Identity ​
| Workflow | Type | Description |
|---|---|---|
| identity.api-token.create | Linear | Generate a new API token for the current user |
| identity.api-token.query | Atomic | List API tokens for the current user |
| identity.api-token.revoke | Atomic | Revoke (hard-delete) an API token for the current user |
| identity.api-token.rotate | Atomic | Rotate an API token by replacement (new UUID, old UUID revoked) |
| identity.api-token.update | Atomic | Rename an API token belonging to the current user |
| identity.app-organization.add-member | Atomic | Add an end-user to a workspace with a role (active membership) |
| identity.app-organization.assign-role | Atomic | Set or change a member's workspace role |
| identity.app-organization.create | Atomic | Create an app-organization (workspace) inside an identity app |
| identity.app-organization.invite | Atomic | Invite an end-user to a workspace with a role (pending membership) |
| identity.app-organization.query | Atomic | List the app-organizations (workspaces) for an identity app |
| identity.app.add-federation | Linear | Register an upstream identity provider (SSO) for an app |
| identity.app.allow-dev-origin | Atomic | Allow a localhost development origin for an identity app client |
| identity.app.configure-client | Linear | Configure an app's OIDC client (safe-by-default validation) |
| identity.app.deprovision | Linear | Deprovision an identity app and invalidate app-owned identity state |
| identity.app.expose-virtual-workflow | Atomic | Expose a virtual workflow to an app's end-users (eligibility-checked) |
| identity.app.provision | Linear | Provision an identity tenant for a customer app |
| identity.app.query | Atomic | List an organization's identity apps (or one app's detail) |
| identity.app.reconcile-catalog | Atomic | Backfill the capability catalog from an app's exposed compositions |
| identity.app.set-branding | Atomic | Set per-app end-user email HTML and display branding |
| identity.app.set-dev-emails | Atomic | Replace the dev-mode end-user email allowlist on an identity app |
| identity.app.set-email-domains | Atomic | Restrict end-user sign-in on a live identity app to an email-domain allowlist |
| identity.app.set-end-user-agent | Atomic | Write a single scalar AgentConfig pointer on one Identity App; two products need two Identity Apps |
| identity.app.set-mode | Atomic | Graduate an identity app from dev to live (one-way, irreversible) |
| identity.app.set-org-owned | Atomic | Toggle an identity app's org-owned appdata authorization flag |
| identity.app.set-workflow-eligibility | Atomic | Mark a workflow type end-user eligible for this app (or withdraw it) |
| identity.app.unexpose-virtual-workflow | Atomic | Revoke a virtual workflow's exposure to an app's end-users |
| identity.app.workflow-eligibility-query | Atomic | List the workflow types this app marked end-user eligible |
| identity.composition.audience-query | Atomic | Read which access groups may invoke an exposed composition |
| identity.composition.set-audience | Atomic | Set which access groups may invoke an exposed composition |
| identity.end-user.actor-binding.get | Atomic | Read a Staff actor's end-user binding in an app and its eligibility |
| identity.end-user.actor-binding.list | Atomic | List Staff-actor end-user bindings across the organization's identity apps |
| identity.end-user.actor-binding.reconcile | Atomic | Suspend Staff-actor end-user bindings that no longer pass eligibility (scheduled sweep) |
| identity.end-user.actor-binding.suspend | Atomic | Suspend a Staff actor's ineligible end-user bindings (internal lifecycle hook) |
| identity.end-user.admit | Atomic | Login-time seat gate: admit/deny an end-user and seat them |
| identity.end-user.assign-group | Atomic | Assign an end-user to a single access group within an app |
| identity.end-user.audit-query | Atomic | Read the end-user auth audit trail for an organization |
| identity.end-user.bind-actor | Atomic | Bind a Staff actor to an end-user seat of an identity app (human admin only) |
| identity.end-user.continuation.issue | Atomic | Issue a single-use grant to finish one piece of work as the calling end-user |
| identity.end-user.continuation.redeem | Atomic | Spend a continuation grant and resolve the end-user principal to run as |
| identity.end-user.continuation.revoke | Atomic | Revoke an unspent continuation grant |
| identity.end-user.create | Linear | Register an end-user for a customer app |
| identity.end-user.delete | Linear | Soft-delete an end-user for a customer app (frees the seat) |
| identity.end-user.disable | Linear | Disable an end-user for a customer app (frees the seat) |
| identity.end-user.group.define | Atomic | Create or rename a custom end-user access group |
| identity.end-user.group.list | Atomic | List an app's access groups with capabilities |
| identity.end-user.group.seed-defaults | Atomic | Seed the default end-user access groups for an app |
| identity.end-user.group.set-capabilities | Atomic | Replace a group's capability set |
| identity.end-user.invite | Linear | Mail an admin-provisioned end-user their access to an app |
| identity.end-user.member-seat.assign | Atomic | Seat another member of your organization in one of its identity apps (org admins) |
| identity.end-user.member-seat.assume | Atomic | Take an end-user seat of your organization's identity app, as yourself (org members) |
| identity.end-user.member-seat.list | Atomic | List org-member end-user seats (members see their own, admins see all) |
| identity.end-user.member-seat.reconcile | Atomic | Suspend org-member end-user seats whose member left the organization (sweep) |
| identity.end-user.member-seat.release | Atomic | Release an org member's end-user seat in an identity app (self, or org admins for others) |
| identity.end-user.organization.get | Atomic | Get details for one workspace the current end-user belongs to |
| identity.end-user.organization.invite-member | Atomic | Invite a person into the current end-user's active workspace |
| identity.end-user.organization.query | Atomic | List the workspaces the current end-user is a member of |
| identity.end-user.organization.switch | Atomic | Set the current end-user's active workspace |
| identity.end-user.purge | Linear | Hard-purge a previously soft-deleted end-user |
| identity.end-user.query | Atomic | List end-users for an app's identity tenant (paged) |
| identity.end-user.session.revoke | Linear | Revoke all of an end-user's current sessions (force re-login) |
| identity.end-user.unbind-actor | Atomic | Unbind a Staff actor from its end-user seat in an identity app (human admin only) |
| identity.end-user.whoami | Atomic | Return the calling end-user's identity |
| identity.key.bind | Atomic | Bind a key to a consumer (apphost_site, identity_app, custom) |
| identity.key.create | Linear | Generate a signing keypair for the current organization |
| identity.key.ensure | Atomic | Idempotent service key for a consumer binding; returns public_key only |
| identity.key.get | Atomic | Get one signing key (public metadata only) |
| identity.key.import | Atomic | Import an existing private key; public key is derived; private is never returned |
| identity.key.materialize | Atomic | Decrypt a private key for a trusted consumer; never log it |
| identity.key.query | Atomic | List signing keys for the organization (public metadata only) |
| identity.key.reveal | Atomic | Admin reveal of a private key when policy allows; once or never |
| identity.key.revoke | Atomic | Revoke a signing key and scrub its ciphertext |
| identity.key.rotate | Atomic | Replace a key: mint new, retire old, keep label |
| identity.key.unbind | Atomic | Remove a key binding |
| identity.membership.get | Atomic | Fetch a single membership by UUID, tenant-verified |
| identity.membership.query | Atomic | List active memberships for an organization |
| identity.membership.query-by-org | Atomic | Return user profiles with role for all active members of an organization |
| identity.membership.query-by-user | Atomic | Return organizations a specific user belongs to with their role |
| identity.membership.remove | Atomic | Remove a member from an organization |
| identity.membership.update-role | Atomic | Change a member's role in an organization |
| identity.notification-pref.create | Atomic | Create a notification preference for the current user + org |
| identity.notification-pref.get | Atomic | Fetch a single notification preference by UUID, ownership-verified |
| identity.notification-pref.query | Atomic | List active notification preferences for the authenticated user |
| identity.notification-pref.update | Atomic | Update the current user's notification preferences |
| identity.org-invitation.accept | Linear | Accept an organization invitation by token |
| identity.org-invitation.cancel | Atomic | Cancel / revoke a pending organization invitation |
| identity.org-invitation.create | Linear | Send an organization invitation by email |
| identity.org-invitation.decline | Atomic | Recipient declines a pending organization invitation |
| identity.org-invitation.query | Atomic | List organization invitations (pending by default) |
| identity.org-invitation.resend | Atomic | Re-send a pending organization invitation |
| identity.org-invitation.reveal-link | Atomic | Reveal the acceptance link for a pending organization invitation |
| identity.organization.get | Atomic | Fetch a single organization by UUID, membership-verified |
| identity.organization.query | Atomic | List organizations the authenticated user is a member of |
| identity.seat.grant | Linear | Grant a batch of end-user seats to an app (raises the cap) |
| identity.seat.status | Atomic | Report end-user seat usage (cap / consumed / free) for an app |
| identity.user.delete | Atomic | Request account deletion — sends email to ops; does not delete |
| identity.user.exists-by-email | Atomic | Report whether a platform account exists for an email address |
| identity.user.get | Atomic | Fetch a single user by UUID, verified as an org member |
| identity.user.query | Atomic | List users belonging to an organization |
| identity.user.refresh-token | Atomic | Rotate an API token: validate old, generate new, delete old row |
| identity.user.update | Atomic | Update the current user's profile (name, username, avatar_url) |
| identity.user.validate-token | Atomic | Validate a raw API token and return the associated user profile |
| identity.user.whoami | Atomic | Resolve actor to user profile and organization memberships |
