appdata.credential.revoke ​
Revoke a direct-connection credential, terminating its sessions
Drop the role. Live sessions are terminated first; the catalog row stays, marked revoked.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | App-appdata |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | Authenticated organization UUID |
identity_app_uuid | uuid | Yes | — | Identity app the credential reads; must own an appdata namespace in this organization |
request_id | string | No | — | Caller request id for audit correlation |
actor | string | No | — | — |
credential_uuid | uuid | Yes | — | — |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | — |
identity_app_uuid | uuid | Yes | — | — |
credential_uuid | uuid | No | — | — |
role_name | string | No | — | The Postgres login role; joins to pg_stat_activity.usename |
label | string | No | — | — |
connection_limit | integer | No | — | — |
valid_until | string | No | — | — |
created_at | string | No | — | — |
last_rotated_at | string | No | — | — |
revoked_at | string | No | — | — |
terminated_sessions | integer | No | — | — |
failure_reason | string | No | — | Engine-stamped failure reason |
failed_at_state | string | No | — | State when the workflow failed |
failed_step | string | No | — | Failed DAG step name |
failed_layer | integer | No | — | Failed DAG layer index |
error | string | No | — | Engine-stamped exception message |
error_type | string | No | — | Engine-stamped exception class name |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | complete | Revoke credential |
completed | No | Yes | Yes | — | Credential revoked |
failed | No | Yes | No | — | Revoke failed |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | complete | completed | — |
pending | fail | failed | — |
Outcomes ​
| Outcome | Type | Description | State Data Keys |
|---|---|---|---|
revoked | SUCCESS | Revoke a direct-connection credential, terminating its sessions | credential_uuid |
failed | FAILURE | Appdata workflow failed | failure_reason |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "appdata.credential.revoke",
"initial_data": {
"organization_uuid": "value",
"identity_app_uuid": "value",
"credential_uuid": "value"
}
}