Skip to content

js-bao-wss-client


js-bao-wss-client / InvitationsAPI

Interface: InvitationsAPI ​

Sub-API for app-level invitations and deferred grants.

Methods ​

accept() ​

accept(inviteToken): Promise<AcceptInviteResult>

Accept an invitation via its invite token.

For authenticated users whose session already exists (e.g. they signed up with a different email than the invited one, or were invited after signup). The server marks the invitation accepted (write-once) and binds all pending deferred grants linked to it to the caller's userId.

Throws on any invite-token failure (invalid / expired / already-accepted) with AUTH_CODES.INVITE_TOKEN_INVALID. The server returns a uniform 401 + INVITE_TOKEN_INVALID for all failure modes rather than distinct codes, so the response does not reveal whether an underlying invitation exists.

Parameters ​

inviteToken ​

string

The invitation token from the accept URL

Returns ​

Promise<AcceptInviteResult>


create() ​

create(params): Promise<AppInvitationInfo>

Create an app-level invitation. Members can create invitations when memberInvitationsEnabled is true. Admins/owners can always create invitations.

Parameters ​

params ​

CreateInvitationParams

Invitation details

Returns ​

Promise<AppInvitationInfo>


delete() ​

delete(invitationId): Promise<{ message: string; success: boolean; }>

Delete (revoke) an app-level invitation.

Admins and owners can revoke any invitation. A member can revoke only invitations they created themselves (403 otherwise). Revoking an active invitation frees the member's quota. Also cascade-deletes any linked deferred grants.

Parameters ​

invitationId ​

string

The invitation to delete

Returns ​

Promise<{ message: string; success: boolean; }>


get() ​

get(invitationId): Promise<AppInvitationInfo>

Fetch a single app invitation by id.

Returns the full invitation envelope, including inviteToken so callers can build their own accept-page CTA (e.g. ${baseUrl}/invite/accept?inviteToken=…). The platform does not compose accept URLs because apps own their own accept-page routing.

Permissions: app admin/owner, OR the invitation's original inviter. Members who did not create the invitation receive 403 — inviteToken is a bearer credential, so read access is intentionally narrow.

Legacy invitations with no token are lazily upgraded on first read.

Parameters ​

invitationId ​

string

The invitation to look up

Returns ​

Promise<AppInvitationInfo>


list() ​

list(options?): Promise<InvitationListResult>

List app-level invitations.

Admins and owners see the full app list. Members see only the invitations they created themselves — the memberInvitationsEnabled flag gates creating invitations, not listing your own (a member can always see and revoke invitations they already sent). A member with no invitations of their own gets an empty list, not a 403.

Parameters ​

options? ​

InvitationListOptions

Pagination options

Returns ​

Promise<InvitationListResult>


listDeferredGrants() ​

listDeferredGrants(options?): Promise<DeferredGrantListResult>

List pending deferred grants (admin/owner only). Deferred grants are permissions/memberships created for users who haven't signed up yet.

Parameters ​

options? ​

DeferredGrantListOptions

Filter and pagination options

Returns ​

Promise<DeferredGrantListResult>


quota() ​

quota(): Promise<InvitationQuota>

Check the current user's invitation quota. Admins/owners always get unlimited: true.

Returns ​

Promise<InvitationQuota>


revokeDeferredGrant() ​

revokeDeferredGrant(deferredId, type): Promise<DeferredGrantRevokeResult>

Revoke a deferred grant. Admins/owners can revoke any; the original granter can revoke their own.

Parameters ​

deferredId ​

string

The deferred grant to revoke

type ​

"group" | "document"

Whether this is a "document" or "group" deferred grant

Returns ​

Promise<DeferredGrantRevokeResult>

Documentation validated against js-bao-wss-client 3.4.0 · js-bao 0.11.0 · primitive-admin 1.0.62 · primitive-app 3.1.0 — 2026-09-30