---
title: "Create an Invitation"
method: POST
path: "/iam/v2/invitations"
tags: ["Invitations (iam/v2)"]
---

# Create an Invitation

`POST /iam/v2/invitations`

[![General Availability](https://img.shields.io/badge/Lifecycle%20Stage-General%20Availability-%2345c6e8)](#section/Versioning/API-Lifecycle-Policy)

Make a request to create an invitation.

The newly invited user will not have any permissions. Give the user permission by assigning them to one or
more roles by creating
[role bindings](https://docs.confluent.io/cloud/current/api.html#tag/Role-Bindings-(iamv2))
for the created `user`.

## Request body

- object — `Invitation` objects represent invitations to invite users to join your organizations in Confluent Cloud. The API allows you to list all your invitations, as well as create, read, and delete a specified invitation. Related guide: [User invitations in Confluent Cloud](https://docs.confluent.io/cloud/current/access-management/identity/user-accounts.html). ## The Invitations Model <SchemaDefinition schemaRef="#/components/schemas/iam.v2.Invitation" /> ## Quotas and Limits This resource is subject to the [following quotas](https://docs.confluent.io/cloud/current/quotas/overview.html): | Quota | Description | | --- | --- | | `invitations_per_org` | Invitations in a Confluent Cloud organization |
  - `api_version` 'iam/v2' — APIVersion defines the schema version of this representation of a resource.
  - `kind` 'Invitation' — Kind defines the object this REST resource represents.
  - `id` string — ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space").
  - `metadata` object — ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create.
    - `self` string, uri, required — Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time
    - `resource_name` string, uri — Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name
    - `created_at` string, date-time — The date and time at which this object was created. It is represented in RFC3339 format and is in UTC.
    - `updated_at` string, date-time — The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC.
    - `deleted_at` string, date-time — The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC.
  - `email` string, email, required — The user/invitee's email address
  - `auth_type` string — The user/invitee's authentication type. Note that only the [OrganizationAdmin role](https://docs.confluent.io/cloud/current/access-management/access-control/cloud-rbac.html#organizationadmin) can invite AUTH_TYPE_LOCAL users to SSO organizations. The user's auth_type is set as AUTH_TYPE_SSO by default if the organization has SSO enabled. Otherwise, the user's auth_type is AUTH_TYPE_LOCAL by default.
  - `status` string — The status of invitations
  - `accepted_at` string, date-time, nullable — The timestamp that the invitation was accepted
  - `expires_at` string, date-time — The timestamp that the invitation will expire
  - `user` GlobalObjectReference — ObjectReference provides information for you to locate the referred object
    - `id` string, required — ID of the referred resource
    - `related` string, uri, required — API URL for accessing or modifying the referred object
    - `resource_name` string, uri, required — CRN reference to the referred resource
  - `creator` GlobalObjectReference — ObjectReference provides information for you to locate the referred object
    - `id` string, required — ID of the referred resource
    - `related` string, uri, required — API URL for accessing or modifying the referred object
    - `resource_name` string, uri, required — CRN reference to the referred resource

## Response `201`

An Invitation was created.

- object — `Invitation` objects represent invitations to invite users to join your organizations in Confluent Cloud. The API allows you to list all your invitations, as well as create, read, and delete a specified invitation. Related guide: [User invitations in Confluent Cloud](https://docs.confluent.io/cloud/current/access-management/identity/user-accounts.html). ## The Invitations Model <SchemaDefinition schemaRef="#/components/schemas/iam.v2.Invitation" /> ## Quotas and Limits This resource is subject to the [following quotas](https://docs.confluent.io/cloud/current/quotas/overview.html): | Quota | Description | | --- | --- | | `invitations_per_org` | Invitations in a Confluent Cloud organization |
  - `api_version` 'iam/v2' — APIVersion defines the schema version of this representation of a resource.
  - `kind` 'Invitation' — Kind defines the object this REST resource represents.
  - `id` string — ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space").
  - `metadata` object — ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create.
    - `self` string, uri, required — Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time
    - `resource_name` string, uri — Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name
    - `created_at` string, date-time — The date and time at which this object was created. It is represented in RFC3339 format and is in UTC.
    - `updated_at` string, date-time — The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC.
    - `deleted_at` string, date-time — The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC.
  - `email` string, email, required — The user/invitee's email address
  - `auth_type` string — The user/invitee's authentication type. Note that only the [OrganizationAdmin role](https://docs.confluent.io/cloud/current/access-management/access-control/cloud-rbac.html#organizationadmin) can invite AUTH_TYPE_LOCAL users to SSO organizations. The user's auth_type is set as AUTH_TYPE_SSO by default if the organization has SSO enabled. Otherwise, the user's auth_type is AUTH_TYPE_LOCAL by default.
  - `status` string — The status of invitations
  - `accepted_at` string, date-time, nullable — The timestamp that the invitation was accepted
  - `expires_at` string, date-time — The timestamp that the invitation will expire
  - `user` GlobalObjectReference — ObjectReference provides information for you to locate the referred object
    - `id` string, required — ID of the referred resource
    - `related` string, uri, required — API URL for accessing or modifying the referred object
    - `resource_name` string, uri, required — CRN reference to the referred resource
  - `creator` GlobalObjectReference — ObjectReference provides information for you to locate the referred object
    - `id` string, required — ID of the referred resource
    - `related` string, uri, required — API URL for accessing or modifying the referred object
    - `resource_name` string, uri, required — CRN reference to the referred resource

## Other responses

- `400` — Bad Request
- `401` — The request lacks valid authentication credentials for this resource.
- `402` — The request would exceed one or more quotas.
- `403` — The access credentials were considered insufficient to grant access
- `409` — The request is in conflict with the current server state
- `422` — Validation Failed
- `429` — Rate Limit Exceeded
- `500` — Oops, something went wrong!

---

[API](https://skmtc.dev/confluent/apis/confluent-cloud-apis.md) · [All operations](https://skmtc.dev/confluent/apis/confluent-cloud-apis/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/confluent/confluent-cloud-apis/revisions/a6a73f98a698/schema)
