# List a workspace's invites

> The invites made for a workspace, newest first, with each pending one's code.

<div class="g1t-endpoint"><span class="g1t-method" data-method="get">GET</span><code>/workspaces/{workspace}/invitations</code></div>

Owners only.

- **Authentication:** Required. Send an [access token](/reference/api/#authentication) as `Authorization: Bearer`.
- **MCP tool:** [`workspace`](/reference/mcp/#workspace) with `action` `list_invites`, and the same inputs
- **Scope:** An access token needs [`workspace:read`](/guides/authentication/#scopes).

## Path parameters

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `workspace` | string | Yes | The workspace's slug, e.g. "flagon-io". |

## Example request

```sh
curl https://api.g1t.sh/workspaces/flagon-io/invitations \
  -H "Authorization: Bearer $G1T_TOKEN"
```

## Example response

A successful request answers `200` with:

```json
[
  {
    "id": "inv_01kp2x7m8n9q0r1s2t3v4w5x6y",
    "code": "g1t-k7m2-q9xd-4hpw-…",
    "hint": "g1t-k7m2",
    "email": "ada@example.com",
    "kind": "account",
    "workspace": "acme-labs",
    "status": "pending",
    "charged_to": "workspace",
    "invited_by": "syntaqx",
    "redeemed_by": null,
    "created_at": "2026-10-05T17:00:00.000Z",
    "expires_at": "2026-11-04T17:00:00.000Z",
    "redeemed_at": null,
    "revoked_at": null
  },
  {
    "id": "inv_01kp1z9y8x7w6v5t4s3r2q1p0n",
    "code": "g1t-k7m2-q9xd-4hpw-…",
    "hint": "g1t-w2vb",
    "email": "linus@example.com",
    "kind": "workspace",
    "workspace": "acme-labs",
    "status": "pending",
    "charged_to": "none",
    "invited_by": "syntaqx",
    "redeemed_by": null,
    "created_at": "2026-10-05T17:00:00.000Z",
    "expires_at": "2026-11-04T17:00:00.000Z",
    "redeemed_at": null,
    "revoked_at": null
  }
]
```

## Errors

A failed request answers with one of these statuses and a body like `{"error": {"code": "not_found", "message": "Repository not found."}}`. See [errors](/reference/api/#errors).

| Status | Code | When |
| --- | --- | --- |
| 401 | `unauthenticated` | A token is required, or the one sent is not valid. |
| 403 | `forbidden` | The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | `not_found` | It does not exist, or you cannot see it. |
| 422 | `invalid` | The input is not valid. `message` says which field and why. |
