# team.invitations.revoke

Cancel a pending team invitation so its link stops working, with source (oatmilk, or clerk for an invitation sent before Oatmilk sent its own), id, expectedRevision for an Oatmilk invitation, and idempotencyKey. Only organization administrators can manage the team. MCP calls also require the accounting:admin scope; the direct API cannot send team invitations or remove members.

`POST /api/v1/accounting/team.invitations.revoke`

Permissions: `accounting:read`, `accounting:write`, `accounting:admin` · Roles: admin · Idempotency key required · Send `expectedRevision` · Destructive: confirm with a person first

MCP tool: `accounting_team_invitations_revoke`

## Fields

#### source: "oatmilk"

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `source` | "oatmilk" | Yes | Where the record came from. |
| `id` | string (ID) | Yes | The record's ID. |
| `expectedRevision` | integer | Yes | The record's current revision, from the last time you read it. If someone changed the record since, the request is refused with a conflict so you can reload and check before trying again. at most 9007199254740991; greater than 0. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |

#### source: "clerk"

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `source` | "clerk" | Yes | Where the record came from. |
| `id` | string | Yes | The record's ID. Matches ^orginv_[A-Za-z0-9]{8,64}$. |
| `idempotencyKey` | string | Yes | Any unique text you generate once per intended change, so a retried request only happens once. Send it as the Idempotency-Key header instead if you prefer; if you send both they must match. 8–200 characters. |

## Example request

```bash
curl https://app.getoatmilk.com/api/v1/accounting/team.invitations.revoke \
  -H "Authorization: Bearer $OATMILK_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $(uuidgen)" \
  -d '{
  "source": "oatmilk",
  "id": "9a8b7c6d-5e4f-4a3b-8c2d-1e0f9a8b7c6d",
  "expectedRevision": 3
}'
```

Reference page: https://app.getoatmilk.com/docs/api/team.invitations.revoke
