> ## Documentation Index
> Fetch the complete documentation index at: https://docs.glot.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create an invite link

> Mint a link that lets someone without an account join this room.

The way a guest gets in. Everyone else needs a token from
`POST /v1/rooms/{room_name}/token`, which only an authenticated member of your
organization can request — this hands out a single-purpose capability instead, so a
guest-facing page never needs your credentials. Send the code to your guest in a link
to your own page; that page reads the room with `GET /v1/invites/{invite_code}` and
joins through `POST /v1/invites/{invite_code}/join`.

**The code is returned once, here.** Only a hash of it is stored, so no endpoint can
read it back. Lose it and you revoke the link and mint another.

**Works in a room of either streaming mode, and minting neither sets nor changes it.**
What the mode decides is how many languages your guest sends when they join — one in a
`dual` room, two in a `mono` one, where a single device carries both speakers.
`GET /v1/invites/{invite_code}` reports that count as `languages_required`, so the page
you send them can render the right chooser. If the room has no mode yet, your guest's
join may be the token that settles it, exactly as `POST /v1/rooms/{room_name}/token`
would.

`expires_in_seconds` and `max_uses` are both required — together with revocation they
are the only things bounding a link once you have sent it, so they are yours to choose,
up to a ceiling of 30 days and 100 uses. A link is unusable the moment either runs out,
and returns 410 from then on.

Anything but a live room in your organization returns 404.



## OpenAPI

````yaml https://api.staging.glot.com/openapi.json post /v1/rooms/{room_id}/invites
openapi: 3.1.0
info:
  title: glot-api
  version: 0.1.0
servers:
  - url: https://api.staging.glot.com
security: []
tags:
  - name: rooms
    description: Create translation rooms and let participants join them.
  - name: invites
    description: Invite links that let a guest join a room without an account.
  - name: usage
    description: Minutes and charges over time, for reporting and charts.
  - name: billing
    description: Buy prepaid credit and review the balance behind it.
  - name: api-keys
    description: Create and revoke keys used to authenticate requests.
  - name: supported-languages
    description: Languages available for translation.
  - name: users
    description: The authenticated user's own profile.
paths:
  /v1/rooms/{room_id}/invites:
    post:
      tags:
        - invites
      summary: Create an invite link
      description: >-
        Mint a link that lets someone without an account join this room.


        The way a guest gets in. Everyone else needs a token from

        `POST /v1/rooms/{room_name}/token`, which only an authenticated member
        of your

        organization can request — this hands out a single-purpose capability
        instead, so a

        guest-facing page never needs your credentials. Send the code to your
        guest in a link

        to your own page; that page reads the room with `GET
        /v1/invites/{invite_code}` and

        joins through `POST /v1/invites/{invite_code}/join`.


        **The code is returned once, here.** Only a hash of it is stored, so no
        endpoint can

        read it back. Lose it and you revoke the link and mint another.


        **Works in a room of either streaming mode, and minting neither sets nor
        changes it.**

        What the mode decides is how many languages your guest sends when they
        join — one in a

        `dual` room, two in a `mono` one, where a single device carries both
        speakers.

        `GET /v1/invites/{invite_code}` reports that count as
        `languages_required`, so the page

        you send them can render the right chooser. If the room has no mode yet,
        your guest's

        join may be the token that settles it, exactly as `POST
        /v1/rooms/{room_name}/token`

        would.


        `expires_in_seconds` and `max_uses` are both required — together with
        revocation they

        are the only things bounding a link once you have sent it, so they are
        yours to choose,

        up to a ceiling of 30 days and 100 uses. A link is unusable the moment
        either runs out,

        and returns 410 from then on.


        Anything but a live room in your organization returns 404.
      operationId: create_room_invite_v1_rooms__room_id__invites_post
      parameters:
        - name: room_id
          in: path
          required: true
          schema:
            type: string
            format: uuid
            title: Room Id
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateRoomInviteRequest'
      responses:
        '201':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RoomInviteCreatedResponse'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
      security:
        - HTTPBearer: []
components:
  schemas:
    CreateRoomInviteRequest:
      properties:
        expires_in_seconds:
          type: integer
          maximum: 2592000
          minimum: 60
          title: Expires In Seconds
          description: >-
            How long the link stays usable, in seconds from now, counted on the
            server's clock. Required — there is no default, because a link that
            outlives the conversation it was for is the one mistake this field
            exists to prevent. After it passes, the link returns 410 and cannot
            be renewed; mint a new one.


            At most 30 days (2,592,000). A shareable credential nobody has to
            re-authorize should not outlive the quarter it was made in, and the
            cap is also what stops a value large enough to overflow the stored
            timestamp from reaching the database at all.
          examples:
            - 3600
        max_uses:
          type: integer
          maximum: 100
          minimum: 1
          title: Max Uses
          description: >-
            How many times **this link** may be redeemed. Required, and there is
            no unlimited option. Send `1` for a link meant for one guest — the
            common case, and the one where a forwarded link cannot let a
            stranger in behind them. A higher number admits that many separate
            guests.


            This bounds the link, not the room: a room itself has no participant
            limit, so mint a link with the number of uses you actually intend to
            hand out, or several links, as suits you. The room's only limit is
            that everyone in it must be speaking at most two languages between
            them.


            At most 100. One link admitting an unbounded crowd is a different
            kind of credential from the one this endpoint issues; mint several
            if you need to hand out more, so that a single leak costs you at
            most one of them.
          examples:
            - 1
      type: object
      required:
        - expires_in_seconds
        - max_uses
      title: CreateRoomInviteRequest
      description: >-
        Mint an invite link for a room, bounded in time and in uses.


        Both fields are required: how long a shareable credential lives, and how
        many guests

        it lets in, are the only two things that bound a link once it leaves
        your hands, so

        they are yours to state rather than ours to default. A leaked link is
        bounded by

        exactly what you asked for here — and by `DELETE
        /v1/rooms/{room_id}/invites`, which

        retires the room's links at once and takes effect immediately.


        Each field also has a **server-side ceiling** (30 days, 100 uses). They
        are not a

        policy about how you should run your calls — they are the outer edge of
        what a single

        unauthenticated bearer capability may be, and they are what keeps an
        out-of-range

        value a 422 naming the bound instead of a number the database cannot
        hold. If you

        need more than either allows, mint another link.
    RoomInviteCreatedResponse:
      properties:
        invite_code:
          type: string
          title: Invite Code
        expires_at:
          type: string
          format: date-time
          title: Expires At
        max_uses:
          type: integer
          title: Max Uses
      type: object
      required:
        - invite_code
        - expires_at
        - max_uses
      title: RoomInviteCreatedResponse
      description: >-
        A minted invite link.


        **`invite_code` is shown here and nowhere else.** Only a hash of it is
        stored, so it

        cannot be read back from any endpoint — put it in the link you send your
        guest, and

        save it if you will need it again. Losing it costs you nothing you
        cannot undo:

        `DELETE /v1/rooms/{room_id}/invites` retires the room's links without
        it.


        Build the guest's URL yourself, pointing at your own page: that page
        reads the room's

        state from `GET /v1/invites/{invite_code}` and joins through

        `POST /v1/invites/{invite_code}/join`. Keep the code in the URL's
        **path**, not its

        query string, so it does not travel to third parties in a `Referer`
        header.
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
        input:
          title: Input
        ctx:
          type: object
          title: Context
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError
  securitySchemes:
    HTTPBearer:
      type: http
      scheme: bearer

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.