Integrations

Webhooks, billing-system modules, integration tokens, single sign-on links and batch API calls.

In preview integrations version 0.1.0

Actions

22 actions, callable from the panel, the command palette and the API as POST /api/v1/a/<id>. Internal actions used between modules are not listed.

ActionWhat it doesRiskPreview
integrations.webhook.create Add a webhook medium No dry run
integrations.webhook.update Change a webhook medium No dry run
integrations.webhook.delete Delete a webhook medium No dry run
integrations.webhook.list List webhooks (read) low No dry run
integrations.webhook.test Send a test event low No dry run
integrations.webhook.deliveries Webhook delivery log (read) low No dry run
integrations.webhook.replay Replay a delivery medium No dry run
integrations.token.create Create a billing integration token high No dry run
integrations.token.list List billing integration tokens (read) low No dry run
integrations.token.revoke Revoke a billing integration token medium No dry run
integrations.sso.issue Issue a single sign-on link high No dry run
integrations.billing.test Test the billing connection (read) low No dry run
integrations.billing.provision Create the account for a billing service medium No dry run
integrations.billing.suspend Suspend a billing service medium No dry run
integrations.billing.unsuspend Unsuspend a billing service medium No dry run
integrations.billing.terminate Terminate a billing service medium No dry run
integrations.billing.change_package Change the package of a billing service medium No dry run
integrations.billing.change_password Change the password of a billing service medium No dry run
integrations.billing.usage Usage of a billing service (read) low No dry run
integrations.billing.sso Single sign-on link for a billing service medium No dry run
integrations.billing.plans List the packages a billing system can map (read) low No dry run
integrations.batch Run up to 100 actions in one request low No dry run

Permissions and limits

Permissions

  • integrations.view View integration settings and the API document
  • integrations.webhooks Manage webhooks
  • integrations.tokens Create and revoke billing integration tokens
  • integrations.sso Issue single sign-on links
  • integrations.manage Test billing connections
  • integrations.billing Provision accounts for a billing system (carried by integration tokens)
  • integrations.api Batch API calls

Plan limits

  • integrations.webhooks Webhook endpoints
  • integrations.tokens Integration tokens

Engineering notes

Generated from modules/integrations/docs.md at build d90e9e2. These are the notes the engineers keep next to the code: precise, technical, and honest about what is not done yet.

Webhooks, billing provisioning, integration tokens, SSO links, batch calls and the Idempotency-Key store. User docs are in docs/integrations/. The API-side glue lives in internal/api/openapi.go (OpenAPI, SSO route, rate-limit and idempotency hooks) and modules/integrations/edge (limiter, idempotency wrapper).

Decisions

  • Subscribes with the wildcard {event: "*"} (w9-13): every event of every module reaches integrations.webhook.event, which ignores integrations.* events itself. A new event anywhere needs no change here.
  • Delivery queue = deliveries table, claimed with a lease (FOR UPDATE SKIP LOCKED), UNIQUE(webhook, event id) makes the at-least-once bus exactly-once per endpoint.
  • Integration token = auth.token.create with a fixed name prefix and scope set (internal/auth/tokens.go block). The billing actions elevate to an admin actor internally; the token itself holds only the billing scopes.
  • Idempotency is stored per (principal, key) with a request fingerprint; failures are not stored (retry runs again).
  • SSO tokens are stored as sha256, consumed by one atomic UPDATE.

Verified

Unit tests (SSRF list, signature, backoff, matching, limiter, idempotency, OpenAPI), lab run in the handover.