概要
Casdoor supports invitation-based registration. When an administrator makes the invitation code required on the sign-up page, only users with a valid invitation code can register.

Invitation codes can be a random string (default) or a regular expression that matches multiple codes.

Invitation properties
Each invitation has:
- Organization — Organization that owns the invitation
- Name — Unique invitation name
- Display name — Label shown in the UI
- Code — The invitation code (literal string or regex)
- Default code — Value used in the invitation link. For random codes it matches the code; for regex, you must set a value that matches the regex
- Quota — Maximum number of uses
- Used count — Current use count
- Application — Applications that can use this code;
ALL= all apps in the organization. Shared applications get organization-specific handling - Username / Email / Phone — Optional fixed values required when registering with this invitation
- Expire time — Optional time after which the code is rejected, in RFC 3339 format (e.g.
2026-12-31T23:59:59+08:00). Empty means the invitation never expires - State — Invitation status (e.g. active, suspended)
Default invitation
By default, the code is a random alphanumeric string and Quota is 1 (single use). Application is ALL (all apps in the organization).

To tie an invitation to a specific user, set Username, Email, or Phone. If those fields are empty or not shown on the sign-up form, Casdoor does not enforce them.