# Give someone access to the dashboard

`POST https://api.tryscouty.com/v1/team`

Gives an email address access to this brand's dashboard, as the team panel does. They sign in with the Google account on that address. Nothing is emailed to them.

- Scope: `team:manage`
- Kind: write
- Safe to retry with the same idempotency key: yes
- MCP tool: `scouty_add_team_member`

## Authorization

Send `Authorization: Bearer $SCOUTY_TOKEN`. The token needs the `team:manage` scope.

## Headers

| Name | Type | Required | Description |
|---|---|---|---|
| `Idempotency-Key` | `string` | Optional | The same key the body's idempotencyKey carries. Send one or the other, or both with the same value. |

## Body parameters

| Name | Type | Required | Description |
|---|---|---|---|
| `idempotencyKey` | `string` | Required | A key you choose for this call, 8 to 128 characters of letters, digits, dot, underscore, colon or hyphen. Sending the same key with the same arguments replays the first answer and changes nothing, so a retry after a timeout is safe. |
| `email` | `string` | Required | The person's email address. It is the Google account they sign in with. |

## Details

`scouty_add_team_member` gives an email address access to your dashboard. They sign in with the Google account on that address. Scouty emails nobody, so tell them yourself.

```json
{ "status": "added",
  "member": { "email": "alex@glow.example", "addedAt": "2026-09-23T12:00:00.000Z", "isYou": false },
  "note": "They sign in with the Google account on that address. Adding it does not email anybody, so tell them yourself." }
```

## Request

### cURL

```bash
curl -s -X POST https://api.tryscouty.com/v1/team \
  -H "Authorization: Bearer $SCOUTY_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"idempotencyKey":"team-add-alex-1","email":"alex@acme.example"}'
```

### JavaScript

```js
const response = await fetch("https://api.tryscouty.com/v1/team", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${process.env.SCOUTY_TOKEN}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    idempotencyKey: "team-add-alex-1",
    email: "alex@acme.example"
  }),
});
console.log(await response.json());
```

### Python

```python
import os

import requests

token = os.environ["SCOUTY_TOKEN"]
response = requests.post(
    "https://api.tryscouty.com/v1/team",
    headers={"Authorization": f"Bearer {token}"},
    json={
        "idempotencyKey": "team-add-alex-1",
        "email": "alex@acme.example",
    },
)
print(response.json())
```

## Responses

### 200 OK

```json
{
  "status": "added",
  "member": {
    "email": "alex@acme.example",
    "addedAt": "2026-09-26T12:00:00.000Z",
    "isYou": false
  },
  "note": "They sign in with the Google account on that address. Adding it does not email anybody, so tell them yourself."
}
```

### 400 Bad Request

```json
{
  "error": {
    "code": "invalid_request",
    "message": "Those arguments are not the shape this capability takes: idempotencyKey."
  }
}
```

### 401 Unauthorized

```json
{
  "error": {
    "code": "missing_token",
    "message": "This API needs an Authorization header carrying a bearer token."
  }
}
```

### 403 Forbidden

```json
{
  "error": {
    "code": "insufficient_scope",
    "message": "This token does not carry the team:manage scope. Ask the team for one that does."
  }
}
```

### 409 Conflict

```json
{
  "error": {
    "code": "idempotency_conflict",
    "message": "That idempotency key was already used for a different request. Use a new key."
  }
}
```

### 429 Too Many Requests

```json
{
  "error": {
    "code": "rate_limited",
    "message": "Too many requests. Please wait for the current minute to end."
  }
}
```

## Errors

| Status | `error.code` | Meaning |
|---|---|---|
| 400 Bad Request | `invalid_request` | The request was not the shape this capability takes, or its body was not JSON. |
| 401 Unauthorized | `missing_token`, `invalid_token`, `token_revoked`, `token_expired`, `token_orphaned` | No token, or one that is not recognized, revoked or expired. |
| 403 Forbidden | `insufficient_scope`, `wrong_principal` | The token does not carry the scope this capability needs. |
| 409 Conflict | `idempotency_conflict` | That idempotency key was already used for a different request. Nothing was changed. |
| 429 Too Many Requests | `rate_limited` | Too many requests this minute. Retry-After says how long is left. |

Full reference: https://docs.tryscouty.com/reference
