Skip to content
OpenAppPhysical access, simplified
Login

Require invitation identity

Type
invitation_require_identity
Category
Invitations
Enforced at
Authoring-time
Tiers
OrgIntegrationDevice
Enforcement
EnforceRequire approval
Default
Not configured — PIN, photo, and verified phone are optional.

Each flag is combined with OR across applicable rows (any true flag wins). Create and update reject the request when a required field is missing — they do not clamp. Photo means a host-attached media slot named photo. PIN is 4–8 digits and is stored hashed on the invite. Phone OTP is scoped to that invite. At redemption, missing PIN, photo, or verified phone still blocks the open. Mixed enforce and require_approval rows: enforce wins for blocking; require_approval can still open the inbox when the type is authored that way.

When it is enforced

Evaluated when someone creates or updates an invitation, hold, or share. Requests that would exceed the limit are rejected — they are not silently rewritten.

Where to set it

Settings → Policies (org), the integration Policies tab, or — on PalGate — the device steward Policies tab.

Policies never grant access. See thepolicies architecture guidefor how org, integration, and device tiers combine.

Arguments

The config object on create/update. Shared row fieldsenforcement (enforce, require_approval,audit_only) and enabled apply to every type;audit_only and disabled rows never block.

NameTypeRequiredValuesDescription
require_pinbooleanNoWhen true, the host must set a 4–8 digit PIN (hashed on the invite).
require_photobooleanNoWhen true, the host must attach a photo media slot named photo.
require_verified_phonebooleanNoWhen true, the host must supply an invitee phone and the guest must complete invite-scoped OTP before use.
outputstring or integerNoOptional channel or output id. When set, the policy binds only that output. When omitted, it binds every output of the tier target. A scoped row does not apply when the acting output is unknown.

How overlapping rows combine

Most-restrictive: boolean OR of each flag across applicable rows. Disabled and audit_only rows never block. Reject missing identity, do not clamp.

Example

Creating an invitation without a PIN or invitee phone is rejected. A guest who has not verified the phone cannot redeem the link.

config
{
"require_pin": true,
"require_photo": false,
"require_verified_phone": true
}

Integrations

This type is documented on these connectors:

The OpenAPI contract names this object InvitationIdentityPolicyConfig:

{
"require_pin": true,
"require_photo": false,
"require_verified_phone": true,
"output": "main"
}

At least one requirement must be true. Applicable rows combine each flag with logical OR; missing required invitation identity is rejected rather than silently omitted.