Ask an org holding this CRM to invite you
const url = 'https://api.sloose.com/auth/access-requests';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"zohoOrgId":"example","orgId":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.sloose.com/auth/access-requests \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "zohoOrgId": "example", "orgId": "example" }'Made from a CRM tab by a person whose Zoho sign-in proved THIS CRM within the last day (the same test the frame route makes), to an org the frame route names as holding it — through a listed connection it has not disconnected. Anything else is refused without saying why an org is not askable: an unlisted holder and an org that holds nothing answer alike.
One open request per org and address. Asking again finds the open request and sends nothing; a request made now mails each of the org’s owner and administrators once, with one link to People, where approving makes the ordinary invitation at the role chosen there — an operator unless another is. A request lapses after seven days, like an invitation.
Session only. Limited to a handful per session and a few more per CRM an hour (429 RATE_LIMITED, with retryAfterSeconds and Retry-After).
Authorizations
Section titled “Authorizations”Request Bodyrequired
Section titled “Request Bodyrequired”object
The CRM the tab is in, as the widget SDK reports it: its zgid.
The org being asked: one the frame route named as holding this CRM.
Examplegenerated
{ "zohoOrgId": "example", "orgId": "example"}Responses
Section titled “Responses”Already asked: the open request.
object
object
The org asked, as somebody outside it is shown its name: “a team” when the name could be read as Sloose, as an invitation does.
open until an administrator approves it, or it lapses (7 days); approved once the invitation is on its way.
Whether the person is a member of the org now — the invitation accepted — which is what a tab waiting on the request is waiting for.
Example
{ "request": { "status": "open" }}Asked. The administrators have been mailed.
object
object
The org asked, as somebody outside it is shown its name: “a team” when the name could be read as Sloose, as an invitation does.
open until an administrator approves it, or it lapses (7 days); approved once the invitation is on its way.
Whether the person is a member of the org now — the invitation accepted — which is what a tab waiting on the request is waiting for.
Example
{ "request": { "status": "open" }}The request — its body or its query — did not match the schema. issues carries the Zod issue list.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}No bearer, or one that is expired, revoked or no longer resolves to a member.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}The session’s Zoho sign-in has not proved this CRM in the last day (code: CRM_NOT_PROVED): sign in with Zoho, choosing this CRM’s organisation. Or an API token was used (code: SESSION_REQUIRED), or the session is a staff member’s view of an org, which does not act as the person outside it (code: STAFF_VIEW).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}No org this person may ask holds this CRM by that id (code: NOT_ASKABLE) — whether it holds nothing, is closed, or would rather not be named.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}Already a member of that org (code: ALREADY_MEMBER), or an invitation to it is already waiting in their mail (code: ALREADY_INVITED).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}Too many requests (code: RATE_LIMITED, with retryAfterSeconds).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}No administrator could be emailed (code: NOT_DELIVERED): nothing was asked, and asking again tries again.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}