Administration

accountants.invite

Invite an accountant by email with an access level (preset read, comment or prepare), an access end date (or null for no end date), optional name, firm and message, and an idempotency key. Returns the invitation and a private join link. Administrator access is required. MCP calls also require accounting:admin; the web agent asks for approval before changing outside access. Direct API requests cannot perform these access-granting actions.

POST/api/v1/accounting/accountants.invite

Permissions

accounting:readaccounting:writeaccounting:admin

Who can call it

admin

Retries

Idempotency key required

MCP

accounting_accountants_invite

Reaches outside Oatmilk

It emails people or calls another service.

Fields

  • emailstring (email)Required

    An email address.

    at most 320 characters

  • accessExpiresOnstring or nullRequired
  • namestring

    A display name.

    at most 200 characters

  • firmstring

    at most 200 characters

  • messagestring

    at most 2000 characters

  • presetenum
    readcommentprepare

    Default "read"

  • idempotencyKeystringRequired

    Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match.

    8–200 characters

Example

curl https://app.getoatmilk.com/api/v1/accounting/accountants.invite \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "email": "finance@example.com",
  "accessExpiresOn": "2026-09-30"
}'
Response
{
  "data": { … }
}

Try it

Try it

Checks your input with this action’s real schema and answers like the API, with synthetic data. No key needed, and nothing changes.

POST/api/v1/accounting/accountants.invite
curl https://app.getoatmilk.com/api/v1/accounting/accountants.invite \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "email": "finance@example.com",
  "accessExpiresOn": "2026-09-30"
}'

More in Administration.