accountants.inviteMany
Invite up to 10 people from one accounting firm in one go. Each person has their own email, name, access level (preset) and end date; the firm name and message are shared. Returns which invitations were sent and which failed, each with its private join link. Administrator access is required. MCP calls also require accounting:admin; the web agent asks for approval before changing outside access. Direct API requests cannot perform these access-granting actions.
/api/v1/accounting/accountants.inviteManyPermissions
Who can call it
Retries
MCP
accounting_accountants_invite_manyReaches outside Oatmilk
Fields
firmstringat most 200 characters
messagestringat most 2000 characters
peoplearray of objectsRequired1–10 items
idempotencyKeystringRequiredAny unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.
8–150 characters
Example
curl https://app.getoatmilk.com/api/v1/accounting/accountants.inviteMany \
-H "Authorization: Bearer $OATMILK_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{
"people": [
{
"email": "finance@example.com",
"accessExpiresOn": "2026-09-30"
}
]
}'{
"data": { … }
}Try it
Try it
Checks your input with this action’s real schema and answers like the API, with synthetic data. No key needed, and nothing changes.
curl https://app.getoatmilk.com/api/v1/accounting/accountants.inviteMany \
-H "Authorization: Bearer $OATMILK_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $(uuidgen)" \
-d '{
"people": [
{
"email": "finance@example.com",
"accessExpiresOn": "2026-09-30"
}
]
}'More in Administration.