data.connection.persist ​
Create or restore a CloudConnection and set secrets
Persist a cloud connection: create new or restore soft-deleted.
Input: organization_uuid, provider_type, connection_name, plus auth fields (role_arn, external_ref, account_ref, api_token, etc.) and optional account_info. Output in state_data: connection_uuid, persisted, restored, persisted_at.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | App-connection |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
organization_uuid | uuid | Yes | — | UUID of the organization that owns the connection |
provider_type | string | Yes | — | Cloud provider key (aws, gcp, azure, cloudflare, github, route53, lovable, ...) |
connection_name | string | No | — | Human-friendly name; idempotency key within an organization |
actor | string | No | — | Authenticated caller (Cognito sub or UUID) initiating the persist |
account_info | dict | No | — | Provider account metadata returned by test_connection |
role_arn | string | No | — | AWS IAM role ARN to assume |
external_ref | string | No | — | External ID for AWS STS:AssumeRole |
regions | list | No | — | AWS regions the connection should cover |
region | string | No | — | Default region (Azure / single-region providers) |
aws_connection_uuid | uuid | No | — | Existing AWS CloudConnection.uuid (Route53 reuse) |
zone_mode | string | No | — | Route53 hosted-zone selection mode |
zone_refs | list | No | — | Route53 hosted-zone references |
api_token | string | No | — | Bearer/API token credential |
api_key | string | No | — | Generic API key credential (OpenAI and compat providers) |
organization | string | No | — | OpenAI organization slug (optional) |
refresh_token | string | No | — | GCP OAuth refresh token (OAuth path) |
account_ref | string | No | — | Provider account reference (Cloudflare, etc.) |
team_ref | string | No | — | Provider team/organization reference (Vercel) |
base_url | string | No | — | Self-hosted provider base URL |
service_account_json | json | No | — | GCP service-account key (JSON object) |
project_ref | string | No | — | GCP project reference; derived from service_account_json when omitted |
tenant_ref | string | No | — | Azure AD tenant reference |
tenant_id | string | No | — | Magalu Cloud project tenant UUID (x-tenant-id) |
auth_mode | string | No | — | Magalu auth mode: api_key, oauth, or object_storage |
key_pair_id | string | No | — | Magalu Object Storage key pair ID |
key_pair_secret | string | No | — | Magalu Object Storage key pair secret |
client_ref | string | No | — | Azure AD application client reference |
client_secret | string | No | — | Azure AD application secret |
subscription_ref | string | No | — | Azure subscription reference |
installation_ref | integer | No | — | GitHub App installation reference |
access_token | string | No | — | OAuth access token |
user_access_token | string | No | — | Long-lived Meta User token for Page/IG discovery |
page_access_token | string | No | — | Page access token for the default Meta Page |
default_page_ref | string | No | — | Default Meta Page ID for organic publishing |
instagram_business_account_ref | string | No | — | Linked Instagram Business Account ID |
graph_api_version | string | No | — | Meta Graph API version (default v21.0) |
pages | json | No | — | Cached Meta Pages + IG refs from sync-assets |
organization_ref | string | No | — | LinkedIn organization URN for organic org authoring |
organizations | json | No | — | Cached LinkedIn org ACL inventory from sync-assets |
conversions_api_key | string | No | — | OpenAI Ads Conversions API key |
pixel_id | string | No | — | OpenAI Ads default Pixel ID for Conversions API sends |
account | json | No | — | Authenticated X user |
bot_token | string | No | — | Slack bot token (xoxb-...) |
signing_secret | string | No | — | Slack request signing secret |
enterprise_ref | string | No | — | Slack enterprise/team grid reference |
bot_user_ref | string | No | — | Slack bot user reference |
access_key_ref | string | No | — | Alibaba Cloud access key reference |
access_key_secret | string | No | — | Alibaba Cloud access key secret |
auth_method | string | No | — | Sentry auth method |
token | string | No | — | Sentry auth token |
organization_slug | string | No | — | Sentry organization slug |
project_slug | string | No | — | Sentry project slug |
expires_at | string | No | — | ISO-8601 expiry of the current OAuth access_token |
scope | string | No | — | OAuth scope string granted by the provider |
company_ref | string | No | — | Provider-side account/company reference (Bling) |
kubernetes_auth_mode | string | No | — | Kubernetes auth mode: static, incluster_service_account, gke_delegated, or eks_delegated |
kubernetes_provider_connection_uuid | uuid | No | — | Same-organization GCP/AWS connection for delegated auth |
kubernetes_cluster_location | string | No | — | Cluster region or location for delegated auth |
kubernetes_cluster_name | string | No | — | Provider cluster name for delegated auth |
kubeconfig | string | No | — | Full kubeconfig YAML |
api_server | string | No | — | Kubernetes API server URL override |
bearer_token | string | No | — | ServiceAccount or static bearer token |
ca_certificate | string | No | — | Cluster CA bundle (PEM) |
namespace_default | string | No | — | Default Kubernetes namespace |
header_name | string | No | — | MCP: header to carry the API key |
auth_scheme | string | No | — | MCP: Authorization scheme prefix |
resource_url | string | No | — | MCP: RFC 9728 protected-resource identifier |
authorization_server | string | No | — | MCP: authorization server issuer |
authorize_endpoint | string | No | — | MCP: RFC 8414 authorization endpoint |
token_endpoint | string | No | — | MCP: RFC 8414 token endpoint |
registration_endpoint | string | No | — | MCP: RFC 7591 DCR endpoint |
registered_via_dcr | boolean | No | — | MCP: client_id was created by DCR |
token_expires_at | string | No | — | MCP: ISO-8601 expiry of the current access token |
scopes | json | No | — | MCP: granted OAuth scopes |
extra_headers | json | No | — | MCP: additional static headers |
redirect_uri | string | No | — | MCP: primary OAuth callback registered on the DCR client |
redirect_uris | json | No | — | MCP: all OAuth callbacks registered on the DCR client |
dialect | string | No | — | SQL dialect (postgres v1) |
host | string | No | — | SQL database hostname or IP |
port | string | No | — | SQL database TCP port |
database | string | No | — | SQL database / catalog name |
ssl_mode | string | No | — | Postgres sslmode |
username | string | No | — | SQL database username |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
connection_uuid | uuid | Yes | — | UUID of the persisted CloudConnection |
persisted | boolean | Yes | — | True when a row was created or restored in this run |
restored | boolean | Yes | — | True when a soft-deleted row was restored |
persisted_at | string | Yes | — | ISO-8601 timestamp of the persist operation |
failure_reason | string | No | — | Engine-stamped: human-readable failure reason |
failure_type | string | No | — | Engine-stamped: failure category |
failed_action | string | No | — | Engine-stamped: action method that raised |
failed_at_state | string | No | — | Engine-stamped: state name when the failure occurred |
failed_step | string | No | — | Engine-stamped: name of the step that failed (DAG workflows) |
failed_layer | integer | No | — | Engine-stamped: layer index that failed (DAG workflows) |
error | string | No | — | Engine-stamped: error message on the failure envelope |
error_type | string | No | — | Engine-stamped: exception class name on the failure envelope |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | complete | Persist connection |
completed | No | Yes | Yes | — | Persisted |
failed | No | Yes | No | — | Persist failed |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | complete | completed | — |
pending | fail | failed | — |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "data.connection.persist",
"initial_data": {
"organization_uuid": "value",
"provider_type": "value"
}
}