Orkestia
Blog
Getting Started

Quick Start

From zero to a first workflow run in your own cloud. Create an org, connect a cloud, then run a workflow from an AI assistant over MCP, the console, or the SDKs

TL;DR

  1. Create an account and an organization. The org scopes everything.
  2. Connect a cloud with a scoped, revocable role. No access keys.
  3. Run a workflow from an AI assistant over MCP, the console, or an SDK. Same engine, same catalog.
  4. Optional: turn on Lumen for observability, deploy an app, or build one on Orkestia.

The fastest path is to connect an AI assistant to https://mcp.orkestia.dev/mcp and let it walk you through steps 2 and 3.

Orkestia is generally available. Exact workflow names and request shapes still change between releases. The authoritative per-workflow detail (inputs, outputs, prerequisites) lives in the workflow reference, and an assistant can always read the live schema with get_workflow_schema.

The shape of the journey

Orkestia is a privacy-first orchestrator. It holds workflow state and observability data. Cloud execution stays in your accounts. Apps you host on Orkestia (App Host + App Data) are an opt-in data and hosting plane — still isolated by identity, never a DSN in the frontend.

Prerequisites

You needWhy
An Orkestia account and organizationEvery run, connection, and resource is scoped to an org
A cloud account you controlWorkflows execute there. Orkestia never holds custody of code or data
Permission to create a role in that accountThe connection is a cross-account role, not access keys
(Optional) An MCP-capable assistant or an API tokenTo run workflows by talking, or from code

1. Create your account and organization

Sign up with email or social login, then create an organization or accept an invite into one. The org is your tenancy boundary: it scopes connections, runs, Staff governance, Lumen data, and end-user identity.

Joining an existing org? Your admins have probably already connected a cloud. Check Settings → Connections, or ask your assistant: "List my organization's connections."

Full walkthrough: User onboarding · Settings

2. Connect a cloud

Orkestia talks to your cloud through a cross-account role, never stored access keys. You create a role whose trust policy lets Orkestia's principal assume it. Orkestia then uses short-lived credentials per operation. Delete the role and access is revoked instantly. Every action shows up in your own audit log.

AWS is the reference connection. Once linked, every AWS-backed capability reuses it. GCP, Azure, Magalu Cloud, and Kubernetes follow the same delegation pattern with provider-native grants. See Cloud connections and DNS providers.

With an AI assistant

This is the canonical MCP flow, and the server enforces it through rule://prerequisites-first:

assistant transcript
whoami()
get_workflow_schema("connection.setup")            → has_prerequisites: true, prerequisite_variants: ["aws", "gcp", …]
get_workflow_prerequisites("connection.setup", variant="aws")
  → a setup guide with Orkestia's principal ARN already filled in
# you create the role in your account, then hand back role_arn + external_id
start_workflow("connection.setup", { "provider_type": "aws", "role_arn": "…", "external_id": "…" })
watch_workflow(workflow_id)                        → COMPLETED

Prompt to paste:

prompt
Set up an AWS connection for my organization. Fetch the prerequisites first and show me exactly what to create. Do not start the workflow until I give you the role ARN and external ID.

Manually

Step by step (console, CloudFormation, or Terraform): AWS connections · DNS: DNS providers · Multi-cloud runners: Runners

Least-privilege credentials. On AWS, Orkestia stores a role ARN and an encrypted external ID and never a static key. On other providers it stores the scoped key or token you create, encrypted at rest and never surfaced back. Either way you can revoke from your side and the connection fails closed. This is the mechanical basis of Zero Code Custody. See Security & compliance.

3. Run your first workflow

In Orkestia, everything is a workflow: an event-sourced, resumable state machine with a typed input schema. Pick one capability and run it any of three ways.

Connect your assistant to the Orkestia MCP server (https://mcp.orkestia.dev/mcp) and talk. The assistant follows the same loop every time:

the loop
whoami()                          → confirm identity; org resolved server-side
list_workflow_namespaces()        → what's available
list_workflow_types(prefix="…")   → candidates in one namespace
get_workflow_schema(type)         → required inputs, read_only, has_prerequisites
get_workflow_prerequisites(type)  → only if has_prerequisites is true
start_workflow(type, initial_data)
watch_workflow(workflow_id)       → follow to COMPLETED or FAILED

Good first prompts:

prompts
List the workflow namespaces my org can use and pick three safe read-only workflows to try.

Run a read-only workflow that lists my AWS S3 buckets and summarise the result.

Show me the schema for aws.s3.create_bucket. Do not run it.

Setup for Claude, ChatGPT, Cursor, and Claude Code: Connect an AI assistant. Tool reference: MCP integration.

The request shapes above are examples, not a contract. Resolve the real workflow_type, schema, and prerequisites from the workflow reference or, for assistants, from get_workflow_schema and get_workflow_prerequisites before starting a run.

Deeper: Workflows · Building with DGI · Virtual workflows

4. (Optional) Turn on Lumen

Lumen is a separate host (https://lumen-api.orkestia.dev) from the workflow API. It is off until provisioned (403 LUMEN_NOT_PROVISIONED). An org admin enables a plan under Governance → Observability (Lumen), mints a lumk_ ingest key, then POSTs JSON to /api/logs/ingest or installs the collector. Lumen also has its own MCP server at https://mcp-lumen.orkestia.dev/mcp for triage.

Contract: Enable · Send data · Query API · Lumen MCP

5. (Optional) Deploy an app, or build one on Orkestia

Cloud Deploy

Ship a GitHub repo into your connected cloud.

App Enablement

Build on Orkestia: "Sign in with Orkestia", App Data, and end-user-scoped compositions. An assistant can provision the identity app in one call by following rule://orkestia-auth-setup.

DevKit

Local CLI for webhook redirect, the coding runner, and compositions.

Where to go next

Connect an AI assistant

Client configs, first prompts, and the prompt library.

Architecture overview

Control plane vs your cloud, and where the MCP server sits.

Concepts at a glance

One paragraph per concept, with a prompt to try for each.

Governing AI agents

Staff gives fleets of agents an org structure, approvals, and oversight.

Agent Exchange

Hire or list Staff actors across organizations.