Skip to content
Proud to collaborate with Microsoft for Startups

identity.user.refresh-token ​

Rotate an API token: validate old, generate new, delete old row

Rotate an API token: validate the old token, generate a new one, delete the old row.

Inputs:

  • refresh_token: Old raw API token (required; runtime input)
  • token_name: Name for the new token; defaults to the old token's name (optional)
  • organization_uuid: Unused at rotation time; forwarded to output if present (optional)

Outputs (terminal state_data):

  • new_token: Raw value of the new token — shown exactly once
  • user_uuid: UUID of the token owner (string)
  • rotated_at: ISO-8601 timestamp of rotation

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-identity
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
refresh_tokenstringYes—Old raw API token to rotate
token_namestringNo—Name for the new token (defaults to old token's name)
organization_uuiduuidNo—Forwarded to output if present; not used during rotation

Output Schema ​

FieldTypeRequiredDefaultDescription
new_tokenstringYes—Raw value of the new token — shown exactly once
user_uuiduuidYes—UUID of the token owner (string form)
rotated_atdatetimeYes—ISO-8601 UTC timestamp of rotation
token_namestringNo—Name assigned to the new token
organization_uuiduuidNo—Forwarded from input if provided
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_stepstringNo——
failed_layerstringNo——
errorstringNo——
error_typestringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "identity.user.refresh-token",
  "initial_data": {
    "refresh_token": "value"
  }
}