> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developers.awork.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developers.awork.com/_mcp/server.

# Login & Access

> Login & Access API Reference.

![awork permissions and access illustration](/_fern-img/23ccad9115afa164cc7f289d5188a662a48954b8b9da37920537a3e5926d3bc3.webp)

The Login & Access endpoints help you identify the current account, invite workspace members, and inspect the roles and permissions that control API access. Use the [Authentication guide](/authentication) to obtain the Bearer token before calling these endpoints.

## Inspecting the current user's access

Start with `GET /me/permissions` to discover the features available to the authenticated user. This is useful for integrations that enable or hide functionality based on workspace permissions:

**`Get current user permissions`**

```sh title="Get current user permissions"
curl 'https://api.awork.com/api/v1/me/permissions' \
  -H 'Authorization: Bearer {token}'
```

To identify the user and workspace the token belongs to, call `GET /users/me`:

**`Get current user and workspace`**

```sh title="Get current user and workspace"
curl 'https://api.awork.com/api/v1/users/me' \
  -H 'Authorization: Bearer {token}'
```

**`Response`**

```json title="Response"
{
  "id": "123e4567-e89b-12d3-a456-426614174000",
  "workspace": {
    "id": "223e4567-e89b-12d3-a456-426614174001",
    "name": "Northstar Creative",
    "url": "https://northstar.awork.com"
  }
}
```

## Inviting a workspace member

Invitations are one of the few API calls that require an explicit `workspaceId`. Get that id from `/users/me`, then provide the role that the new member should receive:

**`Invite a user`**

```sh title="Invite a user"
curl -X POST 'https://api.awork.com/api/v1/invitations' \
  -H 'Authorization: Bearer {token}' \
  -H 'Content-Type: application/json' \
  -d '{
    "email": "carla.creative@example.com",
    "invitationFlow": "invite",
    "workspaceId": "223e4567-e89b-12d3-a456-426614174001",
    "roleId": "323e4567-e89b-12d3-a456-426614174002"
  }'
```

The caller must have permission to invite users. Use `GET /roles` to list valid role ids before creating the invitation. The recipient completes the process with the invitation link; integrations do not need to handle the acceptance request themselves.

Learn more about awork's [permission management](https://support.awork.com/en/articles/permissions-management-in-awork-qVeVCScCl9db).