> ## Documentation Index
> Fetch the complete documentation index at: https://docs.scanova.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Invite a shared user

> POST /multi-users/

Shared users are the teammates you invite into your Scanova account — the same list shown on the dashboard's **Users** table. This endpoint lets you list, invite, update, or remove them programmatically.

<Note>
  This endpoint was not previously documented. It requires a Management API key with `MANAGEMENT_API` (or `MANAGEMENT_API_SANDBOX`) quota, sent as the raw `Authorization` header value — see the [Management API overview](/api-reference/management-api/overview) — plus the account's own Team quota for shared users. For what each role actually grants, see [Roles & permissions](/team/roles-and-permissions); for the wire format of roles themselves, see [Roles (access levels)](/api-reference/management-api/shared-users/roles-list).
</Note>

<RequestExample>
  ```bash cURL theme={null}
  curl --request POST \
    --url 'https://management.scanova.io/multi-users/' \
    --header 'Authorization: YOUR_API_KEY' \
    --header 'Content-Type: application/json' \
    --data '{
      "email": "teammate@example.com",
      "name": "Jordan Lee",
      "access_level": 5
    }'
  ```
</RequestExample>

<ResponseExample>
  ```json 201 theme={null}
  {
    "id": 118,
    "shared_user": {
      "id": 88213,
      "first_name": "Jordan",
      "last_name": "Lee",
      "full_name": "Jordan Lee",
      "email": "teammate@example.com",
      "is_active": false,
      "is_locked": false
    },
    "access_level": {
      "id": 5,
      "name": "Manager",
      "slug": "manager",
      "permissions": [],
      "is_custom": false
    },
    "invitation_sent_on": null,
    "invitation_accepted_on": null,
    "is_invitation_sent": false,
    "is_invitation_accepted": false,
    "status": "Invitation Sent",
    "is_active": false,
    "created": "2026-08-16T20:41:09.442000+05:30",
    "modified": "2026-08-16T20:41:09.442000+05:30",
    "include_untagged": true,
    "enable_tag_permission": false,
    "tags": []
  }
  ```
</ResponseExample>

<ParamField body="email" type="string" required>
  Email address for the new teammate. Must not already belong to another Scanova user — a duplicate returns a 400 with `{"email": ["Email address is already used."]}`.
</ParamField>

<ParamField body="name" type="string" required>
  Display name, up to 20 characters.
</ParamField>

<ParamField body="access_level" type="integer" required>
  ID of a role from [`GET /multi-users/access-levels/`](/api-reference/management-api/shared-users/roles-list) — either a default system role or a custom one this account created.
</ParamField>

<ParamField body="tags" type="array">
  Tag IDs to scope this user's access to. Requires the account's `CUSTOM_TAG`/tag-permission quota — otherwise rejected with a 403.
</ParamField>

<ParamField body="enable_tag_permission" type="boolean" default="false">
  Restrict this user's visible QR codes to `tags`.
</ParamField>

<ParamField body="include_untagged" type="boolean" default="true">
  When `enable_tag_permission` is true, whether untagged QR codes are still visible.
</ParamField>

<Note>
  Inviting a teammate always sends them an invitation email — creating the record here has the same effect as clicking **Invite Users** in the dashboard's Users table. There is no way to skip the email via this endpoint.
</Note>

## Related

* [List shared users](/api-reference/management-api/shared-users/list) — the other operation on this same endpoint.
* [Retrieve a shared user](/api-reference/management-api/shared-users/retrieve) — operate on the shared user's record after inviting them.
* [Update a shared user](/api-reference/management-api/shared-users/update) — operate on the shared user's record after inviting them.
* [Remove a shared user](/api-reference/management-api/shared-users/remove) — operate on the shared user's record after inviting them.
* [List roles](/api-reference/management-api/shared-users/roles-list) — look up or create the `access_level` ID this endpoint's invite/update calls require.
* [Create a custom role](/api-reference/management-api/shared-users/roles-create) — look up or create the `access_level` ID this endpoint's invite/update calls require.
* [Shared users](/team/shared-users) — the dashboard's own Users table, showing the same invite/deactivate/remove actions.
* [Roles & permissions](/team/roles-and-permissions) — what each role actually grants a teammate.


## OpenAPI

````yaml api-reference/openapi/management-api.json POST /multi-users/
openapi: 3.1.0
info:
  title: Scanova Management API (v2)
  description: >-
    The complete Scanova Management API — every endpoint available at
    management.scanova.io (QR codes, folders, tags, leads, forms, analytics,
    plans, shared users & roles), plus the token-creation and usage-stats
    endpoints used to authenticate against it. Every path and request/response
    shape below was verified live against a real API key and the actual running
    backend (Phase 7, 2026-08-16) — not guessed from reading urls.py alone.
  version: 2.0.0
servers:
  - url: https://management.scanova.io
    description: Management API — QR/folder/tag/lead/form/analytics/plans endpoints
security:
  - apiKeyAuth: []
paths:
  /multi-users/:
    post:
      summary: Invite a shared user
      operationId: createManagedSharedUser
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                email:
                  type: string
                  format: email
                name:
                  type: string
                  maxLength: 20
                access_level:
                  type: integer
                  description: Role ID from GET /multi-users/access-levels/.
                tags:
                  type: array
                  items:
                    type: integer
                enable_tag_permission:
                  type: boolean
                  default: false
                include_untagged:
                  type: boolean
                  default: true
              required:
                - email
                - name
                - access_level
            example:
              email: teammate@example.com
              name: Jordan Lee
              access_level: 5
      responses:
        '201':
          description: Invitation created — sends an invitation email to the shared user.
          content:
            application/json:
              example:
                id: 118
                shared_user:
                  id: 88213
                  first_name: Jordan
                  last_name: Lee
                  full_name: Jordan Lee
                  email: teammate@example.com
                  is_active: false
                  is_locked: false
                access_level:
                  id: 5
                  name: Manager
                  slug: manager
                  permissions: []
                  is_custom: false
                invitation_sent_on: null
                invitation_accepted_on: null
                is_invitation_sent: false
                is_invitation_accepted: false
                status: Invitation Sent
                is_active: false
                include_untagged: true
                enable_tag_permission: false
                tags: []
components:
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: Authorization
      description: >-
        Send your Management API key as the raw value of the Authorization
        header — no "Bearer " or "Token " prefix, and no other characters.
        Example: `Authorization: 401f7ac837da42b97f613d789819ff93537bee6a`. A
        header containing more than one space-separated part is rejected
        outright. Requests also require the request's Host header to be the
        management API host (e.g. management.scanova.io) — the same key sent to
        the regular API host will not authenticate.

````