neosourceDocs
Search docs

List pending invites

GET/api/orgs/{org}/invites

listOrgInvites

Admins+ only. Tokens are never returned here — only invite metadata.

Requires authentication using a bearer token or a session cookie — see tokens and scopes.

curl

curl -X GET 'https://neosource.dev/api/orgs/ORG/invites' \
  -H 'Authorization: Bearer $NEOSOURCE_TOKEN'

fetch

fetch("https://neosource.dev/api/orgs/ORG/invites", {
  method: "GET",
  headers: {
    Authorization: "Bearer $NEOSOURCE_TOKEN",
  },
});

Path parameters

orgrequired

Organization slug.

string

Responses

200Pending invites

application/json

OrgInviteListResponse

object

invitesrequired

array

items

OrgInviteResponse

object

created_atrequired

integerint64

created_byrequired

string

emailrequired

string

expires_atrequired

integerint64

invite_idrequired

string

org_slugrequired

string

Org slug (so the SPA doesn't need a second lookup to render).

rolerequired
WorkspaceRole
token

string | null

Present only on `createOrgInvite` — the bearer the inviter passes to the recipient. Subsequent reads omit it.

workspace_idrequired

string

403Forbidden — one of: forbidden, needs_scope

application/json

one of
  • ErrorForbidden
  • NeedsScopeError

    object

    `403` body returned when listing private repos but the linked identity lacks the required provider scope. The SPA turns this into an incremental-authorization prompt (Tier 2) that calls the `/elevate` OAuth endpoint with this `scope`.

    errorrequired

    string

    Always `needs_scope` — this body exists to carry the extra fields that kind needs.

    "needs_scope"

    scoperequired

    string

    The provider scope to request via elevation (e.g. `"repo"`).

Standard errors

Bodies documented once for the whole API — see standard errors.

  • 400Bad Request — one of: invalid_input
  • 401Authentication required
  • 404Not Found — one of: not_found
  • 429Rate limited — retry after the `Retry-After` header
  • 500Internal server error
  • 503Service temporarily unavailable / at capacity — retry after the `Retry-After` header
  • 504Gateway timeout — the request exceeded the server's handling budget

Schemas

Referenced above. Listed here rather than expanded inline, so the same definition is not repeated at every level.

WorkspaceRole

string

Workspace membership role. Ordered low → high (`Member < Admin < Owner`) so that `if actor_role >= WorkspaceRole::Admin` reads naturally.

"member""admin""owner"