[{"data":1,"prerenderedAt":2083},["ShallowReactive",2],{"navigation":3,"/sdks/auth":879,"/sdks/auth-surround":2078},[4,22,45,115,156,187,214,235,264,295,318,361,389,418,436,470,491,534,548,571,632,670,693,757,850],{"title":5,"path":6,"stem":7,"children":8,"icon":11},"Introduction","/introduction","01.introduction/1.index",[9,12,17],{"title":10,"path":6,"stem":7,"icon":11},"What is Orkestia?","i-lucide-sparkles",{"title":13,"path":14,"stem":15,"icon":16},"Core Philosophy","/introduction/core-philosophy","01.introduction/2.core-philosophy","i-lucide-shield-check",{"title":18,"path":19,"stem":20,"icon":21},"Key Benefits","/introduction/key-benefits","01.introduction/3.key-benefits","i-lucide-trophy",{"title":23,"path":24,"stem":25,"children":26,"icon":29},"Getting Started","/getting-started","02.getting-started/1.index",[27,30,35,40],{"title":28,"path":24,"stem":25,"icon":29},"Quick Start","i-lucide-rocket",{"title":31,"path":32,"stem":33,"icon":34},"Architecture Overview","/getting-started/architecture-overview","02.getting-started/2.architecture-overview","i-lucide-layout-dashboard",{"title":36,"path":37,"stem":38,"icon":39},"Concepts at a Glance","/getting-started/concepts","02.getting-started/3.concepts","i-lucide-list",{"title":41,"path":42,"stem":43,"icon":44},"Connect an AI Assistant","/getting-started/connect-an-ai-assistant","02.getting-started/4.connect-an-ai-assistant","i-lucide-bot",{"title":46,"path":47,"stem":48,"children":49,"icon":51},"Core Concepts","/concepts","03.concepts/01.index",[50,52,57,62,67,71,76,81,86,91,96,100,105,110],{"title":46,"path":47,"stem":48,"icon":51},"i-lucide-book-open",{"title":53,"path":54,"stem":55,"icon":56},"Workflows","/concepts/workflows","03.concepts/02.workflows","i-lucide-workflow",{"title":58,"path":59,"stem":60,"icon":61},"DGI — Dialog Generative Interface","/concepts/dgi","03.concepts/03.dgi","i-lucide-brain",{"title":63,"path":64,"stem":65,"icon":66},"Staff & AI Workforce Governance","/concepts/staff-governance","03.concepts/04.staff-governance","i-lucide-users-round",{"title":68,"path":69,"stem":70,"icon":44},"Agents — the execution substrate","/concepts/agents-platform","03.concepts/05.agents-platform",{"title":72,"path":73,"stem":74,"icon":75},"Runners & Execution Environments","/concepts/runners","03.concepts/06.runners","i-lucide-server-cog",{"title":77,"path":78,"stem":79,"icon":80},"Lumen Observability","/concepts/lumen","03.concepts/07.lumen","i-lucide-activity",{"title":82,"path":83,"stem":84,"icon":85},"Identity & Multi-Tenancy","/concepts/identity-multi-tenancy","03.concepts/08.identity-multi-tenancy","i-lucide-users",{"title":87,"path":88,"stem":89,"icon":90},"Billing, Pricing & Seats","/concepts/billing-and-seats","03.concepts/09.billing-and-seats","i-lucide-credit-card",{"title":92,"path":93,"stem":94,"icon":95},"App Data","/concepts/appdata","03.concepts/10.appdata","i-lucide-database",{"title":97,"path":98,"stem":99,"icon":61},"Engram","/concepts/engram","03.concepts/11.engram",{"title":101,"path":102,"stem":103,"icon":104},"DevKit","/concepts/devkit","03.concepts/12.devkit","i-lucide-terminal",{"title":106,"path":107,"stem":108,"icon":109},"App Host","/concepts/app-host","03.concepts/13.app-host","i-lucide-globe",{"title":111,"path":112,"stem":113,"icon":114},"Agent Exchange","/concepts/agent-exchange","03.concepts/14.agent-exchange","i-lucide-landmark",{"title":116,"path":117,"stem":118,"children":119,"icon":121},"Guides","/guides","04.guides/1.index",[120,122,127,132,137,142,147,151],{"title":116,"path":117,"stem":118,"icon":121},"i-lucide-compass",{"title":123,"path":124,"stem":125,"icon":126},"Building with DGI","/guides/building-with-dgi","04.guides/2.building-with-dgi","i-lucide-brain-circuit",{"title":128,"path":129,"stem":130,"icon":131},"Creating & Exposing Virtual Workflows","/guides/virtual-workflows","04.guides/4.virtual-workflows","i-lucide-blocks",{"title":133,"path":134,"stem":135,"icon":136},"Runner Management & Provisioning","/guides/runner-management","04.guides/5.runner-management","i-lucide-server",{"title":138,"path":139,"stem":140,"icon":141},"Security & Compliance","/guides/security-and-compliance","04.guides/7.security-and-compliance","i-lucide-shield",{"title":143,"path":144,"stem":145,"icon":146},"Tickets & Software Delivery","/guides/tickets-and-software-delivery","04.guides/8.tickets-and-software-delivery","i-lucide-ticket",{"title":148,"path":149,"stem":150},"Orkestia for AI-driven cloud infrastructure automation","/guides/cloud-automation-alternatives","04.guides/9.cloud-automation-alternatives",{"title":152,"path":153,"stem":154,"icon":155},"Typed decisions with TypeSafe","/guides/typed-decisions-with-typesafe","04.guides/9.typed-decisions-with-typesafe","i-lucide-git-branch",{"title":157,"path":158,"stem":159,"children":160,"icon":162},"Reference","/reference","05.reference/1.index",[161,163,168,173,177,182],{"title":157,"path":158,"stem":159,"icon":162},"i-lucide-library",{"title":164,"path":165,"stem":166,"icon":167},"Workflow Types & Registry","/reference/workflow-types-registry","05.reference/2.workflow-types-registry","i-lucide-list-tree",{"title":169,"path":170,"stem":171,"icon":172},"MCP Integration","/reference/mcp-integration","05.reference/3.mcp-integration","i-lucide-plug-zap",{"title":174,"path":175,"stem":176,"icon":104},"API & Tooling","/reference/api-tooling","05.reference/4.api-tooling",{"title":178,"path":179,"stem":180,"icon":181},"Integrations Catalog","/reference/integrations-catalog","05.reference/6.integrations-catalog","i-lucide-plug",{"title":183,"path":184,"stem":185,"icon":186},"Platform Services","/reference/platform-services","05.reference/7.platform-services","i-lucide-boxes",{"title":188,"path":189,"stem":190,"children":191,"icon":193},"Advanced Topics","/advanced","06.advanced/1.index",[192,194,199,204,209],{"title":188,"path":189,"stem":190,"icon":193},"i-lucide-flask-conical",{"title":195,"path":196,"stem":197,"icon":198},"Hybrid AI + Deterministic Execution","/advanced/hybrid-execution-model","06.advanced/2.hybrid-execution-model","i-lucide-git-merge",{"title":200,"path":201,"stem":202,"icon":203},"Drift Detection & Self-Healing","/advanced/drift-detection-self-healing","06.advanced/3.drift-detection-self-healing","i-lucide-heart-pulse",{"title":205,"path":206,"stem":207,"icon":208},"Governance & Approvals","/advanced/governance-and-approvals","06.advanced/4.governance-and-approvals","i-lucide-scale",{"title":210,"path":211,"stem":212,"icon":213},"Cost & Performance Optimization","/advanced/cost-and-performance","06.advanced/5.cost-and-performance","i-lucide-zap",{"title":215,"path":216,"stem":217,"children":218,"icon":220},"Operations","/operations","07.operations/1.index",[219,221,225,230],{"title":215,"path":216,"stem":217,"icon":220},"i-lucide-settings-2",{"title":222,"path":223,"stem":224,"icon":186},"Deployment Models","/operations/deployment-models","07.operations/2.deployment-models",{"title":226,"path":227,"stem":228,"icon":229},"Monitoring & Debugging","/operations/monitoring-and-debugging","07.operations/3.monitoring-and-debugging","i-lucide-bug",{"title":231,"path":232,"stem":233,"icon":234},"Best Practices","/operations/best-practices","07.operations/4.best-practices","i-lucide-check-check",{"title":236,"path":237,"stem":238,"children":239,"icon":241},"AWS Connections","/aws-connections","08.aws-connections/1.index",[240,242,245,250,255,260],{"title":236,"path":237,"stem":238,"icon":241},"i-simple-icons-amazonaws",{"title":23,"path":243,"stem":244,"icon":29},"/aws-connections/getting-started","08.aws-connections/2.getting-started",{"title":246,"path":247,"stem":248,"icon":249},"Setup Methods","/aws-connections/setup-methods","08.aws-connections/3.setup-methods","i-lucide-wrench",{"title":251,"path":252,"stem":253,"icon":254},"Managing Connections","/aws-connections/managing-connections","08.aws-connections/4.managing-connections","i-lucide-settings",{"title":256,"path":257,"stem":258,"icon":259},"Security Best Practices","/aws-connections/security-best-practices","08.aws-connections/5.security-best-practices","i-lucide-lock",{"title":261,"path":262,"stem":263,"icon":229},"Troubleshooting","/aws-connections/troubleshooting","08.aws-connections/6.troubleshooting",{"title":265,"path":266,"stem":267,"children":268,"icon":270},"Cloud Connections","/cloud-connections","09.cloud-connections/1.index",[269,271,276,281,286,291],{"title":265,"path":266,"stem":267,"icon":270},"i-lucide-cable",{"title":272,"path":273,"stem":274,"icon":275},"Google Cloud (GCP)","/cloud-connections/gcp","09.cloud-connections/2.gcp","i-simple-icons-googlecloud",{"title":277,"path":278,"stem":279,"icon":280},"Microsoft Azure","/cloud-connections/azure","09.cloud-connections/3.azure","i-simple-icons-microsoftazure",{"title":282,"path":283,"stem":284,"icon":285},"Magalu Cloud","/cloud-connections/magalu","09.cloud-connections/4.magalu","i-lucide-cloud",{"title":287,"path":288,"stem":289,"icon":290},"Kubernetes","/cloud-connections/kubernetes","09.cloud-connections/5.kubernetes","i-simple-icons-kubernetes",{"title":292,"path":293,"stem":294,"icon":208},"TypeSafe","/cloud-connections/typesafe","09.cloud-connections/6.typesafe",{"title":296,"path":297,"stem":298,"children":299,"icon":136},"DNS Providers","/dns-providers","10.dns-providers/1.index",[300,302,305,308,311,315],{"title":301,"path":297,"stem":298,"icon":136},"DNS Provider Connections",{"title":23,"path":303,"stem":304,"icon":29},"/dns-providers/getting-started","10.dns-providers/2.getting-started",{"title":246,"path":306,"stem":307,"icon":249},"/dns-providers/setup-methods","10.dns-providers/3.setup-methods",{"title":251,"path":309,"stem":310,"icon":254},"/dns-providers/managing-connections","10.dns-providers/4.managing-connections",{"title":312,"path":313,"stem":314,"icon":39},"Zones and Records","/dns-providers/zones-and-records","10.dns-providers/5.zones-and-records",{"title":261,"path":316,"stem":317,"icon":229},"/dns-providers/troubleshooting","10.dns-providers/6.troubleshooting",{"title":319,"path":320,"stem":321,"children":322,"icon":29},"Cloud Deploy","/cloud-deploy","11.cloud-deploy/01.index",[323,324,327,332,336,341,345,349,354,358],{"title":319,"path":320,"stem":321,"icon":29},{"title":23,"path":325,"stem":326,"icon":29},"/cloud-deploy/getting-started","11.cloud-deploy/02.getting-started",{"title":328,"path":329,"stem":330,"icon":331},"Creating a Site","/cloud-deploy/creating-a-site","11.cloud-deploy/03.creating-a-site","i-lucide-plus-circle",{"title":333,"path":334,"stem":335,"icon":34},"Site Overview and Deployments","/cloud-deploy/site-overview","11.cloud-deploy/04.site-overview",{"title":337,"path":338,"stem":339,"icon":340},"Deployment Progress and Success","/cloud-deploy/deployment-progress","11.cloud-deploy/05.deployment-progress","i-lucide-loader",{"title":342,"path":343,"stem":344,"icon":254},"Settings","/cloud-deploy/settings","11.cloud-deploy/06.settings",{"title":346,"path":347,"stem":348,"icon":109},"Custom Domains","/cloud-deploy/custom-domains","11.cloud-deploy/07.custom-domains",{"title":350,"path":351,"stem":352,"icon":353},"Resources, Releases, and Danger Zone","/cloud-deploy/resources-releases","11.cloud-deploy/08.resources-releases","i-lucide-package",{"title":355,"path":356,"stem":357,"icon":141},"Admin Dashboard","/cloud-deploy/admin-dashboard","11.cloud-deploy/09.admin-dashboard",{"title":261,"path":359,"stem":360,"icon":229},"/cloud-deploy/troubleshooting","11.cloud-deploy/10.troubleshooting",{"title":362,"path":363,"stem":364,"children":365,"icon":368},"User Onboarding","/user-onboarding","12.user-onboarding/1.index",[366,369,372,377,382,386],{"title":367,"path":363,"stem":364,"icon":368},"User Creation and Onboarding","i-lucide-user-plus",{"title":23,"path":370,"stem":371,"icon":29},"/user-onboarding/getting-started","12.user-onboarding/2.getting-started",{"title":373,"path":374,"stem":375,"icon":376},"Creating Your Organization","/user-onboarding/onboarding","12.user-onboarding/3.onboarding","i-lucide-building-2",{"title":378,"path":379,"stem":380,"icon":381},"Invitations","/user-onboarding/invitations","12.user-onboarding/4.invitations","i-lucide-mail",{"title":383,"path":384,"stem":385,"icon":254},"Managing Your Account","/user-onboarding/managing-account","12.user-onboarding/5.managing-account",{"title":261,"path":387,"stem":388,"icon":229},"/user-onboarding/troubleshooting","12.user-onboarding/6.troubleshooting",{"title":342,"path":390,"stem":391,"children":392,"icon":394},"/settings","13.settings/1.index",[393,395,400,404,409,413],{"title":342,"path":390,"stem":391,"icon":394},"i-lucide-sliders-horizontal",{"title":396,"path":397,"stem":398,"icon":399},"General Settings","/settings/general","13.settings/2.general","i-lucide-user",{"title":401,"path":402,"stem":403,"icon":85},"Members Settings","/settings/members","13.settings/3.members",{"title":405,"path":406,"stem":407,"icon":408},"Notifications Settings","/settings/notifications","13.settings/4.notifications","i-lucide-bell",{"title":410,"path":411,"stem":412,"icon":141},"Security Settings","/settings/security","13.settings/5.security",{"title":414,"path":415,"stem":416,"icon":417},"Signing Keys","/settings/keys","13.settings/6.keys","i-lucide-key-round",{"title":419,"path":420,"stem":421,"children":422,"icon":29},"App Enablement","/app-enablement","14.app-enablement/1.index",[423,424,428,432],{"title":419,"path":420,"stem":421,"icon":29},{"title":425,"path":426,"stem":427,"icon":417},"Sign in with Orkestia","/app-enablement/sign-in-with-orkestia","14.app-enablement/2.sign-in-with-orkestia",{"title":429,"path":430,"stem":431,"icon":95},"End-user data","/app-enablement/end-user-data","14.app-enablement/3.end-user-data",{"title":433,"path":434,"stem":435,"icon":131},"Compositions — use, invoke, share","/app-enablement/compositions","14.app-enablement/4.compositions",{"title":437,"path":438,"stem":439,"children":440,"icon":80},"Lumen","/lumen","15.lumen/1.index",[441,442,447,452,457,461,465],{"title":437,"path":438,"stem":439,"icon":80},{"title":443,"path":444,"stem":445,"icon":446},"Enable Lumen","/lumen/enable","15.lumen/2.enable","i-lucide-power",{"title":448,"path":449,"stem":450,"icon":451},"Send data","/lumen/send-data","15.lumen/3.send-data","i-lucide-upload",{"title":453,"path":454,"stem":455,"icon":456},"Collector","/lumen/collector","15.lumen/4.collector","i-lucide-container",{"title":458,"path":459,"stem":460,"icon":34},"Use Lumen","/lumen/observe","15.lumen/5.observe",{"title":462,"path":463,"stem":464,"icon":44},"Lumen MCP","/lumen/mcp","15.lumen/6.mcp",{"title":466,"path":467,"stem":468,"icon":469},"Query API","/lumen/query-api","15.lumen/7.query-api","i-lucide-search",{"title":471,"path":472,"stem":473,"children":474,"icon":476},"SDKs","/sdks","16.sdks/1.index",[475,477,482,487],{"title":471,"path":472,"stem":473,"icon":476},"i-lucide-code",{"title":478,"path":479,"stem":480,"icon":481},"Workflows SDK — Node / TypeScript","/sdks/workflows-nodejs","16.sdks/2.workflows-nodejs","i-lucide-file-ts",{"title":483,"path":484,"stem":485,"icon":486},"Workflows SDK — Python","/sdks/workflows-python","16.sdks/3.workflows-python","i-simple-icons-python",{"title":488,"path":489,"stem":490,"icon":417},"Auth SDK — Sign in with Orkestia","/sdks/auth","16.sdks/4.auth",{"title":92,"path":492,"stem":493,"children":494,"icon":95},"/appdata","17.appdata/1.index",[495,496,501,506,510,515,520,525,530],{"title":92,"path":492,"stem":493,"icon":95},{"title":497,"path":498,"stem":499,"icon":500},"Declare structures","/appdata/declare","17.appdata/2.declare","i-lucide-table",{"title":502,"path":503,"stem":504,"icon":505},"Records & Data API","/appdata/data-api","17.appdata/3.data-api","i-lucide-rows-3",{"title":507,"path":508,"stem":509,"icon":376},"Ownership & workspaces","/appdata/ownership","17.appdata/4.ownership",{"title":511,"path":512,"stem":513,"icon":514},"Expose App Data to end-users","/appdata/expose","17.appdata/5.expose","i-lucide-app-window",{"title":516,"path":517,"stem":518,"icon":519},"PostgREST HTTP","/appdata/postgrest","17.appdata/6.postgrest","i-lucide-unplug",{"title":521,"path":522,"stem":523,"icon":524},"Ordered append","/appdata/append","17.appdata/7.append","i-lucide-list-ordered",{"title":526,"path":527,"stem":528,"icon":529},"Databases and instances","/appdata/instances","17.appdata/8.instances","i-lucide-hard-drive",{"title":531,"path":532,"stem":533,"icon":104},"Query console and SQL","/appdata/query","17.appdata/9.query",{"title":97,"path":535,"stem":536,"children":537,"icon":61},"/engram","18.engram/1.index",[538,539,543],{"title":97,"path":535,"stem":536,"icon":61},{"title":540,"path":541,"stem":542,"icon":155},"Write & recall","/engram/write-recall","18.engram/2.write-recall",{"title":544,"path":545,"stem":546,"icon":547},"Field & feed","/engram/agent-memory","18.engram/3.agent-memory","i-lucide-radio",{"title":101,"path":549,"stem":550,"children":551,"icon":104},"/devkit","19.devkit/1.index",[552,553,558,562,567],{"title":101,"path":549,"stem":550,"icon":104},{"title":554,"path":555,"stem":556,"icon":557},"Install DevKit","/devkit/install","19.devkit/2.install","i-lucide-download",{"title":559,"path":560,"stem":561,"icon":519},"Hook redirect","/devkit/hooks","19.devkit/3.hooks",{"title":563,"path":564,"stem":565,"icon":566},"Local coding runner","/devkit/local-runner","19.devkit/4.local-runner","i-lucide-cpu",{"title":568,"path":569,"stem":570,"icon":131},"Compositions from DevKit","/devkit/compositions","19.devkit/5.compositions",{"title":572,"path":573,"stem":574,"children":575,"icon":44},"Staff & Agents","/staff-and-agents","20.staff-and-agents/01.index",[576,577,582,586,590,594,598,602,606,611,615,620,625,629],{"title":572,"path":573,"stem":574,"icon":44},{"title":578,"path":579,"stem":580,"icon":581},"Prerequisites","/staff-and-agents/prerequisites","20.staff-and-agents/02.prerequisites","i-lucide-list-checks",{"title":583,"path":584,"stem":585,"icon":368},"Hire an actor","/staff-and-agents/hire-an-actor","20.staff-and-agents/03.hire-an-actor",{"title":587,"path":588,"stem":589,"icon":34},"Console","/staff-and-agents/console","20.staff-and-agents/04.console",{"title":591,"path":592,"stem":593,"icon":11},"Configs, skills, and MCP","/staff-and-agents/configs-skills-mcp","20.staff-and-agents/05.configs-skills-mcp",{"title":595,"path":596,"stem":597,"icon":136},"Agent runner groups","/staff-and-agents/runner-groups","20.staff-and-agents/06.runner-groups",{"title":599,"path":600,"stem":601,"icon":16},"Governance","/staff-and-agents/governance","20.staff-and-agents/07.governance",{"title":603,"path":604,"stem":605,"icon":417},"Identity and tokens","/staff-and-agents/identity","20.staff-and-agents/08.identity",{"title":607,"path":608,"stem":609,"icon":610},"Memory and cost","/staff-and-agents/memory-and-cost","20.staff-and-agents/09.memory-and-cost","i-lucide-wallet",{"title":612,"path":613,"stem":614,"icon":155},"Coding agents","/staff-and-agents/coding-agents","20.staff-and-agents/10.coding-agents",{"title":616,"path":617,"stem":618,"icon":619},"Wire a repository for coding agents","/staff-and-agents/wire-a-repository","20.staff-and-agents/11.wire-a-repository","i-lucide-link",{"title":621,"path":622,"stem":623,"icon":624},"Run a ticket end to end","/staff-and-agents/run-a-ticket","20.staff-and-agents/12.run-a-ticket","i-lucide-play",{"title":626,"path":627,"stem":628,"icon":66},"Build a product team of actors","/staff-and-agents/build-a-product-team","20.staff-and-agents/13.build-a-product-team",{"title":261,"path":630,"stem":631,"icon":249},"/staff-and-agents/troubleshooting","20.staff-and-agents/14.troubleshooting",{"title":106,"path":633,"stem":634,"children":635,"icon":109},"/app-host","21.app-host/1.index",[636,637,641,644,649,653,658,662,666],{"title":106,"path":633,"stem":634,"icon":109},{"title":638,"path":639,"stem":640,"icon":514},"Your app and site","/app-host/your-app","21.app-host/2.your-app",{"title":92,"path":642,"stem":643,"icon":95},"/app-host/app-data","21.app-host/3.app-data",{"title":645,"path":646,"stem":647,"icon":648},"Website and process","/app-host/hosting","21.app-host/4.hosting","i-lucide-cloud-upload",{"title":650,"path":651,"stem":652,"icon":547},"Buzz","/app-host/buzz","21.app-host/5.buzz",{"title":654,"path":655,"stem":656,"icon":657},"Files","/app-host/files","21.app-host/6.files","i-lucide-folder",{"title":659,"path":660,"stem":661,"icon":109},"Your own domain","/app-host/your-domain","21.app-host/7.your-domain",{"title":663,"path":664,"stem":665,"icon":229},"Troubleshooting App Host","/app-host/troubleshooting","21.app-host/8.troubleshooting",{"title":667,"path":668,"stem":669,"icon":417},"Signing keys","/app-host/signing-keys","21.app-host/9.signing-keys",{"title":111,"path":671,"stem":672,"children":673,"icon":114},"/agent-exchange","22.agent-exchange/01.index",[674,675,678,682,686,690],{"title":111,"path":671,"stem":672,"icon":114},{"title":583,"path":676,"stem":677,"icon":368},"/agent-exchange/hire","22.agent-exchange/02.hire",{"title":679,"path":680,"stem":681,"icon":208},"List an actor","/agent-exchange/list","22.agent-exchange/03.list",{"title":683,"path":684,"stem":685,"icon":104},"Invoke & leases","/agent-exchange/invoke","22.agent-exchange/04.invoke",{"title":687,"path":688,"stem":689,"icon":141},"Settlement & trust","/agent-exchange/settlement","22.agent-exchange/05.settlement",{"title":53,"path":691,"stem":692,"icon":56},"/agent-exchange/workflows","22.agent-exchange/06.workflows",{"title":694,"path":695,"stem":696,"children":697,"icon":75},"Runners","/runners","23.runners/1.index",[698,700,704,709,713,717,721,726,730,734,738,741,745,749,753],{"title":699,"path":695,"stem":696,"icon":75},"Runner groups",{"title":701,"path":702,"stem":703,"icon":275},"Cloud Run","/runners/cloud-run","23.runners/10.cloud-run",{"title":705,"path":706,"stem":707,"icon":708},"DigitalOcean App Job","/runners/do-app-job","23.runners/11.do-app-job","i-simple-icons-digitalocean",{"title":710,"path":711,"stem":712,"icon":708},"DigitalOcean Droplet","/runners/do-droplet","23.runners/12.do-droplet",{"title":714,"path":715,"stem":716,"icon":285},"Magalu Cloud VM","/runners/magalu-vm","23.runners/13.magalu-vm",{"title":101,"path":718,"stem":719,"icon":720},"/runners/devkit","23.runners/14.devkit","i-lucide-laptop",{"title":722,"path":723,"stem":724,"icon":725},"Purposes & integrations","/runners/purposes","23.runners/16.purposes","i-lucide-layers",{"title":727,"path":728,"stem":729,"icon":241},"Fargate","/runners/fargate","23.runners/2.fargate",{"title":731,"path":732,"stem":733,"icon":241},"EC2 Auto Scaling","/runners/ec2-auto-scaling","23.runners/3.ec2-auto-scaling",{"title":735,"path":736,"stem":737,"icon":241},"EC2 VM","/runners/ec2-vm","23.runners/4.ec2-vm",{"title":287,"path":739,"stem":740,"icon":290},"/runners/kubernetes","23.runners/5.kubernetes",{"title":742,"path":743,"stem":744,"icon":280},"Azure Container Apps","/runners/azure-container-apps","23.runners/6.azure-container-apps",{"title":746,"path":747,"stem":748,"icon":280},"Azure VMSS","/runners/azure-vmss","23.runners/7.azure-vmss",{"title":750,"path":751,"stem":752,"icon":280},"Azure VM","/runners/azure-vm","23.runners/8.azure-vm",{"title":754,"path":755,"stem":756,"icon":275},"GCE","/runners/gce","23.runners/9.gce",{"title":758,"path":759,"stem":760,"children":761,"icon":763},"Chat","/chat","24.chat/01.index",[762,764,768,773,777,782,787,791,796,800,805,810,814,819,824,828,832,836,840,845],{"title":758,"path":759,"stem":760,"icon":763},"i-lucide-messages-square",{"title":765,"path":766,"stem":767,"icon":446},"Enable and publish","/chat/enable-and-publish","24.chat/02.enable-and-publish",{"title":769,"path":770,"stem":771,"icon":772},"Theme and customization","/chat/theme-and-customization","24.chat/03.theme-and-customization","i-lucide-palette",{"title":774,"path":775,"stem":776,"icon":85},"Members and moderation","/chat/members-and-moderation","24.chat/04.members-and-moderation",{"title":778,"path":779,"stem":780,"icon":781},"Channels","/chat/channels","24.chat/05.channels","i-lucide-hash",{"title":783,"path":784,"stem":785,"icon":786},"Using the chat","/chat/using-the-chat","24.chat/06.using-the-chat","i-lucide-message-circle",{"title":788,"path":789,"stem":790,"icon":44},"Actors in chat","/chat/actors-in-chat","24.chat/07.actors-in-chat",{"title":792,"path":793,"stem":794,"icon":795},"Internal support actor","/chat/internal-support-actor","24.chat/08.internal-support-actor","i-lucide-life-buoy",{"title":797,"path":798,"stem":799,"icon":104},"API and console","/chat/api-and-console","24.chat/09.api-and-console",{"title":801,"path":802,"stem":803,"icon":804},"Limits","/chat/limits","24.chat/10.limits","i-lucide-triangle-alert",{"title":806,"path":807,"stem":808,"icon":809},"Structured chat with DGI","/chat/structured-chat","24.chat/11.structured-chat","i-lucide-layout-list",{"title":811,"path":812,"stem":813,"icon":109},"Option A: hosted chat with DGI","/chat/option-a-hosted-chat","24.chat/12.option-a-hosted-chat",{"title":815,"path":816,"stem":817,"icon":818},"Option B: embed the chat component","/chat/option-b-embed-component","24.chat/13.option-b-embed-component","i-lucide-component",{"title":820,"path":821,"stem":822,"icon":823},"Option C: custom client (wire contract)","/chat/option-c-custom-client","24.chat/14.option-c-custom-client","i-lucide-braces",{"title":825,"path":826,"stem":827,"icon":394},"Responder configuration reference","/chat/responder-reference","24.chat/15.responder-reference",{"title":829,"path":830,"stem":831,"icon":547},"Cards, live updates and proactive posts","/chat/cards-live-and-proactive","24.chat/16.cards-live-and-proactive",{"title":833,"path":834,"stem":835,"icon":16},"Structured chat security model","/chat/structured-chat-security","24.chat/17.structured-chat-security",{"title":837,"path":838,"stem":839,"icon":181},"Option D: any app or API (dgi.chat)","/chat/option-d-chat-api","24.chat/18.option-d-chat-api",{"title":841,"path":842,"stem":843,"icon":844},"Card catalog","/chat/card-catalog","24.chat/19.card-catalog","i-lucide-layout-grid",{"title":846,"path":847,"stem":848,"icon":849},"Living Surfaces","/chat/living-surfaces","24.chat/20.living-surfaces","i-lucide-sprout",{"title":851,"path":852,"stem":853,"children":854,"icon":61},"DGI","/dgi","25.dgi/1.index",[855,857,862,866,870,874],{"title":856,"path":852,"stem":853,"icon":61},"What is DGI",{"title":858,"path":859,"stem":860,"icon":861},"How DGI works","/dgi/how-it-works","25.dgi/2.how-it-works","i-lucide-cog",{"title":863,"path":864,"stem":865,"icon":844},"Interfaces","/dgi/interfaces","25.dgi/3.interfaces",{"title":867,"path":868,"stem":869,"icon":29},"Quickstart","/dgi/quickstart","25.dgi/4.quickstart",{"title":871,"path":872,"stem":873,"icon":16},"Trust and safety","/dgi/trust-and-safety","25.dgi/5.trust-and-safety",{"title":875,"path":876,"stem":877,"icon":878},"FAQ","/dgi/faq","25.dgi/6.faq","i-lucide-circle-help",{"id":880,"title":488,"body":881,"description":2071,"extension":2072,"links":2073,"meta":2074,"navigation":2075,"path":489,"seo":2076,"stem":490,"__hash__":2077},"docs/16.sdks/4.auth.md",{"type":882,"value":883,"toc":2061},"minimark",[884,908,921,936,950,955,980,984,990,1109,1125,1129,1304,1329,1333,1436,1617,1621,1635,1755,1773,1777,1788,1940,1947,1951,1958,2025,2029,2038,2057],[885,886,887,894,895,898,899,902,903,907],"p",{},[888,889,890],"strong",{},[891,892,893],"code",{},"@orkestia/auth"," is the browser SDK for ",[888,896,897],{},"\"Sign in with Orkestia\""," — the OAuth 2.0 / OIDC authorization-code flow with ",[888,900,901],{},"PKCE"," that authenticates ",[904,905,906],"em",{},"your app's users",", not your org members.",[909,910,913],"callout",{"icon":911,"to":912},"i-lucide-clipboard-paste","/app-enablement#paste-this-into-your-agent",[885,914,915,916,920],{},"To provision an identity app and wire this SDK, paste the ",[917,918,919],"a",{"href":912},"agent prompt on App Enablement"," into an MCP-connected agent.",[885,922,923,924,927,928,931,932,935],{},"Your frontend never sees a password and never holds a client secret. The public ",[891,925,926],{},"client_key"," is safe to ship in the browser. After login you hold an ",[888,929,930],{},"RS256 JWT"," you can send to the workflow API as ",[891,933,934],{},"Authorization: Bearer …",".",[937,938,939],"note",{},[885,940,941,942,945,946,949],{},"Early access (",[891,943,944],{},"v0.0.x","). The API may change before 1.0. ",[891,947,948],{},"npm i @orkestia/auth"," will work once the package is published; until then install from the repository.",[951,952,954],"h2",{"id":953},"install","Install",[956,957,962],"pre",{"className":958,"code":959,"language":960,"meta":961,"style":961},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","npm i github:orkestia/orkestia-auth-sdk\n","bash","",[891,963,964],{"__ignoreMap":961},[965,966,969,973,977],"span",{"class":967,"line":968},"line",1,[965,970,972],{"class":971},"sBMFI","npm",[965,974,976],{"class":975},"sfazB"," i",[965,978,979],{"class":975}," github:orkestia/orkestia-auth-sdk\n",[951,981,983],{"id":982},"_1-provision-the-app-once","1. Provision the app (once)",[885,985,986,987,989],{},"An org member (or an agent over MCP) provisions the identity app. One workflow returns the ",[891,988,926],{}," and every URL the SDK needs:",[956,991,995],{"className":992,"code":993,"language":994,"meta":961,"style":961},"language-ts shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","identity.app.provision({\n  name: \"My App\",\n  redirect_uris: [\n    \"http://localhost:5173/callback\",\n    \"https://myapp.com/callback\",\n  ],\n})\n// → { client_key, client_uuid, redirect_uris,\n//     integration: { issuer, discovery_url, authorize_url, token_url, jwks_url, flow, sdk } }\n","ts",[891,996,997,1021,1043,1054,1067,1079,1087,1096,1103],{"__ignoreMap":961},[965,998,999,1003,1006,1009,1011,1015,1018],{"class":967,"line":968},[965,1000,1002],{"class":1001},"sTEyZ","identity",[965,1004,935],{"class":1005},"sMK4o",[965,1007,1008],{"class":1001},"app",[965,1010,935],{"class":1005},[965,1012,1014],{"class":1013},"s2Zo4","provision",[965,1016,1017],{"class":1001},"(",[965,1019,1020],{"class":1005},"{\n",[965,1022,1024,1028,1031,1034,1037,1040],{"class":967,"line":1023},2,[965,1025,1027],{"class":1026},"swJcz","  name",[965,1029,1030],{"class":1005},":",[965,1032,1033],{"class":1005}," \"",[965,1035,1036],{"class":975},"My App",[965,1038,1039],{"class":1005},"\"",[965,1041,1042],{"class":1005},",\n",[965,1044,1046,1049,1051],{"class":967,"line":1045},3,[965,1047,1048],{"class":1026},"  redirect_uris",[965,1050,1030],{"class":1005},[965,1052,1053],{"class":1001}," [\n",[965,1055,1057,1060,1063,1065],{"class":967,"line":1056},4,[965,1058,1059],{"class":1005},"    \"",[965,1061,1062],{"class":975},"http://localhost:5173/callback",[965,1064,1039],{"class":1005},[965,1066,1042],{"class":1005},[965,1068,1070,1072,1075,1077],{"class":967,"line":1069},5,[965,1071,1059],{"class":1005},[965,1073,1074],{"class":975},"https://myapp.com/callback",[965,1076,1039],{"class":1005},[965,1078,1042],{"class":1005},[965,1080,1082,1085],{"class":967,"line":1081},6,[965,1083,1084],{"class":1001},"  ]",[965,1086,1042],{"class":1005},[965,1088,1090,1093],{"class":967,"line":1089},7,[965,1091,1092],{"class":1005},"}",[965,1094,1095],{"class":1001},")\n",[965,1097,1099],{"class":967,"line":1098},8,[965,1100,1102],{"class":1101},"sHwdD","// → { client_key, client_uuid, redirect_uris,\n",[965,1104,1106],{"class":967,"line":1105},9,[965,1107,1108],{"class":1101},"//     integration: { issuer, discovery_url, authorize_url, token_url, jwks_url, flow, sdk } }\n",[885,1110,1111,1112,1115,1116,1119,1120,1122,1123,935],{},"Registered ",[891,1113,1114],{},"redirect_uris"," are accepted immediately — there is no manual CORS step. Add more later with ",[891,1117,1118],{},"identity.app.configure-client",". See ",[917,1121,419],{"href":420}," and ",[917,1124,425],{"href":426},[951,1126,1128],{"id":1127},"_2-wire-the-browser","2. Wire the browser",[956,1130,1132],{"className":992,"code":1131,"language":994,"meta":961,"style":961},"import { createOrkestiaAuth } from \"@orkestia/auth\"\n\nconst auth = createOrkestiaAuth({ clientKey: \"orkestia_…\" })\n\n// On your \"Sign in\" button:\nawait auth.signIn()\n\n// On the registered redirect_uri page:\nconst session = await auth.handleCallback()\n// { token, claims, email, endUserUuid } | null\n\n// Anywhere later:\nconst current = auth.getSession()\nauth.signOut()\n",[891,1133,1134,1159,1165,1200,1204,1209,1225,1229,1234,1255,1261,1266,1272,1291],{"__ignoreMap":961},[965,1135,1136,1140,1143,1146,1149,1152,1154,1156],{"class":967,"line":968},[965,1137,1139],{"class":1138},"s7zQu","import",[965,1141,1142],{"class":1005}," {",[965,1144,1145],{"class":1001}," createOrkestiaAuth",[965,1147,1148],{"class":1005}," }",[965,1150,1151],{"class":1138}," from",[965,1153,1033],{"class":1005},[965,1155,893],{"class":975},[965,1157,1158],{"class":1005},"\"\n",[965,1160,1161],{"class":967,"line":1023},[965,1162,1164],{"emptyLinePlaceholder":1163},true,"\n",[965,1166,1167,1171,1174,1177,1179,1181,1184,1187,1189,1191,1194,1196,1198],{"class":967,"line":1045},[965,1168,1170],{"class":1169},"spNyl","const",[965,1172,1173],{"class":1001}," auth ",[965,1175,1176],{"class":1005},"=",[965,1178,1145],{"class":1013},[965,1180,1017],{"class":1001},[965,1182,1183],{"class":1005},"{",[965,1185,1186],{"class":1026}," clientKey",[965,1188,1030],{"class":1005},[965,1190,1033],{"class":1005},[965,1192,1193],{"class":975},"orkestia_…",[965,1195,1039],{"class":1005},[965,1197,1148],{"class":1005},[965,1199,1095],{"class":1001},[965,1201,1202],{"class":967,"line":1056},[965,1203,1164],{"emptyLinePlaceholder":1163},[965,1205,1206],{"class":967,"line":1069},[965,1207,1208],{"class":1101},"// On your \"Sign in\" button:\n",[965,1210,1211,1214,1217,1219,1222],{"class":967,"line":1081},[965,1212,1213],{"class":1138},"await",[965,1215,1216],{"class":1001}," auth",[965,1218,935],{"class":1005},[965,1220,1221],{"class":1013},"signIn",[965,1223,1224],{"class":1001},"()\n",[965,1226,1227],{"class":967,"line":1089},[965,1228,1164],{"emptyLinePlaceholder":1163},[965,1230,1231],{"class":967,"line":1098},[965,1232,1233],{"class":1101},"// On the registered redirect_uri page:\n",[965,1235,1236,1238,1241,1243,1246,1248,1250,1253],{"class":967,"line":1105},[965,1237,1170],{"class":1169},[965,1239,1240],{"class":1001}," session ",[965,1242,1176],{"class":1005},[965,1244,1245],{"class":1138}," await",[965,1247,1216],{"class":1001},[965,1249,935],{"class":1005},[965,1251,1252],{"class":1013},"handleCallback",[965,1254,1224],{"class":1001},[965,1256,1258],{"class":967,"line":1257},10,[965,1259,1260],{"class":1101},"// { token, claims, email, endUserUuid } | null\n",[965,1262,1264],{"class":967,"line":1263},11,[965,1265,1164],{"emptyLinePlaceholder":1163},[965,1267,1269],{"class":967,"line":1268},12,[965,1270,1271],{"class":1101},"// Anywhere later:\n",[965,1273,1275,1277,1280,1282,1284,1286,1289],{"class":967,"line":1274},13,[965,1276,1170],{"class":1169},[965,1278,1279],{"class":1001}," current ",[965,1281,1176],{"class":1005},[965,1283,1216],{"class":1001},[965,1285,935],{"class":1005},[965,1287,1288],{"class":1013},"getSession",[965,1290,1224],{"class":1001},[965,1292,1294,1297,1299,1302],{"class":967,"line":1293},14,[965,1295,1296],{"class":1001},"auth",[965,1298,935],{"class":1005},[965,1300,1301],{"class":1013},"signOut",[965,1303,1224],{"class":1001},[885,1305,1306,1309,1310,1313,1314,1317,1318,1321,1322,1325,1326],{},[891,1307,1308],{},"signIn()"," builds the PKCE challenge and redirects to ",[891,1311,1312],{},"login.orkestia.dev",". After the user authenticates, Orkestia returns to your ",[891,1315,1316],{},"redirect_uri"," with a one-time ",[891,1319,1320],{},"?code",". ",[891,1323,1324],{},"handleCallback()"," exchanges the code for the JWT. ",[888,1327,1328],{},"The token never appears in a URL.",[951,1330,1332],{"id":1331},"api","API",[1334,1335,1336,1349],"table",{},[1337,1338,1339],"thead",{},[1340,1341,1342,1346],"tr",{},[1343,1344,1345],"th",{},"Method",[1343,1347,1348],{},"Purpose",[1350,1351,1352,1362,1378,1388,1406,1416,1426],"tbody",{},[1340,1353,1354,1359],{},[1355,1356,1357],"td",{},[891,1358,1308],{},[1355,1360,1361],{},"Start PKCE — redirect to the hosted login",[1340,1363,1364,1368],{},[1355,1365,1366],{},[891,1367,1324],{},[1355,1369,1370,1371,1373,1374,1377],{},"Exchange ",[891,1372,1320],{}," for a session (",[891,1375,1376],{},"OrkestiaSession | null",")",[1340,1379,1380,1385],{},[1355,1381,1382],{},[891,1383,1384],{},"getSession()",[1355,1386,1387],{},"Current stored session (claims decoded; expiry checked)",[1340,1389,1390,1395],{},[1355,1391,1392],{},[891,1393,1394],{},"renew()",[1355,1396,1397,1398,1401,1402,1405],{},"Silent refresh (",[891,1399,1400],{},"prompt=none","); throws ",[891,1403,1404],{},"OrkestiaLoginRequiredError"," if the session is gone",[1340,1407,1408,1413],{},[1355,1409,1410],{},[891,1411,1412],{},"signOut()",[1355,1414,1415],{},"Clear the local session",[1340,1417,1418,1423],{},[1355,1419,1420],{},[891,1421,1422],{},"verify(token)",[1355,1424,1425],{},"Verify the RS256 signature against the published JWKS",[1340,1427,1428,1433],{},[1355,1429,1430],{},[891,1431,1432],{},"register(email, password)",[1355,1434,1435],{},"Create an end-user account (does not consume a seat)",[956,1437,1439],{"className":992,"code":1438,"language":994,"meta":961,"style":961},"createOrkestiaAuth({\n  clientKey: \"orkestia_…\",                          // required\n  loginUrl: \"https://login.orkestia.dev\",           // default\n  identityApi: \"https://workflow-api.orkestia.dev\", // default\n  redirectUri: location.origin + \"/\",               // must be registered\n  storage: sessionStorage,                          // default\n  autoRenew: true,                                  // default\n  renewSkewSeconds: 60,\n  onRequiresLogin: (err) => auth.signIn(),\n})\n",[891,1440,1441,1450,1469,1488,1507,1537,1552,1568,1581,1611],{"__ignoreMap":961},[965,1442,1443,1446,1448],{"class":967,"line":968},[965,1444,1445],{"class":1013},"createOrkestiaAuth",[965,1447,1017],{"class":1001},[965,1449,1020],{"class":1005},[965,1451,1452,1455,1457,1459,1461,1463,1466],{"class":967,"line":1023},[965,1453,1454],{"class":1026},"  clientKey",[965,1456,1030],{"class":1005},[965,1458,1033],{"class":1005},[965,1460,1193],{"class":975},[965,1462,1039],{"class":1005},[965,1464,1465],{"class":1005},",",[965,1467,1468],{"class":1101},"                          // required\n",[965,1470,1471,1474,1476,1478,1481,1483,1485],{"class":967,"line":1045},[965,1472,1473],{"class":1026},"  loginUrl",[965,1475,1030],{"class":1005},[965,1477,1033],{"class":1005},[965,1479,1480],{"class":975},"https://login.orkestia.dev",[965,1482,1039],{"class":1005},[965,1484,1465],{"class":1005},[965,1486,1487],{"class":1101},"           // default\n",[965,1489,1490,1493,1495,1497,1500,1502,1504],{"class":967,"line":1056},[965,1491,1492],{"class":1026},"  identityApi",[965,1494,1030],{"class":1005},[965,1496,1033],{"class":1005},[965,1498,1499],{"class":975},"https://workflow-api.orkestia.dev",[965,1501,1039],{"class":1005},[965,1503,1465],{"class":1005},[965,1505,1506],{"class":1101}," // default\n",[965,1508,1509,1512,1514,1517,1519,1522,1525,1527,1530,1532,1534],{"class":967,"line":1069},[965,1510,1511],{"class":1026},"  redirectUri",[965,1513,1030],{"class":1005},[965,1515,1516],{"class":1001}," location",[965,1518,935],{"class":1005},[965,1520,1521],{"class":1001},"origin ",[965,1523,1524],{"class":1005},"+",[965,1526,1033],{"class":1005},[965,1528,1529],{"class":975},"/",[965,1531,1039],{"class":1005},[965,1533,1465],{"class":1005},[965,1535,1536],{"class":1101},"               // must be registered\n",[965,1538,1539,1542,1544,1547,1549],{"class":967,"line":1081},[965,1540,1541],{"class":1026},"  storage",[965,1543,1030],{"class":1005},[965,1545,1546],{"class":1001}," sessionStorage",[965,1548,1465],{"class":1005},[965,1550,1551],{"class":1101},"                          // default\n",[965,1553,1554,1557,1559,1563,1565],{"class":967,"line":1089},[965,1555,1556],{"class":1026},"  autoRenew",[965,1558,1030],{"class":1005},[965,1560,1562],{"class":1561},"sfNiH"," true",[965,1564,1465],{"class":1005},[965,1566,1567],{"class":1101},"                                  // default\n",[965,1569,1570,1573,1575,1579],{"class":967,"line":1098},[965,1571,1572],{"class":1026},"  renewSkewSeconds",[965,1574,1030],{"class":1005},[965,1576,1578],{"class":1577},"sbssI"," 60",[965,1580,1042],{"class":1005},[965,1582,1583,1586,1588,1591,1595,1597,1600,1602,1604,1606,1609],{"class":967,"line":1105},[965,1584,1585],{"class":1013},"  onRequiresLogin",[965,1587,1030],{"class":1005},[965,1589,1590],{"class":1005}," (",[965,1592,1594],{"class":1593},"sHdIc","err",[965,1596,1377],{"class":1005},[965,1598,1599],{"class":1169}," =>",[965,1601,1216],{"class":1001},[965,1603,935],{"class":1005},[965,1605,1221],{"class":1013},[965,1607,1608],{"class":1001},"()",[965,1610,1042],{"class":1005},[965,1612,1613,1615],{"class":967,"line":1257},[965,1614,1092],{"class":1005},[965,1616,1095],{"class":1001},[951,1618,1620],{"id":1619},"silent-renew","Silent renew",[885,1622,1623,1624,1627,1628,1631,1632,1634],{},"Access tokens are short-lived. With ",[891,1625,1626],{},"autoRenew"," on (the default) the SDK refreshes ",[891,1629,1630],{},"renewSkewSeconds"," before expiry using a hidden OIDC ",[891,1633,1400],{}," iframe. The hosted login's session cookie is the long-lived state.",[956,1636,1638],{"className":992,"code":1637,"language":994,"meta":961,"style":961},"import { createOrkestiaAuth, OrkestiaLoginRequiredError } from \"@orkestia/auth\"\n\ntry {\n  const session = await auth.renew()\n} catch (err) {\n  if (err instanceof OrkestiaLoginRequiredError) {\n    await auth.signIn() // session revoked or expired — full re-login\n  }\n}\n",[891,1639,1640,1663,1667,1675,1697,1709,1728,1745,1750],{"__ignoreMap":961},[965,1641,1642,1644,1646,1648,1650,1653,1655,1657,1659,1661],{"class":967,"line":968},[965,1643,1139],{"class":1138},[965,1645,1142],{"class":1005},[965,1647,1145],{"class":1001},[965,1649,1465],{"class":1005},[965,1651,1652],{"class":1001}," OrkestiaLoginRequiredError",[965,1654,1148],{"class":1005},[965,1656,1151],{"class":1138},[965,1658,1033],{"class":1005},[965,1660,893],{"class":975},[965,1662,1158],{"class":1005},[965,1664,1665],{"class":967,"line":1023},[965,1666,1164],{"emptyLinePlaceholder":1163},[965,1668,1669,1672],{"class":967,"line":1045},[965,1670,1671],{"class":1138},"try",[965,1673,1674],{"class":1005}," {\n",[965,1676,1677,1680,1683,1686,1688,1690,1692,1695],{"class":967,"line":1056},[965,1678,1679],{"class":1169},"  const",[965,1681,1682],{"class":1001}," session",[965,1684,1685],{"class":1005}," =",[965,1687,1245],{"class":1138},[965,1689,1216],{"class":1001},[965,1691,935],{"class":1005},[965,1693,1694],{"class":1013},"renew",[965,1696,1224],{"class":1026},[965,1698,1699,1701,1704,1707],{"class":967,"line":1069},[965,1700,1092],{"class":1005},[965,1702,1703],{"class":1138}," catch",[965,1705,1706],{"class":1001}," (err) ",[965,1708,1020],{"class":1005},[965,1710,1711,1714,1716,1718,1721,1723,1726],{"class":967,"line":1081},[965,1712,1713],{"class":1138},"  if",[965,1715,1590],{"class":1026},[965,1717,1594],{"class":1001},[965,1719,1720],{"class":1005}," instanceof",[965,1722,1652],{"class":971},[965,1724,1725],{"class":1026},") ",[965,1727,1020],{"class":1005},[965,1729,1730,1733,1735,1737,1739,1742],{"class":967,"line":1089},[965,1731,1732],{"class":1138},"    await",[965,1734,1216],{"class":1001},[965,1736,935],{"class":1005},[965,1738,1221],{"class":1013},[965,1740,1741],{"class":1026},"() ",[965,1743,1744],{"class":1101},"// session revoked or expired — full re-login\n",[965,1746,1747],{"class":967,"line":1098},[965,1748,1749],{"class":1005},"  }\n",[965,1751,1752],{"class":967,"line":1105},[965,1753,1754],{"class":1005},"}\n",[885,1756,1757,1758,1761,1762,1764,1765,1768,1769,1772],{},"If the session was revoked (",[891,1759,1760],{},"identity.end-user.session.revoke",") or expired, ",[891,1763,1394],{}," clears local state, fires ",[891,1766,1767],{},"onRequiresLogin",", throws, and does ",[888,1770,1771],{},"not"," retry.",[951,1774,1776],{"id":1775},"use-the-jwt-with-the-workflow-sdks","Use the JWT with the workflow SDKs",[885,1778,1779,1780,1783,1784,1787],{},"The session token is a normal Bearer. Pass it to the ",[917,1781,1782],{"href":479},"Node"," or ",[917,1785,1786],{"href":484},"Python"," workflow SDK, or to REST. The engine injects the end-user principal immutably — the caller cannot set or override it.",[956,1789,1791],{"className":992,"code":1790,"language":994,"meta":961,"style":961},"import { LtIntegWorkflowsClient } from \"@ltinteg/workflows-sdk\"\n\nconst session = auth.getSession()\nconst client = new LtIntegWorkflowsClient({\n  baseUrl: \"https://workflow-api.orkestia.dev\",\n  token: session.token,\n})\n\n// Only workflows you exposed, and only this user's rows.\nconst run = await client.start(\"virtual.\u003Ccomposition_uuid>@1\", {\n  /* free inputs only */\n})\n",[891,1792,1793,1813,1817,1833,1851,1866,1882,1888,1892,1897,1929,1934],{"__ignoreMap":961},[965,1794,1795,1797,1799,1802,1804,1806,1808,1811],{"class":967,"line":968},[965,1796,1139],{"class":1138},[965,1798,1142],{"class":1005},[965,1800,1801],{"class":1001}," LtIntegWorkflowsClient",[965,1803,1148],{"class":1005},[965,1805,1151],{"class":1138},[965,1807,1033],{"class":1005},[965,1809,1810],{"class":975},"@ltinteg/workflows-sdk",[965,1812,1158],{"class":1005},[965,1814,1815],{"class":967,"line":1023},[965,1816,1164],{"emptyLinePlaceholder":1163},[965,1818,1819,1821,1823,1825,1827,1829,1831],{"class":967,"line":1045},[965,1820,1170],{"class":1169},[965,1822,1240],{"class":1001},[965,1824,1176],{"class":1005},[965,1826,1216],{"class":1001},[965,1828,935],{"class":1005},[965,1830,1288],{"class":1013},[965,1832,1224],{"class":1001},[965,1834,1835,1837,1840,1842,1845,1847,1849],{"class":967,"line":1056},[965,1836,1170],{"class":1169},[965,1838,1839],{"class":1001}," client ",[965,1841,1176],{"class":1005},[965,1843,1844],{"class":1005}," new",[965,1846,1801],{"class":1013},[965,1848,1017],{"class":1001},[965,1850,1020],{"class":1005},[965,1852,1853,1856,1858,1860,1862,1864],{"class":967,"line":1069},[965,1854,1855],{"class":1026},"  baseUrl",[965,1857,1030],{"class":1005},[965,1859,1033],{"class":1005},[965,1861,1499],{"class":975},[965,1863,1039],{"class":1005},[965,1865,1042],{"class":1005},[965,1867,1868,1871,1873,1875,1877,1880],{"class":967,"line":1081},[965,1869,1870],{"class":1026},"  token",[965,1872,1030],{"class":1005},[965,1874,1682],{"class":1001},[965,1876,935],{"class":1005},[965,1878,1879],{"class":1001},"token",[965,1881,1042],{"class":1005},[965,1883,1884,1886],{"class":967,"line":1089},[965,1885,1092],{"class":1005},[965,1887,1095],{"class":1001},[965,1889,1890],{"class":967,"line":1098},[965,1891,1164],{"emptyLinePlaceholder":1163},[965,1893,1894],{"class":967,"line":1105},[965,1895,1896],{"class":1101},"// Only workflows you exposed, and only this user's rows.\n",[965,1898,1899,1901,1904,1906,1908,1911,1913,1916,1918,1920,1923,1925,1927],{"class":967,"line":1257},[965,1900,1170],{"class":1169},[965,1902,1903],{"class":1001}," run ",[965,1905,1176],{"class":1005},[965,1907,1245],{"class":1138},[965,1909,1910],{"class":1001}," client",[965,1912,935],{"class":1005},[965,1914,1915],{"class":1013},"start",[965,1917,1017],{"class":1001},[965,1919,1039],{"class":1005},[965,1921,1922],{"class":975},"virtual.\u003Ccomposition_uuid>@1",[965,1924,1039],{"class":1005},[965,1926,1465],{"class":1005},[965,1928,1674],{"class":1005},[965,1930,1931],{"class":967,"line":1263},[965,1932,1933],{"class":1101},"  /* free inputs only */\n",[965,1935,1936,1938],{"class":967,"line":1268},[965,1937,1092],{"class":1005},[965,1939,1095],{"class":1001},[885,1941,1942,1943,1122,1945,935],{},"Next: ",[917,1944,429],{"href":430},[917,1946,92],{"href":492},[951,1948,1950],{"id":1949},"the-oauth-contract","The OAuth contract",[885,1952,1953,1954,1957],{},"The SDK implements this loop. You can do it by hand if you do not want the package; the URLs also arrive in the provision ",[891,1955,1956],{},"integration"," bundle.",[1334,1959,1960,1970],{},[1337,1961,1962],{},[1340,1963,1964,1967],{},[1343,1965,1966],{},"Step",[1343,1968,1969],{},"Endpoint",[1350,1971,1972,1982,2000,2014],{},[1340,1973,1974,1977],{},[1355,1975,1976],{},"Authorize",[1355,1978,1979],{},[891,1980,1981],{},"GET https://login.orkestia.dev/authorize?client_key&redirect_uri&state&code_challenge&code_challenge_method=S256",[1340,1983,1984,1987],{},[1355,1985,1986],{},"Token",[1355,1988,1989,1992,1993,1996,1997],{},[891,1990,1991],{},"POST https://workflow-api.orkestia.dev/api/auth/end-user/token"," ",[891,1994,1995],{},"{ code, code_verifier }"," → ",[891,1998,1999],{},"{ token }",[1340,2001,2002,2005],{},[1355,2003,2004],{},"JWKS",[1355,2006,2007,2010,2011,1377],{},[891,2008,2009],{},"GET https://workflow-api.orkestia.dev/api/auth/end-user/jwks"," (RS256, ",[891,2012,2013],{},"iss=login.orkestia.dev",[1340,2015,2016,2019],{},[1355,2017,2018],{},"Register / verify-email / reset / MFA",[1355,2020,2021,2022],{},"under ",[891,2023,2024],{},"https://workflow-api.orkestia.dev/api/auth/end-user/*",[951,2026,2028],{"id":2027},"org-members-vs-end-users","Org members vs end-users",[885,2030,2031,2032,2034,2035,935],{},"Do not use this SDK for your team operating Orkestia. Members sign in through org login (Cognito). ",[891,2033,893],{}," is only for ",[888,2036,2037],{},"end-users of an app you built",[2039,2040,2041,2048],"card-group",{},[2042,2043,2045],"card",{"icon":85,"title":2044,"to":363},"Org members",[885,2046,2047],{},"Your team — dashboard, API tokens, workflow SDKs, MCP.",[2042,2049,2051],{"icon":399,"title":2050,"to":83},"End-users",[885,2052,2053,2056],{},[904,2054,2055],{},"Your"," users — this SDK, seat-gated, only exposed workflows.",[2058,2059,2060],"style",{},"html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .s2Zo4, html code.shiki .s2Zo4{--shiki-light:#6182B8;--shiki-default:#82AAFF;--shiki-dark:#82AAFF}html pre.shiki code .swJcz, html code.shiki .swJcz{--shiki-light:#E53935;--shiki-default:#F07178;--shiki-dark:#F07178}html pre.shiki code .sHwdD, html code.shiki .sHwdD{--shiki-light:#90A4AE;--shiki-light-font-style:italic;--shiki-default:#546E7A;--shiki-default-font-style:italic;--shiki-dark:#676E95;--shiki-dark-font-style:italic}html pre.shiki code .s7zQu, html code.shiki .s7zQu{--shiki-light:#39ADB5;--shiki-light-font-style:italic;--shiki-default:#89DDFF;--shiki-default-font-style:italic;--shiki-dark:#89DDFF;--shiki-dark-font-style:italic}html pre.shiki code .spNyl, html code.shiki .spNyl{--shiki-light:#9C3EDA;--shiki-default:#C792EA;--shiki-dark:#C792EA}html pre.shiki code .sfNiH, html code.shiki .sfNiH{--shiki-light:#FF5370;--shiki-default:#FF9CAC;--shiki-dark:#FF9CAC}html pre.shiki code .sbssI, html code.shiki .sbssI{--shiki-light:#F76D47;--shiki-default:#F78C6C;--shiki-dark:#F78C6C}html pre.shiki code .sHdIc, html code.shiki .sHdIc{--shiki-light:#90A4AE;--shiki-light-font-style:italic;--shiki-default:#EEFFFF;--shiki-default-font-style:italic;--shiki-dark:#BABED8;--shiki-dark-font-style:italic}",{"title":961,"searchDepth":968,"depth":1023,"links":2062},[2063,2064,2065,2066,2067,2068,2069,2070],{"id":953,"depth":1023,"text":954},{"id":982,"depth":1023,"text":983},{"id":1127,"depth":1023,"text":1128},{"id":1331,"depth":1023,"text":1332},{"id":1619,"depth":1023,"text":1620},{"id":1775,"depth":1023,"text":1776},{"id":1949,"depth":1023,"text":1950},{"id":2027,"depth":1023,"text":2028},"Browser PKCE / OAuth SDK for your app's end-users — hosted login, RS256 JWTs, silent renew, no client secret","md",null,{},{"icon":417},{"title":488,"description":2071},"R_gKKbcsvgFW66FtzZhUMfgIh29V6DSFO7g7uAIcdxA",[2079,2081],{"title":483,"path":484,"stem":485,"description":2080,"icon":486,"children":-1},"Pydantic-typed Python client for the Orkestia workflow API — the same catalog as the Node SDK",{"title":92,"path":492,"stem":493,"description":2082,"icon":95,"children":-1},"Platform-owned application data — declare tables, never hold a DSN in the frontend. Workflows, Data API, PostgREST, and an admitted SQL console for operators.",1790354053510]