Team & invitations
Current release · Updated October 2, 2026
DryKraft team & invitations API: methods, permissions, request fields, response shapes, examples and current limits. Read authentication and error handling first.
/api/auth/invitations/previewPreview invitation
Access: Public · Success: 200
Email-bound invitation; wrong workspace hostname or expired/revoked links return 410. Does not accept access.
JSON request
| Field | Type | Required | Details |
|---|---|---|---|
token | string | Yes | Pattern: ^[a-f0-9]{64}$. |
Response
| Field | Type | Required | Details |
|---|---|---|---|
email | No | Max 200 characters. | |
role | admin | member | viewer | No | Owner cannot be assigned or changed here. Only owners manage administrators. |
expires_at | string | No | Timestamp |
accepted | boolean | No | Already accepted |
workspace | object | No |
curl --request POST \
--url 'https://app.drykraft.com/api/auth/invitations/preview' \
--header 'Content-Type: application/json' \
--data '{
"token": "<value>"
}'/api/auth/invitations/acceptAccept invitation
Access: Public · Success: 200
Checks invited account password, available billing seat and inviter authority. New account needs name. Sets a session directly in the invited workspace.
JSON request
| Field | Type | Required | Details |
|---|---|---|---|
token | string | Yes | Pattern: ^[a-f0-9]{64}$. |
password | string | Yes | Max 128 characters. |
mode | login | signup | Yes | Account choice |
name | string | No | New account name Max 100 characters. |
Response
Use OK.
curl --request POST \
--url 'https://app.drykraft.com/api/auth/invitations/accept' \
--header 'Content-Type: application/json' \
--data '{
"token": "<value>",
"password": "<value>",
"mode": "login"
}'/api/settings/membersList workspace members
Access: Workspace member · Success: 200
25 members per page, ordered by email. Pass next_cursor unchanged.
Query parameters
| Parameter | Type | Required | Details |
|---|---|---|---|
cursor | No | Optional next_cursor email Max 200 characters. |
No request body is required.
Response
| Field | Type | Required | Details |
|---|---|---|---|
items | object[] | No | |
total | integer | No | Total |
next_cursor | string or null | No |
curl --request GET \
--url 'https://app.drykraft.com/api/settings/members' \
--cookie 'drykraft_session=<YOUR_SESSION_TOKEN>'/api/settings/members/{id}Change member role
Access: Owner or admin · Success: 200
Owner is protected; admins cannot manage another administrator or grant admin. Refresh on stale version.
JSON request
| Field | Type | Required | Details |
|---|---|---|---|
role | admin | member | viewer | Yes | Owner cannot be assigned or changed here. Only owners manage administrators. |
version | integer | Yes | Positive optimistic version returned by the latest read. Refresh on 409; do not overwrite stale changes. Min 1. |
Response
Use OK.
curl --request PUT \
--url 'https://app.drykraft.com/api/settings/members/00000000-0000-4000-8000-000000000001' \
--cookie 'drykraft_session=<YOUR_SESSION_TOKEN>' \
--header 'Content-Type: application/json' \
--data '{
"role": "admin",
"version": 1
}'/api/settings/members/{id}Remove member
Access: Owner or admin · Success: 200
Revokes this workspace’s sessions, keeps business records and revokes pending invitations sent by the member. Owner/admin protections apply. Available even after trial expiration.
Query parameters
| Parameter | Type | Required | Details |
|---|---|---|---|
version | integer | Yes | Required current member version Min 1. |
No request body is required.
Response
Use OK.
curl --request DELETE \
--url 'https://app.drykraft.com/api/settings/members/00000000-0000-4000-8000-000000000001?version=1' \
--cookie 'drykraft_session=<YOUR_SESSION_TOKEN>'/api/settings/invitationsList pending invitations
Access: Owner or admin · Success: 200
25 per page; includes expired, nonrevoked pending invitations with active flag.
Query parameters
| Parameter | Type | Required | Details |
|---|---|---|---|
cursor | uuid | No |
No request body is required.
Response
| Field | Type | Required | Details |
|---|---|---|---|
items | object[] | No | |
total | integer | No | Total |
next_cursor | string or null | No |
curl --request GET \
--url 'https://app.drykraft.com/api/settings/invitations' \
--cookie 'drykraft_session=<YOUR_SESSION_TOKEN>'/api/settings/invitationsCreate invitation link
Access: Owner or admin · Success: 201
Valid seven days; replacing the same email revokes the old link. Only owner grants admin. No invitation email is sent. Keep the one-time response token private.
JSON request
| Field | Type | Required | Details |
|---|---|---|---|
email | Yes | Max 200 characters. | |
role | admin | member | viewer | Yes | Owner cannot be assigned or changed here. Only owners manage administrators. |
Response
| Field | Type | Required | Details |
|---|---|---|---|
id | uuid | No | |
email | No | Max 200 characters. | |
role | admin | member | viewer | No | Owner cannot be assigned or changed here. Only owners manage administrators. |
expires_at | string | No | Timestamp |
token | string | No | Private invitation token |
curl --request POST \
--url 'https://app.drykraft.com/api/settings/invitations' \
--cookie 'drykraft_session=<YOUR_SESSION_TOKEN>' \
--header 'Content-Type: application/json' \
--data '{
"email": "person@example.com",
"role": "admin"
}'/api/settings/invitations/{id}Revoke invitation
Access: Owner or admin · Success: 200
Already accepted invitations return 409; use member access instead. Repeated revocation is safe.
No request body is required.
Response
Use OK.
curl --request DELETE \
--url 'https://app.drykraft.com/api/settings/invitations/00000000-0000-4000-8000-000000000001' \
--cookie 'drykraft_session=<YOUR_SESSION_TOKEN>'