appdata.credential.create ​
Create a read-only direct-connection credential (psql, DBeaver, Metabase) for an app
Mint a read-only LOGIN role for direct connections and return its password once.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | App-appdata |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | Authenticated organization UUID |
identity_app_uuid | uuid | Yes | — | Identity app the credential reads; must own an appdata namespace in this organization |
request_id | string | No | — | Caller request id for audit correlation |
actor | string | No | — | — |
label | string | Yes | — | What this credential is for (e.g. 'Metabase prod') |
valid_days | integer | No | — | Expiry in days; default 90, max 365 |
connection_limit | integer | No | — | Concurrent connections; default 5, max 20 |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | — |
identity_app_uuid | uuid | Yes | — | — |
credential_uuid | uuid | No | — | — |
role_name | string | No | — | The Postgres login role; joins to pg_stat_activity.usename |
label | string | No | — | — |
connection_limit | integer | No | — | — |
valid_until | string | No | — | — |
created_at | string | No | — | — |
last_rotated_at | string | No | — | — |
revoked_at | string | No | — | — |
host | string | No | — | — |
port | string | No | — | — |
database | string | No | — | — |
sslmode | string | No | — | 'require' until the identity-aware gateway offers verify-full |
dsn | string | No | — | Connection string with the password redacted; pair it with token |
token | string | No | — | The password. Returned exactly once, never stored; this is the only output the secret contract reveals |
failure_reason | string | No | — | Engine-stamped failure reason |
failed_at_state | string | No | — | State when the workflow failed |
failed_step | string | No | — | Failed DAG step name |
failed_layer | integer | No | — | Failed DAG layer index |
error | string | No | — | Engine-stamped exception message |
error_type | string | No | — | Engine-stamped exception class name |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | complete | Create credential |
completed | No | Yes | Yes | — | Credential created |
failed | No | Yes | No | — | Create failed |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | complete | completed | — |
pending | fail | failed | — |
Outcomes ​
| Outcome | Type | Description | State Data Keys |
|---|---|---|---|
created | SUCCESS | Create a read-only direct-connection credential (psql, DBeaver, Metabase) for an app | credential_uuid, role_name |
failed | FAILURE | Appdata workflow failed | failure_reason |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "appdata.credential.create",
"initial_data": {
"organization_uuid": "value",
"identity_app_uuid": "value",
"label": "value"
}
}