Invite teammates, preview invitation links, and revoke pending invites. Owners and organization admins manage the roster; members work inside the permissions of their role.

Roles are owner (full access), admin (team and settings), and member (day-to-day messaging, inbox, and campaigns). Seat limits follow your plan and team-seat add-ons.

Roles and seats

The account owner is created at signup and cannot be invited. Admins can invite members and other admins, revoke pending invites, and manage workspace settings. Members can operate WhatsApp sessions, inbox, contacts, and campaigns according to RBAC permissions — they cannot invite users.

  • Invite by email. The recipient gets a branded email with an accept link.
  • Invites expire after several days; revoke unused invites from GET /api/team.
  • The invitee sets their password on accept and is logged in immediately.
  • Remove an accepted member with DELETE /api/team/members/{id} to revoke access immediately.

Preview and accept endpoints are public (token in the query or body). Listing and inviting require a JWT from an owner or admin.

GET/api/team

List team

Members and pending invitations for the workspace.

URL: https://api.actiwapi.com/api/team

Auth: JWT Bearer

Headers

HeaderValueRequired
AuthorizationBearer {accessToken}Yes
Content-Typeapplication/jsonYes*

Code examples

curl -X GET "https://api.actiwapi.com/api/team" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer {accessToken}"

Response example200

{
  "success": true,
  "data": {
    "members": [{ "id": "uuid", "email": "ops@acme.com", "name": "Ops", "role": "member" }],
    "invites": [{ "id": "uuid", "email": "new@acme.com", "role": "member", "expiresAt": "2026-09-10T00:00:00.000Z" }]
  }
}

Try in Swagger UI

POST/api/team/invite

Invite a member

Send an invitation email. Role is admin or member (default member).

URL: https://api.actiwapi.com/api/team/invite

Auth: JWT Bearer

Headers

HeaderValueRequired
AuthorizationBearer {accessToken}Yes
Content-Typeapplication/jsonYes*

Request example

{
  "email": "new@acme.com",
  "role": "member"
}

Code examples

curl -X POST "https://api.actiwapi.com/api/team/invite" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer {accessToken}"
  -d '{  "email": "new@acme.com",  "role": "member"}'

Response example201

{
  "success": true,
  "data": { "id": "uuid", "email": "new@acme.com", "role": "member" }
}

Try in Swagger UI

DELETE/api/team/invite/{id}

Revoke invitation

Cancel a pending invite so the token can no longer be accepted.

URL: https://api.actiwapi.com/api/team/invite/{id}

Auth: JWT Bearer

Headers

HeaderValueRequired
AuthorizationBearer {accessToken}Yes
Content-Typeapplication/jsonYes*

Path parameters

  • id — Invitation UUID

Code examples

curl -X DELETE "https://api.actiwapi.com/api/team/invite/{id}" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer {accessToken}"

Response example200

{ "success": true, "data": { "id": "uuid", "revoked": true } }

Try in Swagger UI

DELETE/api/team/members/{id}

Remove team member

Soft-remove an accepted member, revoke their sessions, and free the email for re-invite. Organization admins/owners cannot be removed here.

URL: https://api.actiwapi.com/api/team/members/{id}

Auth: JWT Bearer

Headers

HeaderValueRequired
AuthorizationBearer {accessToken}Yes
Content-Typeapplication/jsonYes*

Path parameters

  • id — Member user UUID

Code examples

curl -X DELETE "https://api.actiwapi.com/api/team/members/{id}" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer {accessToken}"

Response example200

{ "success": true, "data": { "id": "uuid", "removed": true } }

Try in Swagger UI

GET/api/team/invite/preview

Preview invitation

Public: show workspace name and role for an invite token (used on the accept page).

URL: https://api.actiwapi.com/api/team/invite/preview

Auth: None

Query parameters

  • token (required) — Raw invite token from the email link

Code examples

curl -X GET "https://api.actiwapi.com/api/team/invite/preview" \
  -H "Content-Type: application/json"

Response example200

{
  "success": true,
  "data": { "email": "new@acme.com", "role": "member", "tenantName": "Acme Corp" }
}

Try in Swagger UI

POST/api/team/invite/accept

Accept invitation

Public: create the user account, then return JWT tokens as if they logged in.

URL: https://api.actiwapi.com/api/team/invite/accept

Auth: None

Request example

{
  "token": "hex-token-from-email",
  "name": "Alex Kumar",
  "password": "SecurePass123!"
}

Code examples

curl -X POST "https://api.actiwapi.com/api/team/invite/accept" \
  -H "Content-Type: application/json"
  -d '{  "token": "hex-token-from-email",  "name": "Alex Kumar",  "password": "SecurePass123!"}'

Response example200

{
  "success": true,
  "data": {
    "accessToken": "eyJhbG...",
    "refreshToken": "eyJhbG...",
    "user": { "email": "new@acme.com", "role": "member" }
  }
}

Try in Swagger UI

Error codes

Failed requests return a JSON envelope with success: false and a human-readable message.

{
  "success": false,
  "message": "Validation failed",
  "errors": {
    "phone": "Valid phone number is required"
  }
}
HTTPCodeDescription
400VALIDATION_ERRORRequest body or query failed validation.
401UNAUTHORIZEDMissing or invalid JWT / API key.
403FORBIDDENAuthenticated but lacking permission or entitlement.
403SUBSCRIPTION_INACTIVEAction not allowed on the current plan (including Free after trial). Upgrade or wait for entitlements.
403LIMIT_EXCEEDEDPlan limit reached (sessions, messages, API requests, etc.).
404NOT_FOUNDResource does not exist or is not in your account.
409CONFLICTDuplicate resource or invalid state transition.
429RATE_LIMITEDToo many requests; retry after backoff.
500INTERNAL_ERRORUnexpected server error.
502WHATSAPP_UNAVAILABLEWhatsApp session disconnected or provider error.