Skip to main content
POST
Invite a member

Authorizations

Authorization
string
header
default:sk_test_DEMO0000_replace_with_your_sandbox_key
required

API key authentication. Issued by the Safariat admin or via the partner portal. The secret is shown only once at generation.

Production sk_live_* keys must additionally sign every write request (POST/PUT/DELETE) with the X-Timestamp and X-Signature headers. Sandbox sk_test_* keys are exempt from request signing: X-Signature and X-Timestamp are not required for writes in the sandbox (so the developer-portal "Try it" playground works end to end). The Idempotency-Key header remains required on writes in both environments.

Headers

Idempotency-Key
string
required

Opaque, client-generated string unique per logical operation (a UUID v4 is recommended but any non-blank value up to 255 chars is accepted). Same key + same body = the cached response is returned with the Idempotent-Replayed: true header. Same key + different body = 409 Conflict. Retained for 24 h.

Maximum string length: 255
X-Timestamp
integer<int64>
required

Unix timestamp in seconds at the time the request is issued. Validity window ±5 minutes — beyond that the request is rejected. Required for production sk_live_* keys only; not required for sandbox sk_test_* keys.

X-Signature
string
required

hex(HMAC_SHA256(secret, "{X-Timestamp}\n{METHOD}\n{path}\n{body}")). The path includes the query string. The body is the exact JSON representation sent — any reformatting invalidates the signature. Required for production sk_live_* keys only; not required for sandbox sk_test_* keys.

Pattern: ^[a-f0-9]{64}$

Body

application/json
email
string<email>
required
Maximum string length: 200
first_name
string
required
Maximum string length: 50
last_name
string
required
Maximum string length: 50
role
enum<string>
required

Console role (an actual Keycloak realm role). PARTNER_ADMIN = full access (manages team + API keys); FINANCE = settlements + bookings; DEVELOPER = catalog/quotes/bookings/webhooks/audit; VIEWER = read-only.

Available options:
PARTNER_ADMIN,
FINANCE,
DEVELOPER,
VIEWER

Response

Member invited

id
string<uuid>
required

Keycloak user identifier.

email
string<email>
required
role
enum<string>
required

Console role (an actual Keycloak realm role). PARTNER_ADMIN = full access (manages team + API keys); FINANCE = settlements + bookings; DEVELOPER = catalog/quotes/bookings/webhooks/audit; VIEWER = read-only.

Available options:
PARTNER_ADMIN,
FINANCE,
DEVELOPER,
VIEWER
enabled
boolean
required

Active account (false = disabled).

is_you
boolean
required

true if this is the member authenticated on the current request.

first_name
string | null
last_name
string | null
created_at
string<date-time> | null