# Invitations and member keys

> How to add a person to an organization with a one-time link, and how they connect their agent with their own key.

By the end of this page you will be able to:

1. invite a person to your organization;
2. help them issue their own key and connect an agent;
3. revoke a key if a laptop is lost or a key leaks.

Example: Northwind's admin David invites Ben (ben@northwind.example) to the Backend unit as a Member.

## Invitation

1. David switches to the organization and opens People → "Invite a person".

2. He fills in the email, the unit and the role. He leaves "Access term, days" empty — it is meant for [contractors](/organizations/contractors/).

3. He clicks "Create invitation". The account shows an invitation link like `https://app.mmwhub.tech/invite?token=…` with a "Copy" button.

4. David sends the link to Ben **himself**, in a work chat or by email. MMW does not send invitation emails.

5. Ben opens the link, signs in (or signs up) **with the same email**, verifies it and clicks "Accept invitation". The account says "You joined the organization", and Northwind appears in his space switcher.

Link properties:

| Property | Value |
|---|---|
| Lifetime | 7 days from creation |
| Uses | One: once accepted, the link stops working |
| For whom | Only the specified email |
| Storage | The link is shown once; the server keeps only a hash of the token |
| Revocation | The admin clicks "Revoke" in the Invitations list while it is still pending |

Each link in Invitations shows a status: pending, accepted or revoked. Only the admin can invite, list and revoke invitations.

The link lets whoever signs in with that email into the organization. Pass it to that person only. If it went to the wrong place, revoke it and create a new one.

### If an invitation does not work

| Message | Cause | What to do |
|---|---|---|
| "Invitation not found, already used or expired." | 7 days passed, the link was revoked or already accepted | The admin creates a new invitation |
| "This invitation was issued for another email." | The person signed in with a different email | Sign out and sign in with the invited email |
| "Verify your email first." | Email not verified | Use the link from the email; if none arrived, click "Send the email again" on the Organizations page |
| "You are already a member of this organization." | Already a member | Nothing to do |

## A member's key

Every person issues a key **for themselves**. The admin cannot issue a key on someone else's behalf.

1. Ben switches to Northwind and opens the Keys tab.

2. Under "My keys" he enters a name such as "work laptop" and clicks "Issue key".

3. The account shows the `mmw_…` key **once**: "The key is shown once. Copy it into your MCP client settings now."

4. Ben connects his agent with this key, exactly as with a personal key — see [Connect a client](/clients/overview/).

```bash
claude mcp add mmw-northwind \
  -e MMW_API_KEY=mmw_organization_key \
  -e MMW_ENDPOINT=https://mcp.mmwhub.tech \
  -- uvx --from https://app.mmwhub.tech/downloads/mmw-agent/mmw_agent-0.1.4-py3-none-any.whl mmw-agent
```

```json title="mcpServers"
{
  "mcpServers": {
    "mmw-northwind": {
      "url": "https://mcp.mmwhub.tech/mcp",
      "headers": { "Authorization": "Bearer mmw_organization_key" }
    }
  }
}
```

An organization key works only with that organization's memory; a personal key works only with personal memory. If you need both, add two servers with different names, for example `mmw` and `mmw-northwind`.

Until the organization is activated, an agent using an organization key is refused. An auditor cannot issue a key: they only get the audit log.

## What the admin sees

On the Keys tab the admin sees "Organization keys": each key's name, owner and status, and can revoke any of them. But the admin **cannot** see the secret of someone else's key or reissue it: otherwise the admin could act in memory as that person, and the audit log and record authorship would mean nothing.

| | Key owner | Admin | Others |
|---|---|---|---|
| Issue | for themselves | for themselves only | — |
| See the secret | once, when issued | no | no |
| See in the list | own keys | every key in the organization | — |
| Revoke | own keys | any | — |

Revocation takes effect immediately: the next agent call with that key is refused. The member issues a new key themselves.

## Next steps
