Skip to main content
Revoke Invite
Marks a pending invitation revoked. Requires the invite capability (or owner). Fires workspace.invite.revoked.

Path Parameters

string
required
The workspace UUID.
string
required
The invitation UUID.

Body Parameters

string
Service/master keys only — the user to act as. Enforced: the invite capability (or ownership) is required of the named user. Omit it to act as the app itself (unbounded). See Acting on behalf of a user.

Response

Error Responses

Every path id on the workspaces bundle is checked for UUID shape before the route runs, so a malformed one is a plain 400 rather than a 500 from the database.
Every workspaces endpoint declares its fields exactly, and a top-level field it does not declare is refused rather than ignored — in the request body and in the query string alike, for every caller. Two or more at once are named together: Unrecognized keys: "onBehalfOf", "impersonate". An offender in the query string carries workspace/invalid-query instead. Send only the fields documented above, plus actingUserId and projectId, which every workspaces route accepts. See Shapes the server rejects.
Returned when a service/master key sends a body with a Content-Type other than application/json and no actingUserId was read. Sublay parses only application/json, so the actor inside such a body is discarded and the request would fall through to the unbounded path. fetch() sends text/plain;charset=UTF-8 when you pass a stringified body and set no headers — set the header. An empty JSON body and a bodiless request both pass. See Shapes the server rejects.