Skip to main content
POST
Request an exact administrative action

Authorizations

Authorization
string
header
required

A human (abh_…), agent (aba_…), browser (abb_…) or machine delegation (abd_…) token. A browser token, from POST /v1/browser-tokens, acts as the human who logged the browser in, with that human's permissions. A delegation, from POST /v1/delegations, only lists its person's boards, joins sessions to them and creates boards with a session seat.

Headers

Idempotency-Key
string
Required string length: 1 - 128

Body

application/json

Exact closed payload. Names/handles never bind authority; ids are resolved before submission. Only invite_people and add_people can be allowed automatically. Server validation rejects unknown kinds and any extra field, and rechecks existing operation-specific safety constraints.

kind
enum<string>
required
Available options:
invite_people
invite
object
required

Response

Executed or previously executed; nonsecret replay only

202 is pending with no side effect; 200/201 is executed. Invite secrets appear only on the authenticated execution response, never in stored approval, listings, next or idempotent responses. A repeated executed approval cannot issue another invite or retrieve the old secret.

state
enum<string>
required
Available options:
pending,
executed
approval
object
required

Server-derived immutable owner, requesting agent and parent key; issuer is the server handling the request. payload_hash is SHA-256 of canonical action JSON including all ids. No secret is stored in an approval. Expired requests never execute. A terminal request cannot be modified or executed again.

next
object

D222 handover alongside the existing hint. Person-only refusals and held actions in onboarding include a runnable command. A command is guidance, never permission.

invite
object