Cancel team invitation

Cancels the pending invitation for an email address in a team, so it can no longer be accepted. Any invitation URL previously issued for that team and email stops working, and Canva sends no further reminders for it.

The invitation is identified by email because invitations have no public ID in this version of the API.

Cancelling is idempotent and always succeeds for a team you own, whether or not a pending invitation existed. The response doesn't reveal whether there was anything to cancel, so it's safe to retry. To find out whether an invitation is still pending, use listTeamInvitations; to find out whether the invitee already joined, use listTeamMembers.

Cancelling doesn't affect a user who has already accepted. If acceptance happens first, this operation has no effect and the invitee remains a team member. If cancellation happens first, the invitee sees the standard invalid-invitation page when they follow their URL.

To re-invite the same address after cancelling, call createTeamInvitation again. This issues a new invitation with a new URL.

HTTP method and URL path

POST https://api.canva.com/admin/v1/teams/{teamId}/invitations/cancel

Authentication and authorization

This endpoint requires a valid access token that was generated using client credentials.

Scopes

The access token must have all the following scopes (permissions):

  • admin:team:write

Header parameters

Authorizationstring
Required

Provides credentials to authenticate the request, in the form of a Bearer token.

For example: Authorization: Bearer {token}

Content-Typestring
Required

Indicates the media type of the information sent in the request. This must be set to application/json.

For example: Content-Type: application/json

Path parameters

teamIdstring
Required

The team ID.

Body parameters

emailstring
Required

The email address associated with the invitation.

Minimum length: 1

Maximum length: 254

Example request

Examples for using the /v1/teams/{teamId}/invitations/cancel endpoint:

curl --request POST 'https://api.canva.com/admin/v1/teams/{teamId}/invitations/cancel' \
--header 'Authorization: Bearer {token}' \
--header 'Content-Type: application/json' \
--data '{
"email": "drsmith@brightsmiledental.com"
}'
SH
const fetch = require("node-fetch");
fetch("https://api.canva.com/admin/v1/teams/{teamId}/invitations/cancel", {
method: "POST",
headers: {
"Authorization": "Bearer {token}",
"Content-Type": "application/json",
},
body: JSON.stringify({
"email": "drsmith@brightsmiledental.com"
}),
})
.then(async (response) => {
const data = await response.json();
console.log(data);
})
.catch(err => console.error(err));
JS
import java.io.IOException;
import java.net.URI;
import java.net.http.*;
public class ApiExample {
public static void main(String[] args) throws IOException, InterruptedException {
HttpRequest request = HttpRequest.newBuilder()
.uri(URI.create("https://api.canva.com/admin/v1/teams/{teamId}/invitations/cancel"))
.header("Authorization", "Bearer {token}")
.header("Content-Type", "application/json")
.method("POST", HttpRequest.BodyPublishers.ofString("{\"email\": \"drsmith@brightsmiledental.com\"}"))
.build();
HttpResponse<String> response = HttpClient.newHttpClient().send(
request,
HttpResponse.BodyHandlers.ofString()
);
System.out.println(response.body());
}
}
JAVA
import requests
headers = {
"Authorization": "Bearer {token}",
"Content-Type": "application/json"
}
data = {
"email": "drsmith@brightsmiledental.com"
}
response = requests.post("https://api.canva.com/admin/v1/teams/{teamId}/invitations/cancel",
headers=headers,
json=data
)
print(response.json())
PY
using System.Net.Http;
var client = new HttpClient();
var request = new HttpRequestMessage
{
Method = HttpMethod.Post,
RequestUri = new Uri("https://api.canva.com/admin/v1/teams/{teamId}/invitations/cancel"),
Headers =
{
{ "Authorization", "Bearer {token}" },
},
Content = new StringContent(
"{\"email\": \"drsmith@brightsmiledental.com\"}",
Encoding.UTF8,
"application/json"
),
};
using (var response = await client.SendAsync(request))
{
response.EnsureSuccessStatusCode();
var body = await response.Content.ReadAsStringAsync();
Console.WriteLine(body);
};
CSHARP
package main
import (
"fmt"
"io"
"net/http"
"strings"
)
func main() {
payload := strings.NewReader(`{
"email": "drsmith@brightsmiledental.com"
}`)
url := "https://api.canva.com/admin/v1/teams/{teamId}/invitations/cancel"
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer {token}")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}
GO
$curl = curl_init();
curl_setopt_array($curl, array(
CURLOPT_URL => "https://api.canva.com/admin/v1/teams/{teamId}/invitations/cancel",
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => array(
'Authorization: Bearer {token}',
'Content-Type: application/json',
),
CURLOPT_POSTFIELDS => json_encode([
"email" => "drsmith@brightsmiledental.com"
])
));
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if (empty($err)) {
echo $response;
} else {
echo "Error: " . $err;
}
PHP
require 'net/http'
require 'uri'
url = URI('https://api.canva.com/admin/v1/teams/{teamId}/invitations/cancel')
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request['Authorization'] = 'Bearer {token}'
request['Content-Type'] = 'application/json'
request.body = <<REQUEST_BODY
{
"email": "drsmith@brightsmiledental.com"
}
REQUEST_BODY
response = http.request(request)
puts response.read_body
RUBY

Success response

If successful, the endpoint returns the status code 204 No content without a response body.

Error responses

400 Bad Request

codestring

A short string indicating what failed. This field can be used to handle errors programmatically. For a complete list of error codes, see Error responses.

messagestring

A human-readable description of what went wrong.

Example error response

The email address is not valid
{
"code": "invalid_field",
"message": "'email' must be a valid email address."
}
JSON

404 Not Found

codestring

A short string indicating what failed. This field can be used to handle errors programmatically. For a complete list of error codes, see Error responses.

messagestring

A human-readable description of what went wrong.

Example error response

The team was not found
{
"code": "team_not_found",
"message": "Team {teamId} not found"
}
JSON