---
title: "Create invitation link"
method: POST
path: "/customers/invitation-links"
tags: ["Invitation Links"]
---

# Create invitation link

`POST /customers/invitation-links`

Create a shareable link offering your agents, with the permissions and limits you set, to any customer who opens it

## Headers

- `X-Agent-ID` string, nullable
- `X-Instance-ID` string, nullable

## Request body

- object
  - `data` object, required
    - `attributes` object, required
      - `proposedAgents` object[], required — Agents to propose for authorization (required)
        - `agentId` string, required — Agent ID (agt_*)
        - `permissions` string[], required — Permissions for this agent
        - `limits` object — Limits (e.g., {perTransaction: 50000})
          - `perTransaction` integer, nullable — Positive per-transaction limit in cents. Null means no per-transaction limit.
      - `expiresAt` string, date-time — When the link stops accepting new approvals. Omit for a link that never expires.
      - `name` string, required — Label for this link

## Response `201`

Successful Response

- object
  - `data` object, required
    - `type` 'invitationLink', required — Resource type
    - `id` string, required — Link ID (ivl_*)
    - `attributes` object, required — Resource attributes
      - `proposedAgents` object[], required — Agents proposed for authorization
        - `agentId` string, required — Agent ID (agt_*)
        - `permissions` string[], required — Permissions for this agent
        - `limits` object, nullable, required — Transaction limits
      - `status` 'ACTIVE' | 'REVOKED', required — Link status
      - `createdAt` string, required — When this link was created
      - `name` string, required — Label for this link
      - `expiresAt` string, nullable, required — When this link expires
      - `token` string, required — Plaintext link token. Returned only when the link is created; list and get return a masked form
      - `url` string, required — Full shareable URL for this link. Returned only when the link is created
    - `relationships` object, required — Resource relationships
      - `delegateeParty` object, required — Developer party that created this link
        - `data` object, nullable, required — Related resource identifier.
          - `type` 'party', required
          - `id` string, required

## Other responses

- `400` — Validation Error
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found. Returned when the resource does not exist, or when it exists but is not accessible to your account. The two cases are intentionally indistinguishable, so that resource IDs cannot be enumerated by probing.
- `409` — Conflict
- `422` — Validation Error
- `428` — Precondition Required
- `429` — Too Many Requests
- `500` — Internal Server Error
- `501` — Not Implemented
- `502` — Bad Gateway
- `503` — Service Unavailable

---

[API](https://skmtc.net/natural/apis/natural-api.md) · [All operations](https://skmtc.net/natural/apis/natural-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/natural/natural-api/versions/0123533d8361/schema)
