Redeem an ambassador invitation
Accepts an ambassador invitation for the signed-in account — the path for Google and Apple sign-ups, which cannot carry the token through POST /cognito/signup. The invitation is matched against the account's own registered email address; someone else's token is declined with email_mismatch.
A declined redemption is still a 200 with granted: false and a reason, so a client can always call this after sign-up even when the token was already spent. No special permission is needed.
Authorizations
In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.
Request Body
Responses
Granted, or declined with a reason