# Invite a merchant to their portal

Mints a merchant-portal invitation for one deal and answers the bearer token ONCE, with the accept path and a full `inviteUrl` when `baseUrl` is given — the row keeps only the token's hash, so a token not saved now is gone. `email` is required, `expiresAt` must be in the future if sent, and `language` defaults to en. The merchant company is resolved from the deal's merchant cell at mint time and never re-followed. Deals only.

Access class: `def:read`.

## Endpoint

`POST /v1/definitions/{key}/rows/{rowId}/merchant-invitations`

## Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| key | path | string | Yes |
| rowId | path | string | Yes |

## Request body

Content type: `application/json`.

```json
{
  "body": {
    "baseUrl": "string",
    "email": "string",
    "expiresAt": "string",
    "language": "string",
    "name": "string"
  },
  "params": {
    ":key": "string",
    ":rowId": ""
  },
  "query": {}
}
```

## Responses

### 201

the action's answer

Content type: `application/json`.

```json
{}
```

### default

a refusal: `{"error": "<what a person needs to read>"}`. 401 no credential, 402 the plan does not include this, 403 the seat does not, 404 the thing does not exist or is not yours to see.

Content type: `application/json`.

```json
{
  "error": "string"
}
```
