Administration

team.invitations.revoke

Cancel a pending team invitation so its link stops working, with source (oatmilk, or clerk for an invitation sent before Oatmilk sent its own), id, expectedRevision for an Oatmilk invitation, and idempotencyKey. Only organization administrators can manage the team. MCP calls also require the accounting:admin scope; the direct API cannot send team invitations or remove members.

POST/api/v1/accounting/team.invitations.revoke

Permissions

accounting:readaccounting:writeaccounting:admin

Who can call it

admin

Retries

Idempotency key required, with expectedRevision

MCP

accounting_team_invitations_revoke

Can't be undone

It deletes, voids, revokes or discards something. Confirm with a person first.

Fields

Shape 1: source: "oatmilk"

  • source"oatmilk"Required

    Where the record came from.

  • idstring (ID)Required

    The record's ID.

  • expectedRevisionintegerRequired

    The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again.

    at most 9007199254740991 · greater than 0

  • idempotencyKeystringRequired

    Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.

    8–200 characters

Shape 2: source: "clerk"

  • source"clerk"Required

    Where the record came from.

  • idstringRequired

    The record's ID.

    Matches ^orginv_[A-Za-z0-9]{8,64}$

  • idempotencyKeystringRequired

    Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.

    8–200 characters

Example

curl https://app.getoatmilk.com/api/v1/accounting/team.invitations.revoke \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "source": "oatmilk",
  "id": "9a8b7c6d-5e4f-4a3b-8c2d-1e0f9a8b7c6d",
  "expectedRevision": 3
}'
Response
{
  "data": { … }
}

Try it

Try it

Checks your input with this action’s real schema and answers like the API, with synthetic data. No key needed, and nothing changes.

POST/api/v1/accounting/team.invitations.revoke
curl https://app.getoatmilk.com/api/v1/accounting/team.invitations.revoke \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "source": "oatmilk",
  "id": "9a8b7c6d-5e4f-4a3b-8c2d-1e0f9a8b7c6d",
  "expectedRevision": 3
}'

More in Administration.