Skip to content
Proud to collaborate with Microsoft for Startups

identity.end-user.admit ​

Login-time seat gate: admit/deny an end-user and seat them

Login-time seat gate: decide whether an end-user may sign in, and seat them.

Inputs:

  • identity_app_uuid: the app's identity tenant (required)
  • email: the end-user's email (required)
  • external_sub: Cognito sub to bind on first login (optional)
  • actor: the calling principal (optional)

Outputs (terminal state_data):

  • admitted (bool), reason, created, end_user_uuid, seated, cap, consumed, free

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-identity
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
identity_app_uuiduuidYes——
emailstringYes——
external_substringNo——
actorstringNo——

Output Schema ​

FieldTypeRequiredDefaultDescription
admittedbooleanYes——
reasonstringYes——
createdbooleanNo——
end_user_uuiduuidNo——
seatedbooleanNo——
capintegerNo——
consumedintegerNo——
freeintegerNo——
identity_app_uuiduuidNo——
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "identity.end-user.admit",
  "initial_data": {
    "identity_app_uuid": "value",
    "email": "value"
  }
}