Skip to content
Proud to collaborate with Microsoft for Startups

Identity ​

WorkflowTypeDescription
identity.api-token.createLinearGenerate a new API token for the current user
identity.api-token.queryAtomicList API tokens for the current user
identity.api-token.revokeAtomicRevoke (hard-delete) an API token for the current user
identity.api-token.rotateAtomicRotate an API token by replacement (new UUID, old UUID revoked)
identity.api-token.updateAtomicRename an API token belonging to the current user
identity.app-organization.add-memberAtomicAdd an end-user to a workspace with a role (active membership)
identity.app-organization.assign-roleAtomicSet or change a member's workspace role
identity.app-organization.createAtomicCreate an app-organization (workspace) inside an identity app
identity.app-organization.inviteAtomicInvite an end-user to a workspace with a role (pending membership)
identity.app-organization.queryAtomicList the app-organizations (workspaces) for an identity app
identity.app.add-federationLinearRegister an upstream identity provider (SSO) for an app
identity.app.allow-dev-originAtomicAllow a localhost development origin for an identity app client
identity.app.configure-clientLinearConfigure an app's OIDC client (safe-by-default validation)
identity.app.deprovisionLinearDeprovision an identity app and invalidate app-owned identity state
identity.app.expose-virtual-workflowAtomicExpose a virtual workflow to an app's end-users (eligibility-checked)
identity.app.provisionLinearProvision an identity tenant for a customer app
identity.app.queryAtomicList an organization's identity apps (or one app's detail)
identity.app.reconcile-catalogAtomicBackfill the capability catalog from an app's exposed compositions
identity.app.set-brandingAtomicSet per-app end-user email HTML and display branding
identity.app.set-dev-emailsAtomicReplace the dev-mode end-user email allowlist on an identity app
identity.app.set-email-domainsAtomicRestrict end-user sign-in on a live identity app to an email-domain allowlist
identity.app.set-end-user-agentAtomicWrite a single scalar AgentConfig pointer on one Identity App; two products need two Identity Apps
identity.app.set-modeAtomicGraduate an identity app from dev to live (one-way, irreversible)
identity.app.set-org-ownedAtomicToggle an identity app's org-owned appdata authorization flag
identity.app.set-workflow-eligibilityAtomicMark a workflow type end-user eligible for this app (or withdraw it)
identity.app.unexpose-virtual-workflowAtomicRevoke a virtual workflow's exposure to an app's end-users
identity.app.workflow-eligibility-queryAtomicList the workflow types this app marked end-user eligible
identity.composition.audience-queryAtomicRead which access groups may invoke an exposed composition
identity.composition.set-audienceAtomicSet which access groups may invoke an exposed composition
identity.end-user.actor-binding.getAtomicRead a Staff actor's end-user binding in an app and its eligibility
identity.end-user.actor-binding.listAtomicList Staff-actor end-user bindings across the organization's identity apps
identity.end-user.actor-binding.reconcileAtomicSuspend Staff-actor end-user bindings that no longer pass eligibility (scheduled sweep)
identity.end-user.actor-binding.suspendAtomicSuspend a Staff actor's ineligible end-user bindings (internal lifecycle hook)
identity.end-user.admitAtomicLogin-time seat gate: admit/deny an end-user and seat them
identity.end-user.assign-groupAtomicAssign an end-user to a single access group within an app
identity.end-user.audit-queryAtomicRead the end-user auth audit trail for an organization
identity.end-user.bind-actorAtomicBind a Staff actor to an end-user seat of an identity app (human admin only)
identity.end-user.continuation.issueAtomicIssue a single-use grant to finish one piece of work as the calling end-user
identity.end-user.continuation.redeemAtomicSpend a continuation grant and resolve the end-user principal to run as
identity.end-user.continuation.revokeAtomicRevoke an unspent continuation grant
identity.end-user.createLinearRegister an end-user for a customer app
identity.end-user.deleteLinearSoft-delete an end-user for a customer app (frees the seat)
identity.end-user.disableLinearDisable an end-user for a customer app (frees the seat)
identity.end-user.group.defineAtomicCreate or rename a custom end-user access group
identity.end-user.group.listAtomicList an app's access groups with capabilities
identity.end-user.group.seed-defaultsAtomicSeed the default end-user access groups for an app
identity.end-user.group.set-capabilitiesAtomicReplace a group's capability set
identity.end-user.inviteLinearMail an admin-provisioned end-user their access to an app
identity.end-user.member-seat.assignAtomicSeat another member of your organization in one of its identity apps (org admins)
identity.end-user.member-seat.assumeAtomicTake an end-user seat of your organization's identity app, as yourself (org members)
identity.end-user.member-seat.listAtomicList org-member end-user seats (members see their own, admins see all)
identity.end-user.member-seat.reconcileAtomicSuspend org-member end-user seats whose member left the organization (sweep)
identity.end-user.member-seat.releaseAtomicRelease an org member's end-user seat in an identity app (self, or org admins for others)
identity.end-user.organization.getAtomicGet details for one workspace the current end-user belongs to
identity.end-user.organization.invite-memberAtomicInvite a person into the current end-user's active workspace
identity.end-user.organization.queryAtomicList the workspaces the current end-user is a member of
identity.end-user.organization.switchAtomicSet the current end-user's active workspace
identity.end-user.purgeLinearHard-purge a previously soft-deleted end-user
identity.end-user.queryAtomicList end-users for an app's identity tenant (paged)
identity.end-user.session.revokeLinearRevoke all of an end-user's current sessions (force re-login)
identity.end-user.unbind-actorAtomicUnbind a Staff actor from its end-user seat in an identity app (human admin only)
identity.end-user.whoamiAtomicReturn the calling end-user's identity
identity.key.bindAtomicBind a key to a consumer (apphost_site, identity_app, custom)
identity.key.createLinearGenerate a signing keypair for the current organization
identity.key.ensureAtomicIdempotent service key for a consumer binding; returns public_key only
identity.key.getAtomicGet one signing key (public metadata only)
identity.key.importAtomicImport an existing private key; public key is derived; private is never returned
identity.key.materializeAtomicDecrypt a private key for a trusted consumer; never log it
identity.key.queryAtomicList signing keys for the organization (public metadata only)
identity.key.revealAtomicAdmin reveal of a private key when policy allows; once or never
identity.key.revokeAtomicRevoke a signing key and scrub its ciphertext
identity.key.rotateAtomicReplace a key: mint new, retire old, keep label
identity.key.unbindAtomicRemove a key binding
identity.membership.getAtomicFetch a single membership by UUID, tenant-verified
identity.membership.queryAtomicList active memberships for an organization
identity.membership.query-by-orgAtomicReturn user profiles with role for all active members of an organization
identity.membership.query-by-userAtomicReturn organizations a specific user belongs to with their role
identity.membership.removeAtomicRemove a member from an organization
identity.membership.update-roleAtomicChange a member's role in an organization
identity.notification-pref.createAtomicCreate a notification preference for the current user + org
identity.notification-pref.getAtomicFetch a single notification preference by UUID, ownership-verified
identity.notification-pref.queryAtomicList active notification preferences for the authenticated user
identity.notification-pref.updateAtomicUpdate the current user's notification preferences
identity.org-invitation.acceptLinearAccept an organization invitation by token
identity.org-invitation.cancelAtomicCancel / revoke a pending organization invitation
identity.org-invitation.createLinearSend an organization invitation by email
identity.org-invitation.declineAtomicRecipient declines a pending organization invitation
identity.org-invitation.queryAtomicList organization invitations (pending by default)
identity.org-invitation.resendAtomicRe-send a pending organization invitation
identity.org-invitation.reveal-linkAtomicReveal the acceptance link for a pending organization invitation
identity.organization.getAtomicFetch a single organization by UUID, membership-verified
identity.organization.queryAtomicList organizations the authenticated user is a member of
identity.seat.grantLinearGrant a batch of end-user seats to an app (raises the cap)
identity.seat.statusAtomicReport end-user seat usage (cap / consumed / free) for an app
identity.user.deleteAtomicRequest account deletion — sends email to ops; does not delete
identity.user.exists-by-emailAtomicReport whether a platform account exists for an email address
identity.user.getAtomicFetch a single user by UUID, verified as an org member
identity.user.queryAtomicList users belonging to an organization
identity.user.refresh-tokenAtomicRotate an API token: validate old, generate new, delete old row
identity.user.updateAtomicUpdate the current user's profile (name, username, avatar_url)
identity.user.validate-tokenAtomicValidate a raw API token and return the associated user profile
identity.user.whoamiAtomicResolve actor to user profile and organization memberships