Skip to content
Proud to collaborate with Microsoft for Startups

appdata.credential.revoke ​

Revoke a direct-connection credential, terminating its sessions

Drop the role. Live sessions are terminated first; the catalog row stays, marked revoked.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-appdata
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes—Authenticated organization UUID
identity_app_uuiduuidYes—Identity app the credential reads; must own an appdata namespace in this organization
request_idstringNo—Caller request id for audit correlation
actorstringNo——
credential_uuiduuidYes——

Output Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes——
identity_app_uuiduuidYes——
credential_uuiduuidNo——
role_namestringNo—The Postgres login role; joins to pg_stat_activity.usename
labelstringNo——
connection_limitintegerNo——
valid_untilstringNo——
created_atstringNo——
last_rotated_atstringNo——
revoked_atstringNo——
terminated_sessionsintegerNo——
failure_reasonstringNo—Engine-stamped failure reason
failed_at_statestringNo—State when the workflow failed
failed_stepstringNo—Failed DAG step name
failed_layerintegerNo—Failed DAG layer index
errorstringNo—Engine-stamped exception message
error_typestringNo—Engine-stamped exception class name

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—completeRevoke credential
completedNoYesYes—Credential revoked
failedNoYesNo—Revoke failed

State Diagram ​

Transitions ​

FromActionToDescription
pendingcompletecompleted—
pendingfailfailed—

Outcomes ​

OutcomeTypeDescriptionState Data Keys
revokedSUCCESSRevoke a direct-connection credential, terminating its sessionscredential_uuid
failedFAILUREAppdata workflow failedfailure_reason

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "appdata.credential.revoke",
  "initial_data": {
    "organization_uuid": "value",
    "identity_app_uuid": "value",
    "credential_uuid": "value"
  }
}