API reference
Invites
Invite people to sign in, list and revoke invites.
3 actions · base URL https://api.bizisy.com/v1 · generated from the same definitions as the API.
Invite a person to sign in#
POST/v1/org/invites.createWrite
Creates a sign-in invite link for a person. role is member, viewer, hr or admin (hr and admin only for owners/admins); if the person already has a membership, omit role to keep theirs (a different role is a conflict: change it with platform_members_set_role). Bizisy emails the link to the person's work email (reply-to you); email.status says whether it was sent (email.reason rate_limited: the organization reached its daily email limit), and email.message says what to tell the user. Returns the link once as well, in the web app only: API keys and connected AI apps get url null (the link is a sign-in credential), so if email.status is not sent, tell the user to invite the person again from Bizisy and share the link privately. It expires in 14 days. Inviting again revokes their earlier open link. People who have left, or already have a login, cannot be invited.
- Who can call it
- Manage key owner admin hr
- Keys and apps
- url is null: the sign-in link is only emailed to the person.
- MCP tool
org_invites_createon HR Assistant- Preview
?dry_run=trueruns every check and saves nothing- Retries
- An Idempotency-Key prevents a second run, but the result is never stored (it holds a secret or personal data): a retry gets a 409 that points to Activity
Input
person_idstringrequiredrole"member" | "hr" | "admin" | "viewer"
Returns
invite_idstringrequiredurlstring | nullrequiredThe sign-in link, only for a person signed in to Bizisy; null for API keys and connected apps.
expires_atstringrequiredemailobjectrequired3 fields
status"sent" | "failed" | "skipped"requiredmessagestringrequiredreason"rate_limited"
Errors
validation_failed unauthenticated forbidden not_found conflict rate_limited internal
curl https://api.bizisy.com/v1/org/invites.create \
-H "Authorization: Bearer $BIZISY_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{"person_id":"p1","role":"viewer"}'const res = await fetch('https://api.bizisy.com/v1/org/invites.create', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.BIZISY_API_KEY}`,
'Content-Type': 'application/json',
'Idempotency-Key': crypto.randomUUID(),
},
body: JSON.stringify({
"person_id": "p1",
"role": "viewer"
}),
});
const body = await res.json();
if (!res.ok) throw new Error(`${body.error.code}: ${body.error.message}`);
console.log(body.data);import os, uuid
import requests
res = requests.post(
"https://api.bizisy.com/v1/org/invites.create",
headers={"Authorization": f"Bearer {os.environ['BIZISY_API_KEY']}", "Idempotency-Key": str(uuid.uuid4())},
json={
"person_id": "p1",
"role": "viewer",
},
)
body = res.json()
if not res.ok:
raise RuntimeError(f"{body['error']['code']}: {body['error']['message']}")
print(body["data"]){
"data": {
"invite_id": "i1",
"url": "https://acme.bizisy.com/invite#token=tok",
"expires_at": "2026-10-18T10:00:00.000Z",
"email": {
"status": "sent",
"message": "We emailed the link to bea@acme.pt."
}
}
}List invites#
POST/v1/org/invites.listRead
Lists invites, newest first. By default only open ones (not accepted, revoked or expired); include_closed returns all. Filter by person_id. Links are never shown again: to resend, create a new invite.
- Who can call it
- Manage key owner admin hr
- MCP tool
org_invites_liston HR Assistant- Method
POSTwith a JSON body, orGETwith the input as query parameters
Input
person_idstringinclude_closedbooleanDefault
false.
Returns
An array of objects with 8 fields
An array of objects:
idstringrequiredperson_idstringrequiredemailstringrequiredrolestringrequiredcreated_atstringrequiredexpires_atstringrequiredaccepted_atstring | nullrequiredrevoked_atstring | nullrequired
Errors
validation_failed unauthenticated forbidden not_found rate_limited internal
curl https://api.bizisy.com/v1/org/invites.list \
-H "Authorization: Bearer $BIZISY_API_KEY" \
-H "Content-Type: application/json" \
-d '{"person_id":"p1","include_closed":true}'const res = await fetch('https://api.bizisy.com/v1/org/invites.list', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.BIZISY_API_KEY}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({
"person_id": "p1",
"include_closed": true
}),
});
const body = await res.json();
if (!res.ok) throw new Error(`${body.error.code}: ${body.error.message}`);
console.log(body.data);import os
import requests
res = requests.post(
"https://api.bizisy.com/v1/org/invites.list",
headers={"Authorization": f"Bearer {os.environ['BIZISY_API_KEY']}"},
json={
"person_id": "p1",
"include_closed": True,
},
)
body = res.json()
if not res.ok:
raise RuntimeError(f"{body['error']['code']}: {body['error']['message']}")
print(body["data"]){
"data": [
{
"id": "i1",
"person_id": "p1",
"email": "ana@acme.test",
"role": "member",
"created_at": "2026-10-04T10:00:00.000Z",
"expires_at": "2026-10-18T10:00:00.000Z",
"accepted_at": null,
"revoked_at": "2026-10-05T10:00:00.000Z"
}
]
}Revoke an invite#
POST/v1/org/invites.revokeDestructive
Revokes an open invite so its link stops working; the login it would have created is removed. Accepted invites cannot be revoked (disable the member instead). Revoking an already revoked invite is a no-op.
- Who can call it
- Manage key owner admin hr
- MCP tool
org_invites_revokeon HR Assistant- Preview
?dry_run=trueruns every check and saves nothing- Retries
- An Idempotency-Key prevents a second run, but the result is never stored (it holds a secret or personal data): a retry gets a 409 that points to Activity
Input
invite_idstringrequired
Returns
8 fields
idstringrequiredperson_idstringrequiredemailstringrequiredrolestringrequiredcreated_atstringrequiredexpires_atstringrequiredaccepted_atstring | nullrequiredrevoked_atstring | nullrequired
Errors
validation_failed unauthenticated forbidden not_found conflict rate_limited internal
curl https://api.bizisy.com/v1/org/invites.revoke \
-H "Authorization: Bearer $BIZISY_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{"invite_id":"i1"}'const res = await fetch('https://api.bizisy.com/v1/org/invites.revoke', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.BIZISY_API_KEY}`,
'Content-Type': 'application/json',
'Idempotency-Key': crypto.randomUUID(),
},
body: JSON.stringify({
"invite_id": "i1"
}),
});
const body = await res.json();
if (!res.ok) throw new Error(`${body.error.code}: ${body.error.message}`);
console.log(body.data);import os, uuid
import requests
res = requests.post(
"https://api.bizisy.com/v1/org/invites.revoke",
headers={"Authorization": f"Bearer {os.environ['BIZISY_API_KEY']}", "Idempotency-Key": str(uuid.uuid4())},
json={
"invite_id": "i1",
},
)
body = res.json()
if not res.ok:
raise RuntimeError(f"{body['error']['code']}: {body['error']['message']}")
print(body["data"]){
"data": {
"id": "i1",
"person_id": "p1",
"email": "ana@acme.test",
"role": "member",
"created_at": "2026-10-04T10:00:00.000Z",
"expires_at": "2026-10-18T10:00:00.000Z",
"accepted_at": null,
"revoked_at": "2026-10-05T10:00:00.000Z"
}
}Something missing or wrong on this page? Write to hello@bizisy.com.