Skip to content

Members and roles

View Markdown
Role Can
Owner Everything, including granting or removing the Owner role
Admin Everything except the Owner role: members, invites, projects, API keys, service accounts, billing
Member Create and manage work: jobs, sandboxes, volumes, secrets, their own API keys
Viewer Read everything, change nothing

nodus auth can-i create jobs asks the server whether you hold a permission.

Terminal window
nodus create invite --email ada@example.com --role Member

The invite link works for 72 hours and only once. The invitee signs in with that email address (it must be verified) and accepts it in the console, where pending invites also appear as a banner. You can invite up to your seat limit, 10 members by default; pending invites count as seats. An invite nobody accepts stays under Team › Invites after it expires, marked Expired and holding no seat, so you can resend it. Once your org has bought credits, an Owner or Admin can change the seat limit under Team › Members › Change, up to 1,000. When an invite is accepted, or someone is made an Admin or Owner, every Owner and Admin gets an email.

Terminal window
nodus get invites
nodus request resend invite/inv-01j9abc # a fresh link, at most 3 times, 10 minutes apart
nodus delete invite inv-01j9abc

You can invite someone with a role up to your own: Admins invite Admins, Members and Viewers; only Owners invite Owners.

An Owner or Admin adds your company’s email domain under Team › Company domains, then adds the TXT record shown there at your DNS provider and selects Verify. After that, anyone who signs up with a verified email at that domain is offered your org during sign-up and joins it as a Member in one click. Seats still apply, public mailbox domains such as gmail.com are refused, and a domain belongs to one org at a time. Remove the domain to stop new joins; people who already joined stay members. Someone you remove from the org can only come back through an invite.

Terminal window
nodus get members
nodus edit member usr-01j9abc --role Admin

An org always keeps at least one Owner: demoting or removing the last Owner is refused with 409 Conflict.

Terminal window
nodus delete member usr-01j9abc
nodus delete member usr-<your-id> # leave an org yourself

Removing a member revokes their API keys and third-party app access in that org at once. Keys bound to a service account keep working, so CI does not break when the person who set it up leaves.