Connect an account by signing in at the provider (OAuth 2.0, RFC 0044): makes a single-use sign-in for you, valid ten minutes, with its own state and PKCE verifier, and answers authorize_url to open in a browser, session_id and expires_at. The provider sends you back to the console's /connections/callback/ page, which completes it. scopes adds any of the mode's optional_scopes; config holds settings needed before signing in; connection_id reconnects that connection. A connector whose OAuth app is not set up on this platform is needs_app and refused.
Needs scope connections:write.
bearerAuthorizationBearer <token>An access token from the identity provider: a person's, or a customer's from the client credentials grant with an API key (docs.inorbit.hr). The gateway verifies it; the audience is iohr-api.
org_id*stringThe account's id: org in GET /v1/me.
iohr.connections.v1.StartConnectRequest; path variables override their fields
application/json- body
iohr.connections.v1.StartConnectRequest
auth_mode?stringconfig?connection_id?stringconnector?stringname?stringorg_id?stringscopes?array<string>iohr.connections.v1.StartConnectResponse
application/json- response
iohr.connections.v1.StartConnectResponse
authorize_url*stringexpires_at*stringsession_id*stringimport { ApiError, Public } from "@inorbithr/sdk";// Reads INORBIT_TOKEN, or INORBIT_KEY_ID and INORBIT_KEY_SECRET.const api = Public.fromEnv();try { const { value } = await api.connections.startConnect("<org_id>", { auth_mode: "<auth_mode>", connector: "<connector>", name: "<name>", scopes: ["<scopes>"], }); console.log(value);} catch (e) { if (!(e instanceof ApiError)) throw e; console.error(`${e.code}: ${e.problem} (request id ${e.raw.requestId})`);}npm install @inorbithr/sdk. Calls the package's public surface; an operation newer than your package needs the next release or a client generated for your account. The SDKs.
{ "authorize_url": "string", "expires_at": "string", "session_id": "string"}Create a connection POST
Add a connection. An `endpoint` on our cloud takes its key in `secret`, sealed in the vault and never answered; on an agent it takes `secret_ref` (`vault:`, `k8s:`, `env:` or `file:`), which we never resolve. A `webhook-in` answers its signing secret once, in `webhook_secret`, and its `receive_url`. Our cloud calls only hosts inside a verified domain of the account. A connector's id as `kind` (List connectors) takes `auth_mode`, `credentials` (its fields, sealed, never answered) and `config`; its test request runs first, a refused key stores nothing, and `label` names the account at the provider. Needs scope `connections:write`.
Complete a sign-in POST
Called by the console's callback page as the person who started the sign-in, with the `state` and `code` the provider sent back (or its `error`). Exchanges the code with the PKCE verifier, seals the tokens (never answered), runs the connector's test and answers the connection with its `label`, granted `scopes`, `token_expires_at` and `external_id`. A workspace the account already connected is updated, not connected twice. The state works once. Needs scope `connections:write`.