Skip to main content
POST
Shared users are the teammates you invite into your Scanova account — the same list shown on the dashboard’s Users table. This endpoint lets you list, invite, update, or remove them programmatically.
This endpoint was not previously documented. It requires an API key with MANAGEMENT_API (or MANAGEMENT_API_SANDBOX) quota, sent as the raw Authorization header value — see the API overview — plus the account’s own Team quota for shared users. For what each role actually grants, see Roles & permissions; for the wire format of roles themselves, see Roles (access levels).
string
required
Email address for the new teammate. Must not already belong to another Scanova user — a duplicate returns a 400 with {"email": ["Email address is already used."]}.
string
required
Display name, up to 20 characters.
integer
required
ID of a role from GET /multi-users/access-levels/ — either a default system role or a custom one this account created.
array
Tag IDs to scope this user’s access to. Requires the account’s CUSTOM_TAG/tag-permission quota — otherwise rejected with a 403.
boolean
default:"false"
Restrict this user’s visible QR Codes to tags.
boolean
default:"true"
When enable_tag_permission is true, whether untagged QR Codes are still visible.
Inviting a teammate always sends them an invitation email — creating the record here has the same effect as clicking Invite Users in the dashboard’s Users table. There is no way to skip the email via this endpoint.
  • List shared users — the other operation on this same endpoint.
  • Retrieve a shared user — operate on the shared user’s record after inviting them.
  • Update a shared user — operate on the shared user’s record after inviting them.
  • Remove a shared user — operate on the shared user’s record after inviting them.
  • List roles — look up or create the access_level ID this endpoint’s invite/update calls require.
  • Create a custom role — look up or create the access_level ID this endpoint’s invite/update calls require.
  • Shared users — the dashboard’s own Users table, showing the same invite/deactivate/remove actions.
  • Roles & permissions — what each role actually grants a teammate.

Authorizations

Authorization
string
header
required

Send your Management API key as the raw value of the Authorization header — no "Bearer " or "Token " prefix, and no other characters. Example: Authorization: YOUR_API_KEY. A header containing more than one space-separated part is rejected outright. Requests also require the request's Host header to be the management API host (e.g. api.scanova.io) — the same key sent to the regular API host will not authenticate.

Body

application/json
email
string<email>
required
name
string
required
Maximum string length: 20
access_level
integer
required

Role ID from GET /multi-users/access-levels/.

tags
integer[]
enable_tag_permission
boolean
default:false
include_untagged
boolean
default:true

Response

201 - application/json

Invitation created — sends an invitation email to the shared user.