v2
latestOpenAPI 3.1.02026-08-05267431678.1 KBteams
Invite Member
Invite a user to join a team.
Requires owner, admin, or billing role. Owner-role invitations are rejected; ownership can only be transferred to an existing team member. Supports pre-signup invites (invitee doesn't need an account yet).
Accepted risk (ENG-1281): AAL2 enforcement was intentionally removed (PR #3928) — users without MFA enrolled were being blocked from routine team operations. Inviting an attacker-controlled email as admin/billing is the cleanest L-A16 escalation path: the attacker accepts on their own AAL2 account and instantly has MANAGE_BILLING on the victim team. This risk is accepted per the design decision.
post/teams/{team_id}/invitations
Path parameters
team_idstring required
Request body
Response
Successful Response