Skip to content
Proud to collaborate with Microsoft for Startups

data.connection.persist ​

Create or restore a CloudConnection and set secrets

Persist a cloud connection: create new or restore soft-deleted.

Input: organization_uuid, provider_type, connection_name, plus auth fields (role_arn, external_ref, account_ref, api_token, etc.) and optional account_info. Output in state_data: connection_uuid, persisted, restored, persisted_at.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-connection
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
organization_uuiduuidYes—UUID of the organization that owns the connection
provider_typestringYes—Cloud provider key (aws, gcp, azure, cloudflare, github, route53, lovable, ...)
connection_namestringNo—Human-friendly name; idempotency key within an organization
actorstringNo—Authenticated caller (Cognito sub or UUID) initiating the persist
account_infodictNo—Provider account metadata returned by test_connection
role_arnstringNo—AWS IAM role ARN to assume
external_refstringNo—External ID for AWS STS:AssumeRole
regionslistNo—AWS regions the connection should cover
regionstringNo—Default region (Azure / single-region providers)
aws_connection_uuiduuidNo—Existing AWS CloudConnection.uuid (Route53 reuse)
zone_modestringNo—Route53 hosted-zone selection mode
zone_refslistNo—Route53 hosted-zone references
api_tokenstringNo—Bearer/API token credential
api_keystringNo—Generic API key credential (OpenAI and compat providers)
organizationstringNo—OpenAI organization slug (optional)
refresh_tokenstringNo—GCP OAuth refresh token (OAuth path)
account_refstringNo—Provider account reference (Cloudflare, etc.)
team_refstringNo—Provider team/organization reference (Vercel)
base_urlstringNo—Self-hosted provider base URL
service_account_jsonjsonNo—GCP service-account key (JSON object)
project_refstringNo—GCP project reference; derived from service_account_json when omitted
tenant_refstringNo—Azure AD tenant reference
tenant_idstringNo—Magalu Cloud project tenant UUID (x-tenant-id)
auth_modestringNo—Magalu auth mode: api_key, oauth, or object_storage
key_pair_idstringNo—Magalu Object Storage key pair ID
key_pair_secretstringNo—Magalu Object Storage key pair secret
client_refstringNo—Azure AD application client reference
client_secretstringNo—Azure AD application secret
subscription_refstringNo—Azure subscription reference
installation_refintegerNo—GitHub App installation reference
access_tokenstringNo—OAuth access token
user_access_tokenstringNo—Long-lived Meta User token for Page/IG discovery
page_access_tokenstringNo—Page access token for the default Meta Page
default_page_refstringNo—Default Meta Page ID for organic publishing
instagram_business_account_refstringNo—Linked Instagram Business Account ID
graph_api_versionstringNo—Meta Graph API version (default v21.0)
pagesjsonNo—Cached Meta Pages + IG refs from sync-assets
organization_refstringNo—LinkedIn organization URN for organic org authoring
organizationsjsonNo—Cached LinkedIn org ACL inventory from sync-assets
conversions_api_keystringNo—OpenAI Ads Conversions API key
pixel_idstringNo—OpenAI Ads default Pixel ID for Conversions API sends
accountjsonNo—Authenticated X user
bot_tokenstringNo—Slack bot token (xoxb-...)
signing_secretstringNo—Slack request signing secret
enterprise_refstringNo—Slack enterprise/team grid reference
bot_user_refstringNo—Slack bot user reference
access_key_refstringNo—Alibaba Cloud access key reference
access_key_secretstringNo—Alibaba Cloud access key secret
auth_methodstringNo—Sentry auth method
tokenstringNo—Sentry auth token
organization_slugstringNo—Sentry organization slug
project_slugstringNo—Sentry project slug
expires_atstringNo—ISO-8601 expiry of the current OAuth access_token
scopestringNo—OAuth scope string granted by the provider
company_refstringNo—Provider-side account/company reference (Bling)
kubernetes_auth_modestringNo—Kubernetes auth mode: static, incluster_service_account, gke_delegated, or eks_delegated
kubernetes_provider_connection_uuiduuidNo—Same-organization GCP/AWS connection for delegated auth
kubernetes_cluster_locationstringNo—Cluster region or location for delegated auth
kubernetes_cluster_namestringNo—Provider cluster name for delegated auth
kubeconfigstringNo—Full kubeconfig YAML
api_serverstringNo—Kubernetes API server URL override
bearer_tokenstringNo—ServiceAccount or static bearer token
ca_certificatestringNo—Cluster CA bundle (PEM)
namespace_defaultstringNo—Default Kubernetes namespace
header_namestringNo—MCP: header to carry the API key
auth_schemestringNo—MCP: Authorization scheme prefix
resource_urlstringNo—MCP: RFC 9728 protected-resource identifier
authorization_serverstringNo—MCP: authorization server issuer
authorize_endpointstringNo—MCP: RFC 8414 authorization endpoint
token_endpointstringNo—MCP: RFC 8414 token endpoint
registration_endpointstringNo—MCP: RFC 7591 DCR endpoint
registered_via_dcrbooleanNo—MCP: client_id was created by DCR
token_expires_atstringNo—MCP: ISO-8601 expiry of the current access token
scopesjsonNo—MCP: granted OAuth scopes
extra_headersjsonNo—MCP: additional static headers
redirect_uristringNo—MCP: primary OAuth callback registered on the DCR client
redirect_urisjsonNo—MCP: all OAuth callbacks registered on the DCR client
dialectstringNo—SQL dialect (postgres v1)
hoststringNo—SQL database hostname or IP
portstringNo—SQL database TCP port
databasestringNo—SQL database / catalog name
ssl_modestringNo—Postgres sslmode
usernamestringNo—SQL database username

Output Schema ​

FieldTypeRequiredDefaultDescription
connection_uuiduuidYes—UUID of the persisted CloudConnection
persistedbooleanYes—True when a row was created or restored in this run
restoredbooleanYes—True when a soft-deleted row was restored
persisted_atstringYes—ISO-8601 timestamp of the persist operation
failure_reasonstringNo—Engine-stamped: human-readable failure reason
failure_typestringNo—Engine-stamped: failure category
failed_actionstringNo—Engine-stamped: action method that raised
failed_at_statestringNo—Engine-stamped: state name when the failure occurred
failed_stepstringNo—Engine-stamped: name of the step that failed (DAG workflows)
failed_layerintegerNo—Engine-stamped: layer index that failed (DAG workflows)
errorstringNo—Engine-stamped: error message on the failure envelope
error_typestringNo—Engine-stamped: exception class name on the failure envelope

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—completePersist connection
completedNoYesYes—Persisted
failedNoYesNo—Persist failed

State Diagram ​

Transitions ​

FromActionToDescription
pendingcompletecompleted—
pendingfailfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "data.connection.persist",
  "initial_data": {
    "organization_uuid": "value",
    "provider_type": "value"
  }
}