1
Turn on invite-only mode
Set the tenant’s registration mode to invite-only (
registration_mode: 'INVITE_ONLY', under Settings → Authentication - see Registration modes). This is enforced at the API level - even a request that bypasses your frontend entirely still needs a valid token or code.2
Create codes/tokens (server-side)
3
Signup with the code (client-side)
kerne.invitations.validateCode(code) - a public route, no auth required.Pitfalls to avoid
“Account already exists.” If someone with an invite code already has an account,K1008 (email taken) is what you’ll see - route that to “log in instead”, not a generic failure message.
Lost invites. There’s no resend() method today - re-sending means creating a new token/code and emailing it yourself. Track which emails you’ve already invited so you don’t accidentally issue duplicates.
