INVITE_ONLY tenant - pick based on whether you know the person’s email up front.
Token - tied to one email
Code - shareable, not tied to an email
code is an 8-character string Kerne generates (e.g. 7HK4RXPQ) - there’s no way to set your own. Nothing gets emailed: post it in your own onboarding flow, a Slack invite, wherever it needs to go. maxUses defaults to 1; omit expiresAt for a code that never expires.
Both land the invitee on the same signup call, as invitationToken or invitationCode. Creating either requires your secret key, or a JWT owner crossing into their own tenant - never call these from a request an end user triggered themselves.
