Actions
22 actions, callable from the panel, the command palette and the API as
POST /api/v1/a/<id>. Internal actions used between modules are not listed.
| Action | What it does | Risk | Preview |
|---|---|---|---|
integrations.webhook.create | Add a webhook | medium | No dry run |
integrations.webhook.update | Change a webhook | medium | No dry run |
integrations.webhook.delete | Delete a webhook | medium | No dry run |
integrations.webhook.list | List webhooks (read) | low | No dry run |
integrations.webhook.test | Send a test event | low | No dry run |
integrations.webhook.deliveries | Webhook delivery log (read) | low | No dry run |
integrations.webhook.replay | Replay a delivery | medium | No dry run |
integrations.token.create | Create a billing integration token | high | No dry run |
integrations.token.list | List billing integration tokens (read) | low | No dry run |
integrations.token.revoke | Revoke a billing integration token | medium | No dry run |
integrations.sso.issue | Issue a single sign-on link | high | No dry run |
integrations.billing.test | Test the billing connection (read) | low | No dry run |
integrations.billing.provision | Create the account for a billing service | medium | No dry run |
integrations.billing.suspend | Suspend a billing service | medium | No dry run |
integrations.billing.unsuspend | Unsuspend a billing service | medium | No dry run |
integrations.billing.terminate | Terminate a billing service | medium | No dry run |
integrations.billing.change_package | Change the package of a billing service | medium | No dry run |
integrations.billing.change_password | Change the password of a billing service | medium | No dry run |
integrations.billing.usage | Usage of a billing service (read) | low | No dry run |
integrations.billing.sso | Single sign-on link for a billing service | medium | No dry run |
integrations.billing.plans | List the packages a billing system can map (read) | low | No dry run |
integrations.batch | Run up to 100 actions in one request | low | No dry run |
Permissions and limits
Permissions
integrations.viewView integration settings and the API documentintegrations.webhooksManage webhooksintegrations.tokensCreate and revoke billing integration tokensintegrations.ssoIssue single sign-on linksintegrations.manageTest billing connectionsintegrations.billingProvision accounts for a billing system (carried by integration tokens)integrations.apiBatch API calls
Plan limits
integrations.webhooksWebhook endpointsintegrations.tokensIntegration tokens
Engineering notes
Generated from modules/integrations/docs.md at build d90e9e2. These are the notes the engineers keep
next to the code: precise, technical, and honest about what is not done yet.
Webhooks, billing provisioning, integration tokens, SSO links, batch calls and the Idempotency-Key store. User docs are in
docs/integrations/. The API-side glue lives in internal/api/openapi.go (OpenAPI, SSO route, rate-limit and idempotency
hooks) and modules/integrations/edge (limiter, idempotency wrapper).
Decisions
- Subscribes with the wildcard
{event: "*"}(w9-13): every event of every module reachesintegrations.webhook.event, which ignoresintegrations.*events itself. A new event anywhere needs no change here. - Delivery queue =
deliveriestable, claimed with a lease (FOR UPDATE SKIP LOCKED), UNIQUE(webhook, event id) makes the at-least-once bus exactly-once per endpoint. - Integration token =
auth.token.createwith a fixed name prefix and scope set (internal/auth/tokens.goblock). The billing actions elevate to an admin actor internally; the token itself holds only the billing scopes. - Idempotency is stored per (principal, key) with a request fingerprint; failures are not stored (retry runs again).
- SSO tokens are stored as sha256, consumed by one atomic UPDATE.
Verified
Unit tests (SSRF list, signature, backoff, matching, limiter, idempotency, OpenAPI), lab run in the handover.