POST

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Query Parameters

programId
string
required

The program the request acts on. Required on every endpoint. The operator's role bounds which programs they may pass; the program itself is selected by the request, not read from the token.

Body

application/json

What your integration or an operator sends. Which of the user's details are required depends on the role and on your program; if one is missing, the 400 names it.

email
string<email>
required

The user's email address. Must not already be in use in the program.

firstName
string

The user's first name. Send it for a cardholder on a corporate: it is printed on the card.

lastName
string

The user's last name. Send it for a cardholder on a corporate: it is printed on the card.

dob
string

Date of birth, YYYY-MM-DD.

nationality
string

Two-letter country code, for example GB.

phone
string

7 to 15 digits, with an optional + in front.

address
object

The user's address. country is a three-letter code. For some sub-user roles it is copied from the funding account's owner and can be left out.

payInIBAN
string

IBAN assigned to the user for pay-in. Required when the role has pay-in switched on; otherwise ignored.

clientReference
string

The user's id in your own identity provider, at most 36 characters. Required on every invite if your program uses a client reference, and it must be unique (409 if already used). Ignored on every other program.

Maximum string length: 36
accountId
string<uuid>

The parent account a sub-user is funded from. Required with PREPAID_CARD_CUSTOMER, CARD_ONLY and CHILD. Do not send it with EMPLOYEE or a role set up for your program. The account must be ACTIVE, in your program, and not itself funded from a parent.

additionalAccounts
string[]

Names of the optional accounts your program offers, to open for the user on top of the ones onboarding creates. A name your program does not offer returns 400. Example: ["Leefgeldrekening"].

sendInvite
boolean
default:true

Whether to email the user now. Default true.

Send false to create the invite without emailing them. When you are ready, send the email with POST /customers/{customerId}/reset, using the invite's applicationId as customerId. That route is not under /v1 and needs the customers.triage.reset permission.

On a program that uses a client reference, sendInvite: false returns 400: those programs never send an invitation email.

isCompany
boolean
default:false

Send true to invite a company in place of an individual. Default false. Its details are collected during onboarding. Cannot be sent with a role. Your program must support company onboarding, and a caller acting for a custodian cannot send it.

role
string

What the user becomes. Leave it out to invite a customer.

  • PREPAID_CARD_CUSTOMER, CARD_ONLY, CHILD: a sub-user. Send accountId.
  • EMPLOYEE: an employee of a corporate. Send corporateCustomerId and accountIds.
  • A role set up for your program, for example CONSUMER_CARDHOLDER: a cardholder on a corporate's accounts. Send corporateCustomerId and accountIds.

Your program must have the role. Write it exactly, in capitals with underscores. CORPORATE_MANAGER cannot be invited on this route.

Maximum string length: 64
Pattern: ^[A-Z][A-Z0-9]*(?:_[A-Z0-9]+)*$
Example:

"CONSUMER_CARDHOLDER"

corporateCustomerId
string<uuid>

The corporate the cardholder belongs to. Required with EMPLOYEE or a role set up for your program. Must be a company in your program that has finished onboarding. Refused on any other invite.

accountIds
string<uuid>[]

The corporate's accounts the cardholder may use, at least one. Required with EMPLOYEE or a role set up for your program. Each must be an ACTIVE account of that corporate, and not one that is itself funded from a parent. If one is wrong the whole invite is refused, and the message does not say which. Refused on any other invite.

confirmation
Passkey · object

Step-up: a passkey or a TOTP code. Required from an operator. A service user leaves it out.

Response

The invitation was created.

success
boolean
Example:

true

message
string
Example:

"Customer invitation processed successfully"

data
object