EnroutiaEU

Teams and roles

A project can hold up to 20 people. One owns it, some administer it, the rest use it — and each of them signs in with their own account and their own password, so nobody shares a login to share a bill.

The three roles

Every member of a project has exactly one role. The panel hides what the role cannot do rather than greying it out, and the API answers 403 insufficient_role to anything the role may not call.

RoleMay
ownerEverything: billing, aliases, clients, privacy settings, webhooks, account tokens, every key, the team, deleting the account, and handing the project to somebody else. There is exactly one owner and nobody can remove them.
adminEverything the owner may, except deleting the account and changing who owns it. Admins invite, cancel invitations and remove members; they cannot change a member's role.
memberChat, reports, comparisons, tests, audits and usage. They create and manage their own API keys and see nobody else's. No billing, aliases, clients, privacy settings, webhooks, account tokens or team management.

Ownership moves by transfer: the owner sets somebody's role to owner from the Team screen, and becomes an admin in the same step. Deleting the account is the owner's alone and only once the team is empty (409 team_not_empty).

Invitations

An owner or admin invites by email and picks the role: admin or member. The invitee gets a link to /join that lasts 7 days and works once. With a session it accepts on the spot; without one it sends them through sign-in and brings them back. An address with no account yet goes through signup first and joins when the email is verified.

POST https://api.enroutia.com/api/team/invitations
Cookie: session=…                    # or Authorization: Bearer pat_…

{"email": "colleague@company.com", "role": "member"}

201 {"invitation": {"id": "…", "email": "colleague@company.com",
                    "role": "member", "expires_at": "2026-10-02T09:00:00Z"}}

Inviting an address that is already in the project answers 409 already_member. Accepting with a session whose email is not the one invited answers 403 email_mismatch, and a link older than 7 days answers 410 invitation_expired. Pending invitations can be cancelled from the Team screen until they are accepted.

Keys and who made them

Every key records who created it. A member sees and manages only their own keys; the owner and the admins see all of them. Removing a member does not revoke their keys — the traffic may be a production workflow — so revoke them from Keys if that is what you want.

More than one project

Somebody who belongs to several projects gets a selector at the top of the panel's rail. Switching writes the choice to the session and reloads everything: keys, usage, balance, aliases and the rest all belong to the project that is active. Naming a project — from the Team screen — is what makes the selector readable.

Account tokens and projects

An account token (pat_…) belongs to the person who made it and to the project that was active when they made it. It keeps acting on that project whichever one the person later switches to in the panel, so an agent wired to one project does not follow its owner into another. If the person is removed from that project, the token answers 403 project_access_revoked from then on — it never falls back to another project. Make a token per project if you automate several.

Errors

The five codes that are specific to teams, in the same envelope as every other error.

403 insufficient_role     the role cannot do this; ask an owner or admin
403 email_mismatch        the invitation was sent to another address
409 already_member        nothing to accept: they are in
409 team_not_empty        an account with members cannot be deleted
410 invitation_expired    seven days passed; send a new one

See also: MCP · Budgets · Privacy and aggregated metrics