---
title: "Revoke invitation link"
method: POST
path: "/customers/invitation-links/{linkId}/revoke"
tags: ["Invitation Links"]
---

# Revoke invitation link

`POST /customers/invitation-links/{linkId}/revoke`

Revoke an invitation link so it stops connecting new customers

## Path parameters

- `linkId` string, required — Invitation link ID (ivl_*).

## Headers

- `X-Instance-ID` string, nullable

## Response `200`

Successful Response

- object
  - `data` object, required
    - `type` 'invitationLink', required — Resource type. Always `invitationLink`.
    - `id` string, required — Invitation link ID (ivl_*).
    - `attributes` object, required
      - `proposedAgents` object[], required — Agents offered to customers who open this link.
        - `agentId` string, required — Agent ID (agt_*).
        - `permissions` string[], required — Permissions granted to this agent when a customer approves.
        - `limits` object, nullable, required — Transaction limits
      - `status` 'ACTIVE' | 'REVOKED', required — Link status.
      - `createdAt` string, required — RFC 3339 timestamp when this link was created.
      - `name` string, required — Label for this link.
      - `expiresAt` string, nullable, required — RFC 3339 timestamp when this link stops accepting new customers, or null when it never expires.
      - `tags` object, required — Metadata visible to anyone who can read the resource.
      - `maskedToken` string, required — Link token with all but the last 4 characters masked (for example ***bc4d). The full token and URL are returned only when the link is created.
    - `relationships` object, required
      - `delegateeParty` object, required — Party that created this link.
        - `data` object, nullable, required — Related resource identifier.
          - `type` 'party', required — Resource type. Always `party`.
          - `id` string, required

## Other responses

- `400` — Validation Error
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found. Returned when the resource does not exist, or when it exists but is not accessible to your account. The two cases are intentionally indistinguishable, so that resource IDs cannot be enumerated by probing.
- `409` — Conflict
- `422` — Validation Error. The response contains one error object for each invalid request value.
- `428` — Precondition Required
- `429` — Too Many Requests
- `500` — Internal Server Error
- `501` — Not Implemented
- `502` — Bad Gateway
- `503` — Service Unavailable

## Changes

- **2026-09-05** `1197c1fb1ef2` — 1 warning
  - added the new `payment_intents.create` enum value to the `data/attributes/proposedAgents/items/permissions/items/` response property for the response status `200`
- **2026-09-02** `c7c12da5915f` — 12 info
  - added the optional property `errors/items/meta/limitScope` to the response with the `400` status
  - added the optional property `errors/items/meta/limitScope` to the response with the `401` status
  - added the optional property `errors/items/meta/limitScope` to the response with the `403` status
  - added the optional property `errors/items/meta/limitScope` to the response with the `404` status
  - …8 more
- **2026-08-27** `359d267dca88` — 1 info
  - deleted the `header` request parameter `X-Agent-ID` with deprecation
- **2026-08-23** `b1ad79e918ac` — 1 warning, 1 info
  - added the new `wallets.balance` enum value to the `data/attributes/proposedAgents/items/permissions/items/` response property for the response status `200`
  - `header` request parameter `X-Agent-ID` was deprecated
- …earlier changes not shown

[Full history](https://skmtc.dev/natural/apis/natural-api/changes/customers/invitation-links/:linkId/revoke/post.md)

---

[API](https://skmtc.dev/natural/apis/natural-api.md) · [All operations](https://skmtc.dev/natural/apis/natural-api/llms.txt) · [OpenAPI document](https://skmtc.dev/natural/apis/natural-api/revisions/a7210001d0d4?raw)
