Max invitation duration
- Type
- invitation_max_duration
- Category
- Invitations
- Enforced atWhen this policy is checked: while someone tries to open, while they create or change an invitation or hold, or after a denial (notify only).
- Authoring-time
- TiersWhere an admin can set this policy: the whole organization, one integration, or the physical device when the connector supports a device steward.
- OrgIntegrationDevice
- EnforcementHow a configured row behaves. Enforce blocks. Require approval opens an admin inbox when the type supports it. Audit only records and never blocks.
- Enforce
- DefaultWhat happens when no row of this type is configured.
- Not configured — no policy cap on invitation slot length.
Each schedule slot on create or update may last at most max_seconds. The request is rejected rather than silently shortened. The invitation create wizard shows the effective cap.
When it is enforced
Evaluated when someone creates or updates an invitation, hold, or share. Requests that would exceed the limit are rejected — they are not silently rewritten.
Where to set it
Settings → Policies (org), the integration Policies tab, or — on PalGate — the device steward Policies tab.
Policies never grant access. See thepolicies architecture guidefor how org, integration, and device tiers combine.
Arguments
The config object on create/update. Shared row fieldsenforcement (enforce, require_approval,audit_only) and enabled apply to every type;audit_only and disabled rows never block.
| Name | Type | Required | Values | Description |
|---|---|---|---|---|
| max_seconds | integer | Yes | — | Maximum length of each invitation schedule slot in seconds. Must be greater than 0. |
| output | string or integer | No | — | Optional channel or output id. When set, the policy binds only that output. When omitted, it binds every output of the tier target. A scoped row does not apply when the acting output is unknown. |
How overlapping rows combine
Minimum of max_seconds across applicable rows. Reject, do not clamp.
Example
Creating a 48-hour invitation is rejected. A 8-hour slot is accepted.
{ "max_seconds": 86400}Integrations
This type is documented on these connectors:
- Home Assistant (home_assistant)
- KNX (knx)
- MQTT (mqtt)
- PalGate Cloud (palgate_cloud)
- Shelly Cloud (shelly_cloud)
- Shelly Websocket (shelly_websocket)
- Tasmota (tasmota)
- Virtual Access (virtual_access)
- Virtual Demo Devices (virtual_demo)
- Waveshare (waveshare)
Related
- Policy catalog
- Policies architecture guide
- Require invitation expiry (invitation_require_expiry)
- Max invitation uses (invitation_max_uses)
- Invitation curfew (invitation_curfew)
- Max share duration (share_max_duration)
Typed configuration
Section titled “Typed configuration”The OpenAPI contract names this object InvitationMaxDurationPolicyConfig:
{ "max_seconds": 86400, "output": "main"}max_seconds must be positive. Requests exceeding the effective cap are rejected rather than shortened.