# accountants.inviteMany

Invite up to 10 people from one accounting firm in one go. Each person has their own email, name, access level (preset) and end date; the firm name and message are shared. Returns which invitations were sent and which failed, each with its private join link. Administrator access is required. MCP calls also require accounting:admin; the web agent asks for approval before changing outside access. Direct API requests cannot perform these access-granting actions.

`POST /api/v1/accounting/accountants.inviteMany`

Permissions: `accounting:read`, `accounting:write`, `accounting:admin` · Roles: admin · Idempotency key required · Reaches outside Oatmilk (email or a provider)

MCP tool: `accounting_accountants_invite_many`

## Fields

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `firm` | string |  | at most 200 characters. |
| `message` | string |  | at most 2000 characters. |
| `people` | array of objects | Yes | 1–10 items. |
| `people[].email` | string (email) | Yes | An email address. at most 320 characters. |
| `people[].name` | string |  | A display name. at most 200 characters. |
| `people[].preset` | enum |  | One of: `read`, `comment`, `prepare`. Default `"read"`. |
| `people[].accessExpiresOn` | string or null | Yes |  |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–150 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/accountants.inviteMany \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "people": [
    {
      "email": "finance@example.com",
      "accessExpiresOn": "2026-09-30"
    }
  ]
}'
```

Reference page: https://app.getoatmilk.com/docs/api/accountants.inviteMany
