Skip to content
Proud to collaborate with Microsoft for Startups

connection.oauth-exchange ​

Exchange an OAuth code for tokens and run connection.setup

Finish a provider OAuth authorization-code flow (code -> tokens -> connection.setup).

Inputs:

  • provider_type: OAuth provider key (gcp, bling, github, aws, ...) (required)
  • code: authorization code the provider returned to the callback (required)
  • state: signed state token from connection.oauth-start (required)
  • organization_uuid: UUID of the org that will own the connection (required)
  • connection_name: optional name for the connection
  • project_ref: GCP project ID to persist with the OAuth connection
  • region: provider region to persist with the OAuth connection
  • tenant_id: Magalu Cloud project tenant UUID (x-tenant-id)
  • redirect_uri: optional callback URL override (must match the start call)

Outputs (terminal state_data):

  • connection_uuid: str # from connection.setup
  • status: str # connection status after setup
  • provider_type: str
  • error: str | None # only on failure

The client SECRET is read ONLY inside this workflow and never returned/logged/stored in state_data; tokens flow straight into connection.setup (encrypted at rest).

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-connection
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
provider_typestringYes—OAuth provider key (gcp, bling, github, aws, ...)
codestringYes—Authorization code returned to the callback
statestringYes—Signed state token from connection.oauth-start
organization_uuiduuidYes—UUID of the org that will own the connection
connection_namestringNo—Optional name for the connection
project_refstringNo—GCP project ID to persist with the OAuth connection
account_refstringNo—Provider account reference to persist with the OAuth connection
team_refstringNo—Provider team reference to persist with the OAuth connection
tenant_refstringNo—Provider tenant reference to persist with the OAuth connection
subscription_refstringNo—Provider subscription reference to persist with the OAuth connection
regionstringNo—Provider region to persist with the OAuth connection
tenant_idstringNo—Magalu Cloud project tenant UUID (x-tenant-id) to persist with the OAuth connection
enterprise_refstringNo—Provider enterprise reference to persist with the OAuth connection
bot_user_refstringNo—Provider bot/user reference to persist with the OAuth connection
default_page_refstringNo—Meta Page ID to pin after organic OAuth grant
instagram_business_account_refstringNo—Instagram Business account ID to pin after organic OAuth grant
channel_refstringNo—YouTube channel ID to pin after organic OAuth grant
organization_refstringNo—Organization reference to pin after OAuth grant (Deere org id or LinkedIn URN)
ad_account_refstringNo—Meta Ads ad account ID (act_…) to pin after Marketing API OAuth grant
redirect_uristringNo—Callback URL override (must match the start call)

Output Schema ​

FieldTypeRequiredDefaultDescription
connection_uuiduuidNo—UUID of the connection created by connection.setup
statusstringNo—Connection status after setup
provider_typestringNo—Echoed provider key
errorstringNo—Error message when exchange failed
failure_reasonstringNo—Engine-stamped failure reason
failure_typestringNo—Engine-stamped failure category
failed_actionstringNo—Engine-stamped action that raised
failed_at_statestringNo—Engine-stamped state name when the workflow failed
failed_stepstringNo—Engine-stamped step name (DAG path)
failed_layerstringNo—Engine-stamped layer index (DAG path)
error_typestringNo—Engine-stamped exception class name

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "connection.oauth-exchange",
  "initial_data": {
    "provider_type": "value",
    "code": "value",
    "state": "value",
    "organization_uuid": "value"
  }
}