Revoke invitation
Revokes a pending invitation through the existing company-scoped service. Requires API access Manage and Team & access Manage, using the API key’s person and company. Existing account, subscription, staging and usage checks apply; no additional Growth or RBAC gate. Target-management authorization remains in effect.
Supply only a public ID matching ^invite_[A-Za-z0-9]+$. Numeric IDs, UUIDs and acceptance tokens return invalid_request. Send no body or query parameters, including version, empty JSON objects or company overrides. No Content-Type is required. Unexpected input returns 400 invalid_request.
Returns 204 with no response body, including repeated deletion and already-absent IDs after authorization. Foreign-company IDs behave as absent, return the same empty 204, and leave foreign records untouched. No global lookup exposes existence. Accepted invitations return 404 resource_missing; this operation never removes teammates or mutates memberships. Both expired and unexpired pending invitations can be revoked. A target above the caller’s access returns insufficient_permission.
Retry the same DELETE after a timeout or invitation_revoke_failed using bounded backoff; absence succeeds after authorization on every call. No version or Idempotency-Key is required. Fix 400 input, 401 credentials, or 403 access before retrying; do not retry 404 to remove an accepted member. For rate_limit_exceeded, wait Retry-After seconds; monthly_limit_exceeded has no Retry-After and requires waiting for the stated monthly reset or changing the applicable limit. Server operation failures use invitation_revoke_failed with a safe message.