---
title: "Create invitation link"
method: POST
path: "/customers/invitation-links"
tags: ["Invitation Links"]
---

# Create invitation link

`POST /customers/invitation-links`

Create a shareable link offering your agents, with the permissions and limits you set, to any customer who opens it

## Headers

- `X-Instance-ID` string, nullable

## Request body

- object
  - `data` object, required
    - `attributes` object, required
      - `proposedAgents` object[], required — Agents to propose for authorization (required)
        - `agentId` string, required — Agent ID (agt_*)
        - `permissions` string[], required — Permissions for this agent
        - `limits` object — Limits (e.g., {perTransaction: 50000})
          - `perTransaction` integer, nullable — Positive per-transaction limit in cents. Null means no per-transaction limit.
      - `expiresAt` string, date-time — When the link stops accepting new approvals. Omit for a link that never expires.
      - `name` string, required — Label for this link
      - `tags` object

## Response `201`

Successful Response

- object
  - `data` object, required
    - `type` 'invitationLink', required — Resource type
    - `id` string, required — Link ID (ivl_*)
    - `attributes` object, required — Resource attributes
      - `proposedAgents` object[], required — Agents proposed for authorization
        - `agentId` string, required — Agent ID (agt_*)
        - `permissions` string[], required — Permissions for this agent
        - `limits` object, nullable, required — Transaction limits
      - `status` 'ACTIVE' | 'REVOKED', required — Link status
      - `createdAt` string, required — When this link was created
      - `name` string, required — Label for this link
      - `expiresAt` string, nullable, required — When this link expires
      - `tags` object, required — Metadata visible to anyone who can read the resource.
      - `token` string, required — Plaintext link token. Returned only when the link is created; list and get return a masked form
      - `url` string, required — Full shareable URL for this link. Returned only when the link is created
    - `relationships` object, required — Resource relationships
      - `delegateeParty` object, required — Developer party that created this link
        - `data` object, nullable, required — Related resource identifier.
          - `type` 'party', required
          - `id` string, required

## Other responses

- `400` — Validation Error
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found. Returned when the resource does not exist, or when it exists but is not accessible to your account. The two cases are intentionally indistinguishable, so that resource IDs cannot be enumerated by probing.
- `409` — Conflict
- `422` — Validation Error. The response contains one error object for each invalid request value.
- `428` — Precondition Required
- `429` — Too Many Requests
- `500` — Internal Server Error
- `501` — Not Implemented
- `502` — Bad Gateway
- `503` — Service Unavailable

## Changes

- **2026-09-05** `1197c1fb1ef2` — 1 warning, 1 info
  - added the new `payment_intents.create` enum value to the `data/attributes/proposedAgents/items/permissions/items/` response property for the response status `201`
  - added the new `payment_intents.create` enum value to the request property `data/attributes/proposedAgents/items/permissions/items/`
- **2026-09-02** `c7c12da5915f` — 12 info
  - added the optional property `errors/items/meta/limitScope` to the response with the `400` status
  - added the optional property `errors/items/meta/limitScope` to the response with the `401` status
  - added the optional property `errors/items/meta/limitScope` to the response with the `403` status
  - added the optional property `errors/items/meta/limitScope` to the response with the `404` status
  - …8 more
- **2026-08-27** `359d267dca88` — 1 info
  - deleted the `header` request parameter `X-Agent-ID` with deprecation
- **2026-08-23** `b1ad79e918ac` — 1 warning, 2 info
  - added the new `wallets.balance` enum value to the `data/attributes/proposedAgents/items/permissions/items/` response property for the response status `201`
  - `header` request parameter `X-Agent-ID` was deprecated
  - added the new `wallets.balance` enum value to the request property `data/attributes/proposedAgents/items/permissions/items/`
- …earlier changes not shown

[Full history](https://skmtc.dev/natural/apis/natural-api/changes/customers/invitation-links/post.md)

---

[API](https://skmtc.dev/natural/apis/natural-api.md) · [All operations](https://skmtc.dev/natural/apis/natural-api/llms.txt) · [OpenAPI document](https://skmtc.dev/natural/apis/natural-api/revisions/1197c1fb1ef2?raw)
