# accountants.invite

Invite an accountant by email with an access level (preset read, comment or prepare), an access end date (or null for no end date), optional name, firm and message, and an idempotency key. Returns the invitation and a private join link. Administrator access is required. MCP calls also require accounting:admin; the web agent asks for approval before changing outside access. Direct API requests cannot perform these access-granting actions.

`POST /api/v1/accounting/accountants.invite`

Permissions: `accounting:read`, `accounting:write`, `accounting:admin` · Roles: admin · Idempotency key required · Reaches outside Oatmilk (email or a provider)

MCP tool: `accounting_accountants_invite`

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `email` | string (email) | Yes | An email address. at most 320 characters. |
| `accessExpiresOn` | string or null | Yes |  |
| `name` | string |  | A display name. at most 200 characters. |
| `firm` | string |  | at most 200 characters. |
| `message` | string |  | at most 2000 characters. |
| `preset` | enum |  | One of: `read`, `comment`, `prepare`. Default `"read"`. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/accountants.invite \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "email": "finance@example.com",
  "accessExpiresOn": "2026-09-30"
}'
```

Reference page: https://app.getoatmilk.com/docs/api/accountants.invite
