Skip to content
Proud to collaborate with Microsoft for Startups

connection.oauth-start ​

Begin a provider OAuth authorization-code flow (returns authorize URL + state)

Begin a provider OAuth 2.0 authorization-code flow.

Inputs:

  • provider_type: OAuth provider key (gcp, bling, github, aws, ...) (required)
  • organization_uuid: UUID of the org that will own the connection (required)
  • connection_name: optional name to carry through to setup
  • project_ref: GCP project ID to persist with the OAuth connection
  • region: provider region to persist with the OAuth connection
  • tenant_id: Magalu Cloud project tenant UUID (x-tenant-id)
  • redirect_uri: optional callback URL override (else the platform default)

Outputs (terminal state_data):

  • provider_type: str
  • project_ref: str | None
  • region: str | None
  • tenant_id: str | None
  • authorization_url: str # provider consent URL to redirect the user to
  • state: str # signed CSRF/state token, verified on exchange
  • expires_at: str # ISO-8601 expiry of the state token
  • error: str | None # only on failure

No client secret is involved — only the public client_id / redirect_uri / scopes.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-connection
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
provider_typestringYes—OAuth provider key (gcp, bling, github, aws, ...)
organization_uuiduuidYes—UUID of the org that will own the connection
connection_namestringNo—Optional name carried through to connection.setup
project_refstringNo—GCP project ID to persist with the OAuth connection
account_refstringNo—Provider account reference to persist with the OAuth connection
team_refstringNo—Provider team reference to persist with the OAuth connection
tenant_refstringNo—Provider tenant reference to persist with the OAuth connection
subscription_refstringNo—Provider subscription reference to persist with the OAuth connection
regionstringNo—Provider region to persist with the OAuth connection
tenant_idstringNo—Magalu Cloud project tenant UUID (x-tenant-id) to persist with the OAuth connection
enterprise_refstringNo—Provider enterprise reference to persist with the OAuth connection
bot_user_refstringNo—Provider bot/user reference to persist with the OAuth connection
default_page_refstringNo—Meta Page ID to pin after organic OAuth grant
instagram_business_account_refstringNo—Instagram Business account ID to pin after organic OAuth grant
channel_refstringNo—YouTube channel ID to pin after organic OAuth grant
organization_refstringNo—LinkedIn organization URN to pin after organic OAuth grant
ad_account_refstringNo—Meta Ads ad account ID (act_…) to pin after Marketing API OAuth grant
redirect_uristringNo—Callback URL override; else the platform default
connection_uuiduuidNo—Existing connection whose discovered OAuth endpoints drive the flow. Required for providers that resolve their authorization server per connection (mcp).

Output Schema ​

FieldTypeRequiredDefaultDescription
provider_typestringNo—Echoed provider key
organization_uuiduuidNo—Echoed organization UUID
connection_namestringNo—Echoed connection name carried to exchange
redirect_uristringNo—Echoed redirect URI used to build the authorize URL
connection_uuiduuidNo—Echoed connection whose endpoints drove the flow (dynamic providers)
project_refstringNo—GCP project ID to persist with the OAuth connection
account_refstringNo—Provider account reference to persist with the OAuth connection
team_refstringNo—Provider team reference to persist with the OAuth connection
tenant_refstringNo—Provider tenant reference to persist with the OAuth connection
subscription_refstringNo—Provider subscription reference to persist with the OAuth connection
regionstringNo—Provider region to persist with the OAuth connection
tenant_idstringNo—Magalu Cloud project tenant UUID (x-tenant-id) to persist with the OAuth connection
enterprise_refstringNo—Provider enterprise reference to persist with the OAuth connection
bot_user_refstringNo—Provider bot/user reference to persist with the OAuth connection
default_page_refstringNo—Meta Page ID to pin after organic OAuth grant
instagram_business_account_refstringNo—Instagram Business account ID to pin after organic OAuth grant
channel_refstringNo—YouTube channel ID to pin after organic OAuth grant
organization_refstringNo—LinkedIn organization URN to pin after organic OAuth grant
ad_account_refstringNo—Meta Ads ad account ID (act_…) to pin after Marketing API OAuth grant
authorization_urlstringNo—Provider consent URL to redirect the user to
statestringNo—Signed state token (CSRF; verified on exchange)
expires_atstringNo—ISO-8601 expiry of the state token
errorstringNo—Error message when start failed
failure_reasonstringNo—Engine-stamped failure reason
failure_typestringNo—Engine-stamped failure category
failed_actionstringNo—Engine-stamped action that raised
failed_at_statestringNo—Engine-stamped state name when the workflow failed
failed_stepstringNo—Engine-stamped step name (DAG path)
failed_layerstringNo—Engine-stamped layer index (DAG path)
error_typestringNo—Engine-stamped exception class name

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "connection.oauth-start",
  "initial_data": {
    "provider_type": "value",
    "organization_uuid": "value"
  }
}