Add a connection. An endpoint on our cloud takes its key in secret, sealed in the vault and never answered; on an agent it takes secret_ref (vault:, k8s:, env: or file:), which we never resolve. A webhook-in answers its signing secret once, in webhook_secret, and its receive_url. Our cloud calls only hosts inside a verified domain of the account. A connector's id as kind (List connectors) takes auth_mode, credentials (its fields, sealed, never answered) and config; its test request runs first, a refused key stores nothing, and label names the account at the provider.
Needs scope connections:write.
bearerAuthorizationBearer <token>An access token from the identity provider: a person's, or a customer's from the client credentials grant with an API key (docs.inorbit.hr). The gateway verifies it; the audience is iohr-api.
org_id*stringThe account's id: org in GET /v1/me.
idempotency-key?stringMakes a retry safe: a repeat with the same key and the same body within a day answers what the first call did (with Idempotency-Replayed: true) instead of running again; the same key with another body is 422 unprocessable. 1 to 255 visible characters; a UUID is a good one.
1 <= length <= 255iohr.connections.v1.CreateConnectionRequest; path variables override their fields
application/json- body
iohr.connections.v1.CreateConnectionRequest
auth_mode?stringconfig?credentials?description?stringexecutor?iohr.connections.v1.Executor
kind?stringname?stringorg_id?stringsecret?stringsecret_ref?stringiohr.connections.v1.CreateConnectionResponse
application/json- response
iohr.connections.v1.CreateConnectionResponse
connection?iohr.connections.v1.Connection
webhook_secret*stringimport { ApiError, Public } from "@inorbithr/sdk";// Reads INORBIT_TOKEN, or INORBIT_KEY_ID and INORBIT_KEY_SECRET.const api = Public.fromEnv();try { const { value } = await api.connections.createConnection("<org_id>", { auth_mode: "<auth_mode>", description: "<description>", kind: "<kind>", name: "<name>", }); console.log(value);} catch (e) { if (!(e instanceof ApiError)) throw e; console.error(`${e.code}: ${e.problem} (request id ${e.raw.requestId})`);}npm install @inorbithr/sdk. Calls the package's public surface; an operation newer than your package needs the next release or a client generated for your account. The SDKs.
{ "connection": { "account_id": "string", "auth_mode": "string", "config": { "property1": "string", "property2": "string" }, "connector": "string", "created_at": "string", "credential": { "kind": "string", "reference": "string", "set_at": "string" }, "description": "string", "executor": { "agent_id": "string", "kind": "string" }, "external_id": "string", "grants": 0, "id": "string", "kind": "string", "label": "string", "last_test_at": "string", "last_test_error": "string", "last_test_ok": true, "name": "string", "owner": "string", "receive_url": "string", "scopes": [ "string" ], "status": "string", "token_expires_at": "string", "updated_at": "string", "used_by": [ "string" ] }, "webhook_secret": "string"}List connections GET
The account's connections, newest first: kind, executor (`cloud` or an agent), configuration, what kind of credential it holds (never the credential), status, last test and live grants. Needs scope `connections:read`.
Start signing in to a provider POST
Connect an account by signing in at the provider (OAuth 2.0, RFC 0044): makes a single-use sign-in for you, valid ten minutes, with its own state and PKCE verifier, and answers `authorize_url` to open in a browser, `session_id` and `expires_at`. The provider sends you back to the console's `/connections/callback/` page, which completes it. `scopes` adds any of the mode's `optional_scopes`; `config` holds settings needed before signing in; `connection_id` reconnects that connection. A connector whose OAuth app is not set up on this platform is `needs_app` and refused. Needs scope `connections:write`.