Invitations: Data, permissions, and operations
Stores hashed invite tokens with expiry, checks seat limits at accept time, invalidates unused invites on revoke, and binds the granted role at accept rather than encoding it in the URL.
Referencev0.1.0NOASSERTION
Published Sep 12, 2026