamephonesales_audiencesignup_emailsupport_emailtax_inclusivetax_registration_numbervat_id_collectionUpdate the current organization profile › Responses
OK
List the organization's recipient lists
Who on your own side receives each kind of mail: quotes & contracts, approvals, finance, operations and reports. Each list holds one address that receives the mail plus up to two copied on it, and an entry can be a shared mailbox, a named person, or a role — a role reaches everyone who holds it, so the list stays correct when someone joins. The lists are per workspace, so a sandbox alert never reaches your live desk. Small and bounded by design, so the whole list is returned and it is not paginated.
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
List the organization's recipient lists › Responses
OK
Add someone to one of the organization's recipient lists
Adds a shared mailbox, a named person, or a role to one list. Omit is_primary to let the first entry in a list become the one that receives the mail; pass true to move it there from whichever entry holds it. Returns 409 when that recipient is already on the list and 422 when the list already holds three.
Headers
Idempotency-KeyUnique key that makes this POST safe to retry: repeats with the same key replay the first response instead of re-executing. Replays are scoped to the retrying principal (same API key / user) and kept for 24 hours. Required on every POST.
Client-generated idempotency key (e.g. a UUID).
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Add someone to one of the organization's recipient lists › Request Body
categoryWhat this contact receives. Required.
kindWhich arm this row carries. Required.
emailRequired when kind is email; must be absent otherwise.
is_primaryWhether mail for this category is addressed here. Omit to let the first row in a category become its primary.
nameOptional label.
roleRequired when kind is role; must be absent otherwise.
user_idRequired when kind is user; must be absent otherwise.
Add someone to one of the organization's recipient lists › Responses
Created
Remove an organization recipient
Removes the entry. Idempotent - removing one that is already gone succeeds. If it was the entry receiving the mail, that list falls back to the operations list and then to the organization's main address.
path Parameters
contactIdContact UUID
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Remove an organization recipient › Responses
No Content
Update an organization recipient
Changes which list an entry is on, who it names, its label, or whether it is the entry that receives the mail. Setting is_primary moves it there from whichever entry holds it, in one transaction. Clearing it leaves the list with nobody receiving directly, and its mail falls back to the operations list and then to the organization's main address.
path Parameters
contactIdContact UUID
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Update an organization recipient › Request Body
categoryMove this row to a different category. It keeps is_primary, so moving a primary into an occupied category takes that category over.
emailThe mailbox, when the resulting kind is email.
is_primarytrue addresses this category here, demoting whichever row held it. false leaves the category with no primary at all, so it falls back to the operations list and then to the organisation's main address.
kindChange which arm this row carries. Supply the matching arm field with it.
nameSet the label; an empty string clears it.
roleThe organisation role, when the resulting kind is role.
user_idThe member, when the resulting kind is user.
Update an organization recipient › Responses
OK
Where each kind of organization mail is sent
One row per list, showing the address that receives it, the addresses copied on it, and where that answer came from - the list itself, the operations fallback, the organization's main address, or nobody. It is the same lookup the sending path performs, so what it shows is what happens.
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Where each kind of organization mail is sent › Responses
OK
Get the active org's security settings
Returns the per-org auth policy: require_mfa, allowed_idps, allowed_email_domains, session_timeout_seconds. Empty arrays mean "no restriction."
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Get the active org's security settings › Responses
OK
Update the active org's security settings
Partial update - fields omitted from the body are left unchanged. Empty arrays clear the restriction (no allowed_idps / allowed_email_domains). Setting require_mfa=true takes effect on the next request; existing sessions whose access token's amr claim lacks an MFA method receive 403 MFA_REQUIRED until they re-auth with MFA.
Headers
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Update the active org's security settings › Request Body
allowed_email_domainsallowed_idpsjit_default_rolejit_enabledrequire_mfasession_timeout_secondsUpdate the active org's security settings › Responses
OK
Create a new organization
Provisions a new organization and mints its first API key. Mode determines the key prefix - "live" mints sk_live_, "sandbox" mints sk_test_. The plaintext key is returned once.
Headers
Idempotency-KeyUnique key that makes this POST safe to retry: repeats with the same key replay the first response instead of re-executing. Replays are scoped to the retrying principal (same API key / user) and kept for 24 hours. Required on every POST.
Client-generated idempotency key (e.g. a UUID).
X-Workspace-IdSelects the workspace this request operates in, by workspace UUID or slug (e.g. a sandbox workspace for test integrations). Omitted: the organization's default live workspace. Unknown workspace: 404; workspace outside your organization: 403. Discover workspaces via GET /workspaces.
Workspace UUID or slug.
Create a new organization › Request Body
namedefault_currencydefault_localesignup_emailslugCreate a new organization › Responses
Created