cancel-invite
dci cancel-invite <id> [body] [flags]
Marks the invite as Cancelled and invalidates the invite token so any outstanding email
links stop working. The invite document is retained (soft cancel) — the user row remains
visible in GET /iam/v1/users with inviteStatus: Cancelled. Use DELETE /iam/v1/users/\{id\}
to fully remove the record.
Returns 404 if no invite exists for the given ID, and 409 if the invite is already cancelled.
Requires usersManager permission.
id— ID of the invited user — theidof adci list-usersrow whose status isinvited, also returned asuser.idbydci invite-user.
Pass the request body as name: value arguments or pipe JSON on stdin — see Command structure.
cancel-invite carries the API's own dryRun parameter, so --dry-run sends a simulation
request and returns the real response shape marked as a dry run, instead of the local preview
most destructive commands print. An --idempotency-key is required on every real call
(UUID v4 or ULID recommended); when you omit it under --dry-run the CLI generates a
throwaway key for you.
Examples
# Simulate the cancellation server-side; the CLI supplies a throwaway idempotency key for the dry run.
dci cancel-invite <invite-id> --dry-run
# Cancel the invite; the key is required, and retrying with the same key returns the cached result.
dci cancel-invite <invite-id> --idempotency-key "$(uuidgen)" --yes
The invite is marked `Cancelled` and its email links stop working; the row stays in `dci list-users` until you `dci delete-user <invite-id>`.
# Same, as JSON for scripts.
dci cancel-invite <invite-id> --idempotency-key <request-key> --yes --output json
Request
Content-Type: application/json
Raw JSON schema
{
"type": "object"
}
Flags
| Flag | Type | Default | Example | Description |
|---|---|---|---|---|
--dry-run | boolean | false | If true, validates and simulates the operation without committing changes. The response shape is identical to a real execution. |
Every command also accepts the CLI-wide flags for output shaping — see Output formats and Table output options.
Output
OK - Invite cancelled.
By default dci renders the result as a table. Use --output json to get the full structure described below — see Output formats.
| Field | Type | Description |
|---|---|---|
message | string | Success message |
inviteId | string | The invite document ID. |
Raw JSON schema
{
"type": "object",
"description": "Response confirming invite cancellation.",
"required": [
"message",
"inviteId"
],
"properties": {
"message": {
"type": "string",
"description": "Success message"
},
"inviteId": {
"type": "string",
"description": "The invite document ID."
}
}
}
Errors
On failure, dci prints a single error message — with a hint when one is available — and exits with a typed code your scripts can branch on. See Errors and exit codes for the full contract.
HTTP status to exit code mapping
| HTTP status | Exit code | Error code | Meaning |
|---|---|---|---|
| 400 | 30 | VALIDATION_ERROR | The arguments or request body were rejected. Review the command's flags and payload. |
| 401 | 10 | AUTHENTICATION_FAILED | Not signed in, or the API token is invalid. Run dci login or check DCI_API_KEY. |
| 403 | 11 | PERMISSION_DENIED | The DoiT user or the active customer context does not have access. |
| 404 | 20 | RESOURCE_NOT_FOUND | The requested resource does not exist. Check the identifier argument. |
| 409 | 21 | RESOURCE_CONFLICT | The operation conflicts with the resource's current state. |
| 500 | 40 | API_SERVER_ERROR | The API failed to process the request. Retryable; contact DoiT support if it persists. |
Related
- resend-invite — Resend invite
- invite-user — Invite user
- list-users — List users
- delete-user — Delete user
- API reference: POST /iam/v1/users/{id}/actions/cancel
Aliases: cancelinvite