identity.user.refresh-token ​
Rotate an API token: validate old, generate new, delete old row
Rotate an API token: validate the old token, generate a new one, delete the old row.
Inputs:
- refresh_token: Old raw API token (required; runtime input)
- token_name: Name for the new token; defaults to the old token's name (optional)
- organization_uuid: Unused at rotation time; forwarded to output if present (optional)
Outputs (terminal state_data):
- new_token: Raw value of the new token — shown exactly once
- user_uuid: UUID of the token owner (string)
- rotated_at: ISO-8601 timestamp of rotation
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | App-identity |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
refresh_token | string | Yes | — | Old raw API token to rotate |
token_name | string | No | — | Name for the new token (defaults to old token's name) |
organization_uuid | uuid | No | — | Forwarded to output if present; not used during rotation |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
new_token | string | Yes | — | Raw value of the new token — shown exactly once |
user_uuid | uuid | Yes | — | UUID of the token owner (string form) |
rotated_at | datetime | Yes | — | ISO-8601 UTC timestamp of rotation |
token_name | string | No | — | Name assigned to the new token |
organization_uuid | uuid | No | — | Forwarded from input if provided |
failure_reason | string | No | — | — |
failure_type | string | No | — | — |
failed_action | string | No | — | — |
failed_at_state | string | No | — | — |
failed_step | string | No | — | — |
failed_layer | string | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | execute | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | execute | completed | — |
* (any state) | fail | failed | — |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "identity.user.refresh-token",
"initial_data": {
"refresh_token": "value"
}
}