# List a repository's invitations

> A repository's pending invitations: who each is for (invitee, or the email it was sent to when they had no account), the role it gives, who sent it and when it expires.

<div class="g1t-endpoint"><span class="g1t-method" data-method="get">GET</span><code>/repos/{owner}/{name}/invitations</code></div>

Needs the Admin role. People only.

Pending invitations only, newest first. `email` is set for an invitation sent to an address that had no account. Refused with `403` without the Admin role. See [Access and roles](/guides/access-and-roles/).

- **Authentication:** Required. Send an [access token](/reference/api/#authentication) as `Authorization: Bearer`.
- **MCP tool:** [`access`](/reference/mcp/#access) with `action` `list_invitations`, and the same inputs
- **Scope:** An access token needs [`access:read`](/guides/authentication/#scopes).

## Path parameters

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `owner` | string | Yes | The workspace that owns the repository. |
| `name` | string | Yes | The repository's name. |

## Example request

```sh
curl https://api.g1t.sh/repos/flagon-io/hello/invitations \
  -H "Authorization: Bearer $G1T_TOKEN"
```

## Example response

A successful request answers `200` with:

```json
[
  {
    "id": "rin_01kp3c4d5e6f7g8h9j0k1m2n3p",
    "repo": "flagon-io/hello",
    "repo_id": "rep_01m3m5q6p0e2qaw6mmjahk0qrr",
    "invitee": "alan",
    "email": null,
    "role": "write",
    "invited_by": "syntaqx",
    "inviter_avatar": null,
    "status": "pending",
    "created_at": "2026-10-05T17:00:00.000Z",
    "expires_at": "2026-10-12T17:00:00.000Z"
  },
  {
    "id": "rin_01kp3d7e8f9g0h1j2k3m4n5p6q",
    "repo": "flagon-io/hello",
    "repo_id": "rep_01m3m5q6p0e2qaw6mmjahk0qrr",
    "invitee": null,
    "email": "joan@example.com",
    "role": "read",
    "invited_by": "syntaqx",
    "inviter_avatar": null,
    "status": "pending",
    "created_at": "2026-10-05T17:00:00.000Z",
    "expires_at": "2026-10-12T17:00:00.000Z"
  }
]
```

## Errors

A failed request answers with one of these statuses and a body like `{"error": {"code": "not_found", "message": "Repository not found."}}`. See [errors](/reference/api/#errors).

| Status | Code | When |
| --- | --- | --- |
| 401 | `unauthenticated` | A token is required, or the one sent is not valid. |
| 403 | `forbidden` | The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | `not_found` | It does not exist, or you cannot see it. |
| 422 | `invalid` | The input is not valid. `message` says which field and why. |
