## Organizations and Member Invitations

Organizations can allow new Members to join via **explicit email invitation** or [just-in-time (JIT) provisioning](/content/docs/multi-tenant-auth/enterprise-ready/org-management/jit-provision-members/index.html). The right solution depends on the Organization’s use case:

- To reduce friction to joining an Organization, JIT provisioning is a simple way to ensure that new Members are added to their company’s Organization as soon as they authenticate.
- If admins of your product need more control over who gets access to their Organization, they may want to restrict to email invites, or JIT provisioning by a specific OAuth tenant.

Often, the right solution will vary by Organization. To learn about how to enable Organizations to manage their own provisioning settings, see the [Admin Portal](/content/docs/multi-tenant-auth/enterprise-ready/admin-portal/index.html) guide.

## Inviting Members via email

Enable **inviting Members via email** to allow Organization Members to invite new Members to the Organization via email invitation. Using the [Update Organization](/content/docs/api-reference/b2b/api/organizations/update-organization/index.html) endpoint:

- Set [`email_invites`](/content/docs/api-reference/b2b/api/organizations/update-organization#body-email-invites/index.html) to either:
  - `RESTRICTED` to allow specific email domains to be invited to the Organization
  - `ALL_ALLOWED` to allow any email domain to be invited to the Organization
- If `RESTRICTED`, specify which email domains should be allowed with [`email_allowed_domains`](/content/docs/api-reference/b2b/api/organizations/update-organization#body-email-allowed-domains/index.html).

### cURL

```bash
curl --request PUT \
  --url https://api.stytch.com/v1/b2b/organizations/{organization_id} \
  --header 'Authorization: Basic <encoded-value>' \
  --header 'Content-Type: application/json' \
  --data '{
    "email_invites": "RESTRICTED",
    "email_allowed_domains": ["companyname.com"]
  }'
```

### Python

```python
client.organizations.update(
  organization_id="organization-test-07971b06-ac8b-4cdb-9c15-63b17e653931",
  email_invites="RESTRICTED",
  email_allowed_domains=["companyname.com"],
)
```

### Javascript

```javascript
client.organizations.update({
  organization_id: "organization-test-07971b06-ac8b-4cdb-9c15-63b17e653931",
  email_invites: "RESTRICTED",
  email_allowed_domains: ["companyname.com"],
})
```

### Disallowed common email domains

Stytch disallows setting certain common email domains on the `email_allowed_domains` array:

- `gmail`
- `aol`
- `yahoo`
- `icloud`
- `hotmail`
- `msn`
- `comcast`
- `live`
- `outlook`
- `att`
- `earthlink`
- `me`
- `mac`
- `sbcglobal`
- `verizon`
- `ig`
- `mail`
- `hey`
- `laposte`
- `wanadoo`
- `googlemail`
- `orange`
- `rediffmail`
- `uol`
- `bol`
- `free`
- `gmx`
- `yandex`
- `ymail`
- `libero`
