Skip to main content
Pinecone Docs
current

Search documentation

Type to search this documentation.

Invite a user to the organization

Invite a user to the organization by email and grant their initial role bindings.

POST/admin/invites

Invite a user to the organization

1 parameter
  • X-Pinecone-Api-Versionstringheaderrequired

    Required date-based version header

cURL
curl --request POST \
  --url https://api.pinecone.io/admin/invites \
  --header 'Authorization: Bearer <token>' \
  --header 'X-Pinecone-Api-Version: <x-pinecone-api-version>' \
  --header 'Content-Type: application/json' \
  --data '{
  "email": "newhire@acme.com",
  "role_bindings": [
    {
      "resource_type": "organization",
      "role": "OrgMember"
    }
  ]
}'
Python
import requests

url = "https://api.pinecone.io/admin/invites"

payload = {
  "email": "newhire@acme.com",
  "role_bindings": [
    {
      "resource_type": "organization",
      "role": "OrgMember"
    }
  ]
}
headers = {
    "Authorization": "Bearer <token>",
    "X-Pinecone-Api-Version": "<x-pinecone-api-version>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.text)
JavaScript
const options = {method: "POST", headers: {"Authorization": "Bearer <token>", "X-Pinecone-Api-Version": "<x-pinecone-api-version>", "Content-Type": "application/json"}, body: JSON.stringify({
  "email": "newhire@acme.com",
  "role_bindings": [
    {
      "resource_type": "organization",
      "role": "OrgMember"
    }
  ]
})};

fetch("https://api.pinecone.io/admin/invites", options)
  .then(res => res.json())
  .then(res => console.log(res))
  .catch(err => console.error(err));
PHP
<?php

$curl = curl_init();

curl_setopt_array($curl, [
  CURLOPT_URL => "https://api.pinecone.io/admin/invites",
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_CUSTOMREQUEST => "POST",
  CURLOPT_POSTFIELDS => "{\"email\":\"newhire@acme.com\",\"role_bindings\":[{\"resource_type\":\"organization\",\"role\":\"OrgMember\"}]}",
  CURLOPT_HTTPHEADER => [
    "Authorization: Bearer <token>",
    "X-Pinecone-Api-Version: <x-pinecone-api-version>",
    "Content-Type: application/json"
  ],
]);

$response = curl_exec($curl);
$err = curl_error($curl);

curl_close($curl);

if ($err) {
  echo "cURL Error #:" . $err;
} else {
  echo $response;
}
Go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://api.pinecone.io/admin/invites"

	payload := strings.NewReader("{\"email\":\"newhire@acme.com\",\"role_bindings\":[{\"resource_type\":\"organization\",\"role\":\"OrgMember\"}]}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("X-Pinecone-Api-Version", "<x-pinecone-api-version>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(string(body))

}
Java
HttpResponse<String> response = Unirest.post("https://api.pinecone.io/admin/invites")
  .header("Authorization", "Bearer <token>")
  .header("X-Pinecone-Api-Version", "<x-pinecone-api-version>")
  .header("Content-Type", "application/json")
  .body("{\"email\":\"newhire@acme.com\",\"role_bindings\":[{\"resource_type\":\"organization\",\"role\":\"OrgMember\"}]}")
  .asString();
Ruby
require 'uri'
require 'net/http'

url = URI("https://api.pinecone.io/admin/invites")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["X-Pinecone-Api-Version"] = '<x-pinecone-api-version>'
request["Content-Type"] = 'application/json'
request.body = "{\"email\":\"newhire@acme.com\",\"role_bindings\":[{\"resource_type\":\"organization\",\"role\":\"OrgMember\"}]}"

response = http.request(request)
puts response.read_body
200
{
  "created_at": "2026-04-14T20:00:00.000Z",
  "email": "newhire@acme.com",
  "expires_at": "2026-05-21T03:00:00.000Z",
  "id": "9c8e3528-b9c0-4358-84ce-84c28e91b566",
  "processed_at": null,
  "status": "pending"
}
400
{
  "error": {
    "code": "INVALID_ARGUMENT",
    "message": "Bad request. The request body included invalid request parameters."
  },
  "status": 400
}
401
{
  "error": {
    "code": "UNAUTHENTICATED",
    "message": "Invalid API key."
  },
  "status": 401
}
403
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
409
{
  "error": {
    "code": "ABORTED",
    "message": "Cannot delete the last OrgOwner role binding for this organization."
  },
  "status": 409
}
500
{
  "error": {
    "code": "UNKNOWN",
    "message": "Internal server error"
  },
  "status": 500
}
4XX
{
  "error": {
    "code": "QUOTA_EXCEEDED",
    "message": "The index exceeds the project quota of 5 pods by 2 pods. Upgrade your account or change the project settings to increase the quota."
  },
  "status": 429
}
Authorizationstringrequired

An access token must be provided in the Authorization header using the Bearer scheme.

X-Pinecone-Api-Versionstringrequired

Required date-based version header

Typestring
Default2026-07

The invite to create.

emailstringrequired

The email address to invite.

Required string length: 0 - 254. Example: newhire@acme.com

Typestring
role_bindingsobject[]required

Role bindings for the invitee. Must include at least one organization-scoped binding that grants organization membership (OrgOwner, OrgManager, OrgBillingAdmin, or OrgMember); project-scoped bindings are optional. Not returned in the response.

Typeobject[]
Show child attributes
resource_typestringrequired

The kind of resource scope a role binding applies to. Possible values: organization, project.

Example: project

Typestring
resource_id?string

Project UUID. Required when resource_type is project; omit for organization scope.

Typestring
rolestringrequired

A role assigned to a principal at a resource scope.

Example: ProjectOwner

Typestring

200 — Invite created and email sent. The invite's role bindings are first-class; view or change them through the role-binding endpoints.

An invitation to join the organization.

idstringrequired

The unique ID of the invite.

Typestring
emailstringrequired

The email address the invite was sent to.

Typestring
statusstringrequired

The lifecycle status of an invite. Possible values: pending, expired, processed. List endpoints return only pending and expired invites; processed is returned only when fetching a single invite by ID.

Example: pending

Typestring
expires_at?string | null

When the invite expires if not accepted. Default TTL is 7 days. Resending the invite extends this to now plus 7 days. null if the invite does not expire.

Typestring | null
processed_at?string | null

The date and time the invite was accepted. null or omitted while the invite is still pending or expired.

Typestring | null
created_atstringrequired

The date and time the invite was created.

Typestring
Suggest an edit

Propose a replacement for this page. The site team reviews it before applying any changes.

Export
Documentation menu