Skip to main content
Both routes are public - no secret key required - so you can call them straight from a signup page before the user has any session, to show “this invitation isn’t valid anymore” before they fill out the form.

Validate token

Validate a unique invitation token sent via email.

Validate code

Validate a shareable join code.

canUse vs valid

A code can be valid: true and still canUse: false - that’s a code that exists and hasn’t expired, but has already hit its maxUses. valid: false means it doesn’t exist at all, or has expired. Gate signup on canUse, not valid. A token has no equivalent split: it’s single-use, so being used and being invalid are the same event, and valid: false already covers it.