Invite User
POST/api/users/store-user
Creates a new user and sends them an email invitation to set their own password (in production). In non-production environments, a password is generated and returned in the response.
This endpoint currently requires session authentication; Personal Access Token scope support is in progress.
Authentication: Requires Bearer token.
Fields:
- email (required, unique, max:255) — User's email address
- name (required, string, max:255) — User's full name
- is_admin (optional, boolean, default: false) — Grant admin privileges
- is_power_user (optional, boolean, default: false) — Grant power user privileges
Requires permission: users.create
Request
Responses
- 200
- 401
- 403
- 422
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Unprocessable Entity
Response Headers
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.