curl --request POST \
--url 'https://management.scanova.io/multi-users/' \
--header 'Authorization: YOUR_API_KEY' \
--header 'Content-Type: application/json' \
--data '{
"email": "teammate@example.com",
"name": "Jordan Lee",
"access_level": 5
}'
{
"id": 118,
"shared_user": {
"id": 88213,
"first_name": "Jordan",
"last_name": "Lee",
"full_name": "Jordan Lee",
"email": "teammate@example.com",
"is_active": false,
"is_locked": false
},
"access_level": {
"id": 5,
"name": "Manager",
"slug": "manager",
"permissions": [],
"is_custom": false
},
"invitation_sent_on": null,
"invitation_accepted_on": null,
"is_invitation_sent": false,
"is_invitation_accepted": false,
"status": "Invitation Sent",
"is_active": false,
"created": "2026-08-16T20:41:09.442000+05:30",
"modified": "2026-08-16T20:41:09.442000+05:30",
"include_untagged": true,
"enable_tag_permission": false,
"tags": []
}
Management API — Shared Users & Roles
Invite a shared user
POST /multi-users/
POST
/
multi-users
/
curl --request POST \
--url 'https://management.scanova.io/multi-users/' \
--header 'Authorization: YOUR_API_KEY' \
--header 'Content-Type: application/json' \
--data '{
"email": "teammate@example.com",
"name": "Jordan Lee",
"access_level": 5
}'
{
"id": 118,
"shared_user": {
"id": 88213,
"first_name": "Jordan",
"last_name": "Lee",
"full_name": "Jordan Lee",
"email": "teammate@example.com",
"is_active": false,
"is_locked": false
},
"access_level": {
"id": 5,
"name": "Manager",
"slug": "manager",
"permissions": [],
"is_custom": false
},
"invitation_sent_on": null,
"invitation_accepted_on": null,
"is_invitation_sent": false,
"is_invitation_accepted": false,
"status": "Invitation Sent",
"is_active": false,
"created": "2026-08-16T20:41:09.442000+05:30",
"modified": "2026-08-16T20:41:09.442000+05:30",
"include_untagged": true,
"enable_tag_permission": false,
"tags": []
}
Shared users are the teammates you invite into your Scanova account — the same list shown on the dashboard’s Users table. This endpoint lets you list, invite, update, or remove them programmatically.
This endpoint was not previously documented. It requires a Management API key with
MANAGEMENT_API (or MANAGEMENT_API_SANDBOX) quota, sent as the raw Authorization header value — see the Management API overview — plus the account’s own Team quota for shared users. For what each role actually grants, see Roles & permissions; for the wire format of roles themselves, see Roles (access levels).curl --request POST \
--url 'https://management.scanova.io/multi-users/' \
--header 'Authorization: YOUR_API_KEY' \
--header 'Content-Type: application/json' \
--data '{
"email": "teammate@example.com",
"name": "Jordan Lee",
"access_level": 5
}'
{
"id": 118,
"shared_user": {
"id": 88213,
"first_name": "Jordan",
"last_name": "Lee",
"full_name": "Jordan Lee",
"email": "teammate@example.com",
"is_active": false,
"is_locked": false
},
"access_level": {
"id": 5,
"name": "Manager",
"slug": "manager",
"permissions": [],
"is_custom": false
},
"invitation_sent_on": null,
"invitation_accepted_on": null,
"is_invitation_sent": false,
"is_invitation_accepted": false,
"status": "Invitation Sent",
"is_active": false,
"created": "2026-08-16T20:41:09.442000+05:30",
"modified": "2026-08-16T20:41:09.442000+05:30",
"include_untagged": true,
"enable_tag_permission": false,
"tags": []
}
string
required
Email address for the new teammate. Must not already belong to another Scanova user — a duplicate returns a 400 with
{"email": ["Email address is already used."]}.string
required
Display name, up to 20 characters.
integer
required
ID of a role from
GET /multi-users/access-levels/ — either a default system role or a custom one this account created.array
Tag IDs to scope this user’s access to. Requires the account’s
CUSTOM_TAG/tag-permission quota — otherwise rejected with a 403.boolean
default:"false"
Restrict this user’s visible QR codes to
tags.boolean
default:"true"
When
enable_tag_permission is true, whether untagged QR codes are still visible.Inviting a teammate always sends them an invitation email — creating the record here has the same effect as clicking Invite Users in the dashboard’s Users table. There is no way to skip the email via this endpoint.
Related
- List shared users — the other operation on this same endpoint.
- Retrieve a shared user — operate on the shared user’s record after inviting them.
- Update a shared user — operate on the shared user’s record after inviting them.
- Remove a shared user — operate on the shared user’s record after inviting them.
- List roles — look up or create the
access_levelID this endpoint’s invite/update calls require. - Create a custom role — look up or create the
access_levelID this endpoint’s invite/update calls require. - Shared users — the dashboard’s own Users table, showing the same invite/deactivate/remove actions.
- Roles & permissions — what each role actually grants a teammate.
Authorizations
Send your Management API key as the raw value of the Authorization header — no "Bearer " or "Token " prefix, and no other characters. Example: Authorization: 401f7ac837da42b97f613d789819ff93537bee6a. A header containing more than one space-separated part is rejected outright. Requests also require the request's Host header to be the management API host (e.g. management.scanova.io) — the same key sent to the regular API host will not authenticate.
Body
application/json
Response
201 - application/json
Invitation created — sends an invitation email to the shared user.
Was this page helpful?
⌘I