Skip to content
Proud to collaborate with Microsoft for Startups

identity.app.provision ​

Provision an identity tenant for a customer app

Provision an identity tenant for a customer app ("Sign in with Orkestia").

ONE-CALL SETUP (no human, no follow-up): pass your app's redirect_uris here and this returns everything needed to wire auth — client_key (public, goes in your app source), plus integration with the authorize/token/jwks endpoints. An MCP agent can call this and immediately wire a PKCE "Sign in with Orkestia" flow.

Inputs:

  • actor: Cognito sub or user UUID (auto-injected from your token)
  • organization_uuid: owning organization (auto-injected from your token)
  • name: human-readable app name (required)
  • redirect_uris: your app's OAuth callback URLs, e.g. ["https://myapp.com/callback"] (optional but recommended — absolute http(s), no wildcards; registering them here means the origin is accepted immediately, no configure-client call needed)
  • project_uuid: the customer project this tenant serves (optional)

Outputs (terminal state_data):

  • client_key: public OIDC client identifier (no secret — PKCE only); put this in your app
  • client_uuid: the OIDC client's uuid (for later identity.app.configure-client calls)
  • redirect_uris: the registered callback URLs
  • identity_app_uuid: public uuid of the identity tenant
  • integration:
  • name, created_at

Overview ​

PropertyValue
Workflow typeLinear
LibraryApp-identity
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
actorstringYes—Authenticated Cognito subject or user UUID provisioning the app.
organization_uuiduuidYes—Organization that will own the identity app.
namestringYes—Human-readable name for the identity app.
project_uuiduuidNo—Optional customer project served by this identity app.
redirect_urislistNo—OAuth callback URLs allowed for the hosted PKCE login flow.
modestringNo—App lifecycle mode controlling redirect and sign-in policy.
dev_allowed_emailslistNo—Email allowlist used while the identity app is in dev mode.
org_owned_enabledbooleanNoFalseWhether organization-owned end-user accounts are enabled.

Output Schema ​

FieldTypeRequiredDefaultDescription
identity_app_uuiduuidYes—Public UUID of the provisioned identity app.
client_uuiduuidNo—UUID of the initial public OIDC client.
client_keystringYes—Public PKCE OIDC client identifier; this is not a secret.
redirect_urislistNo—OAuth callback URLs registered for the client.
namestringYes—Human-readable identity app name.
created_atstringYes—ISO-8601 creation timestamp.
integrationdictNo—Hosted-login endpoints, flow, and SDK integration settings.
actorstringNo—Authenticated principal that provisioned the app.
organization_uuiduuidNo—Organization that owns the identity app.
project_uuiduuidNo—Customer project served by the identity app, when supplied.
failure_reasonstringNo—Human-readable explanation when provisioning fails.
failure_typestringNo—Stable category for a provisioning failure.
failed_actionstringNo—Action that failed during provisioning.
failed_at_statestringNo—Workflow state in which provisioning failed.

States ​

StateInitialTerminalSuccessAuto-advanceDescription
initiatedYesNo—validate—
persistingNoNo—complete—
validatingNoNo—persist—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
initiatedvalidatevalidating—
validatingpersistpersisting—
persistingcompletecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "identity.app.provision",
  "initial_data": {
    "actor": "value",
    "organization_uuid": "value",
    "name": "value"
  }
}