Product help
Give every vendor a clear private workspace
Product team · Reviewed
title: Vendor portals, access codes and private file exchange description: Share the right wedding records, inspect each invitation, reuse permission presets and collect private contributions.
Open a wedding and choose Collaboration. Create a private invitation for a vendor, helper or couple. This lightweight invitation does not require an account and never adds a paid seat. Anyone who possesses the link, and its separate code when enabled, has its selected access. Use named workspace or day-of access when the work requires an individually accountable account rather than a bearer invitation.
Give each invitation a useful scope
Select tasks, timeline moments and private documents from this wedding. Read access and write access are separate: allow task completion, completion of selected timeline moments, reading team updates, replying to those updates, and contributing private files independently. Couple portals keep timeline execution read-only. Reading the full timeline never grants completion of every moment; only selected moments can be changed.
Team updates are a wedding-wide conversation. Every invitation allowed to read updates can see that conversation. Do not put private client notes or financial information there. Turning off reading also turns off replies. Private business CRM records, rates, invoices, guest contact details and unselected files never appear in the portal.
Only ready documents in private storage are selectable. A portal downloads the document's current revision, after checking current invitation access, selected document IDs and asset status. Replacing a document changes what that invitation can download next; archiving it stops portal downloads. Executed agreement archives and other isolated originals are not exposed through this document picker.
Choose Preview this access to inspect the invitation's actual current projection, including tasks, timeline, files and conversation visibility. This owner preview is read-only and does not create an unlocked guest session or issue a private-link secret.
Codes, expiration and recovery
Optional access codes require at least eight characters and are retained only as salted hashes. Send a code separately from the invitation link. Successful entry creates a private, HTTP-only session lasting at most 24 hours and never beyond the invitation's expiration. Ten failed or successful code attempts per invitation per 15-minute window are allowed; excessive attempts require waiting for the next window.
Changing permissions or replacing/removing a code invalidates previously unlocked sessions. Replacing a private link immediately invalidates the old link and its sessions. Revocation ends access. Previously revoked invitations cannot be restored; create a new one. Updating an active or expired invitation explicitly sets a new expiration between one and 365 days from saving.
New and replacement link secrets appear once. Mutation receipts retain the result ID and revision, not the link secret or access code. If the response was lost, a retry cannot recover the secret; use Replace private link to issue a new one. Keep codes out of notes, email subjects and shared screenshots.
Reusable permission presets
Save a preset from the invitation editor, then apply it at another wedding. A preset contains role, expiry duration and permissions only. It never copies people, task IDs, moment IDs, documents, codes or private links. Presets are versioned within the business. Updating or archiving a preset does not silently change invitations already issued from it.
Receive and review files
Enable Contribute private files for review for the chosen invitation. A contributor can upload a PDF, JPEG or PNG up to 8 MB. Each invitation allows 20 active contributions and 80 MB total. Original checksums and a stable upload request protect retries from changing the original file. The host must have private storage, media usage pricing and an enrolled allowance; no guest contribution automatically enrolls the host in spending.
Contributions are private to their invitation and the owning business. The manager can download, accept, reject or remove them. Acceptance keeps the original with its contributor; it does not publish it or add it to the general wedding document library. A rejected contribution stops the contributor's download but remains available to the manager for review. Removal stops access immediately and queues object deletion. Up to 200 recent contributions appear in the review screen.
If an upload is interrupted, retry the same original before choosing another file. A pending contribution can also be removed by the manager. Provider confirmation and cleanup retain their own receipts; an upload error never means a document was safely delivered.
Reference links and frozen questionnaires
Under References and vendor questionnaires, enable reference-link contributions for a specific invitation and select up to ten published questionnaires from Forms. This permission is separate from file upload and team messaging. Only public HTTPS viewing links without embedded usernames or passwords are accepted. The application does not retrieve the destination, execute HTML or import remote contents.
Each questionnaire assignment retains its exact published definition and hash. Changing the business form later cannot change an existing assignment or its prior answers. Remove an assignment to end new responses, or explicitly select a newer published version. Conditional visibility and required/type/choice rules use the same validated form engine. Contributors review their answers before sending; hidden and unknown answers are discarded by the server.
Links and completed questionnaires appear in the owner's review queue and in that invitation's submission history. Accept, reject or request changes with feedback visible to the contributor. A correction creates another retained submission; review history and original answers remain intact. Each invitation allows up to 100 link/questionnaire submissions combined. Retrying the same request returns its existing result and does not duplicate the submission.
Questionnaire responses stay within the wedding invitation. They never silently become a lead, overwrite client information, send a message or start an automation. All submissions recheck the active invitation and current contribution settings; revocation ends read and submission access. Prior submissions remain available to the business after invitation expiry.
Add an entrance to your business website
An owner or administrator can enable a branded portal entrance and approve up to ten exact HTTPS website origins. Copy the iframe snippet to an approved website. The entrance asks for an existing invitation link and optional code, then opens the private portal in a new tab. It does not create an account or display wedding data inside an external page. Private portal pages prohibit framing. Disabling the entrance stops the launcher without revoking individual invitations.
The entrance uses the business's reviewed public name, tagline and accent. The private portal uses its approved public letterhead and attribution preferences. Arbitrary HTML or scripts are not supported.
API and activation
/api/v1/vendor-portals exposes the same management services to a named account session with X-Workspace-Id. The account must be a currently authorized full business operator; entrance settings require owner or admin. Generic API keys cannot manage these personal invitation sessions. Grant and preset writes use request UUIDs and revision checks; revision conflicts require reviewing the current record.
During coordinated setup, verify private storage, media pricing and usage caps, first-party application URL, secure cookies, upload limits, allowed embedding origins and content-security headers. Rehearse changed permissions, replacement links, expired codes, revoked invitations and interrupted uploads against the configured deployment. Existing private links remain usable with their original permissions and no added code until explicitly changed.