Called by the console's callback page as the person who started the sign-in, with the state and code the provider sent back (or its error). Exchanges the code with the PKCE verifier, seals the tokens (never answered), runs the connector's test and answers the connection with its label, granted scopes, token_expires_at and external_id. A workspace the account already connected is updated, not connected twice. The state works once.
Needs scope connections:write.
bearerAuthorizationBearer <token>An access token from the identity provider: a person's, or a customer's from the client credentials grant with an API key (docs.inorbit.hr). The gateway verifies it; the audience is iohr-api.
org_id*stringThe account's id: org in GET /v1/me.
iohr.connections.v1.CompleteConnectRequest; path variables override their fields
application/json- body
iohr.connections.v1.CompleteConnectRequest
code?stringerror?stringerror_description?stringorg_id?stringstate?stringiohr.connections.v1.CompleteConnectResponse
application/json- response
iohr.connections.v1.CompleteConnectResponse
connection?iohr.connections.v1.Connection
import { ApiError, Public } from "@inorbithr/sdk";// Reads INORBIT_TOKEN, or INORBIT_KEY_ID and INORBIT_KEY_SECRET.const api = Public.fromEnv();try { const { value } = await api.connections.completeConnect("<org_id>", { code: "<code>", error: "<error>", error_description: "<error_description>", state: "<state>", }); console.log(value);} catch (e) { if (!(e instanceof ApiError)) throw e; console.error(`${e.code}: ${e.problem} (request id ${e.raw.requestId})`);}npm install @inorbithr/sdk. Calls the package's public surface; an operation newer than your package needs the next release or a client generated for your account. The SDKs.
{ "connection": { "account_id": "string", "auth_mode": "string", "config": { "property1": "string", "property2": "string" }, "connector": "string", "created_at": "string", "credential": { "kind": "string", "reference": "string", "set_at": "string" }, "description": "string", "executor": { "agent_id": "string", "kind": "string" }, "external_id": "string", "grants": 0, "id": "string", "kind": "string", "label": "string", "last_test_at": "string", "last_test_error": "string", "last_test_ok": true, "name": "string", "owner": "string", "receive_url": "string", "scopes": [ "string" ], "status": "string", "token_expires_at": "string", "updated_at": "string", "used_by": [ "string" ] }}Start signing in to a provider POST
Connect an account by signing in at the provider (OAuth 2.0, RFC 0044): makes a single-use sign-in for you, valid ten minutes, with its own state and PKCE verifier, and answers `authorize_url` to open in a browser, `session_id` and `expires_at`. The provider sends you back to the console's `/connections/callback/` page, which completes it. `scopes` adds any of the mode's `optional_scopes`; `config` holds settings needed before signing in; `connection_id` reconnects that connection. A connector whose OAuth app is not set up on this platform is `needs_app` and refused. Needs scope `connections:write`.
Get a sign-in GET
Where a sign-in stands, for a command line waiting on the browser: `pending`, `completed` (with the connection), `failed` (with why) or `expired`. Only the person who started it may read it. Needs scope `connections:read`.