Control
`GET /v1/control/invitations/{token}`: what this invitation is for.
Unauthenticated by necessity - the invitee has no account yet. It reveals
only the address the invitation was already sent to and the role it grants,
and an unknown token is a flat 404 rather than anything that would let
somebody probe for live tokens.
Errors
Returns 404 for a token that is unknown, expired or already used - the
same answer for each, so this cannot be used to probe for live tokens -
and 503 when the invitation store cannot be read.
GET
`GET /v1/control/invitations/{token}`: what this invitation is for.

