Skip to content
Proud to collaborate with Microsoft for Startups

appdata.credential.create ​

Create a read-only direct-connection credential (psql, DBeaver, Metabase) for an app

Mint a read-only LOGIN role for direct connections and return its password once.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-appdata
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes—Authenticated organization UUID
identity_app_uuiduuidYes—Identity app the credential reads; must own an appdata namespace in this organization
request_idstringNo—Caller request id for audit correlation
actorstringNo——
labelstringYes—What this credential is for (e.g. 'Metabase prod')
valid_daysintegerNo—Expiry in days; default 90, max 365
connection_limitintegerNo—Concurrent connections; default 5, max 20

Output Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes——
identity_app_uuiduuidYes——
credential_uuiduuidNo——
role_namestringNo—The Postgres login role; joins to pg_stat_activity.usename
labelstringNo——
connection_limitintegerNo——
valid_untilstringNo——
created_atstringNo——
last_rotated_atstringNo——
revoked_atstringNo——
hoststringNo——
portstringNo——
databasestringNo——
sslmodestringNo—'require' until the identity-aware gateway offers verify-full
dsnstringNo—Connection string with the password redacted; pair it with token
tokenstringNo—The password. Returned exactly once, never stored; this is the only output the secret contract reveals
failure_reasonstringNo—Engine-stamped failure reason
failed_at_statestringNo—State when the workflow failed
failed_stepstringNo—Failed DAG step name
failed_layerintegerNo—Failed DAG layer index
errorstringNo—Engine-stamped exception message
error_typestringNo—Engine-stamped exception class name

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—completeCreate credential
completedNoYesYes—Credential created
failedNoYesNo—Create failed

State Diagram ​

Transitions ​

FromActionToDescription
pendingcompletecompleted—
pendingfailfailed—

Outcomes ​

OutcomeTypeDescriptionState Data Keys
createdSUCCESSCreate a read-only direct-connection credential (psql, DBeaver, Metabase) for an appcredential_uuid, role_name
failedFAILUREAppdata workflow failedfailure_reason

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "appdata.credential.create",
  "initial_data": {
    "organization_uuid": "value",
    "identity_app_uuid": "value",
    "label": "value"
  }
}