Documentation
¶
Overview ¶
Package config parses the authio.yaml desired-state file consumed by `authio check` and `authio apply` (config-as-code, Phase 3 of the 2026-09 platform program).
One file describes one project's declarative surface:
version: 1
prune: false # delete live resources missing from this file
redirect_uris:
- uri: https://app.example.com/api/auth/callback
kind: oauth_callback # oauth_callback | magic_link_redirect | custom_app_callback
webhooks:
- url: https://app.example.com/api/authio/webhook
events: ["session.revoked", "user.created"] # default ["*"]
description: main receiver
risk_policy:
threshold_step_up: 50
threshold_block: 90
signal_weights: { new_device: 25 }
enabled_signals: [new_device]
sso_connections:
- organization_id: org_...
external_id: acme-okta # stable identity for diffing (required)
provider: saml
display_name: Acme Okta
saml: { metadata_url: ..., sso_url: ..., certificate: ... }
Identity keys for diffing: redirect_uris by uri, webhooks by url, sso_connections by organization_id + external_id, risk_policy is a singleton. Webhook secrets are write-only: they are returned exactly once at create/replace time and never stored in the file.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type File ¶
type File struct {
Version int `yaml:"version"`
Prune bool `yaml:"prune"`
RedirectURIs []RedirectURI `yaml:"redirect_uris"`
Webhooks []Webhook `yaml:"webhooks"`
RiskPolicy *RiskPolicy `yaml:"risk_policy"`
SSOConnections []SSOConnection `yaml:"sso_connections"`
// Clearance is the agent-authorization block (profiles, agents,
// providers). It is captured verbatim and validated server-side by
// the Clearance engine via POST /v1/clearance/import (the workspace
// API-key surface `authio apply`/`check` use — not
// /v1/session/clearance/import, which needs a dashboard session JWT)
// — the CLI does not duplicate that schema. `providers` inside it is
// read locally by `authio clearance serve`.
Clearance yaml.Node `yaml:"clearance"`
}
File is the root of authio.yaml.
func Load ¶
Load reads and validates an authio.yaml file. Validation is shape-level only — URL reachability, redirect-URI policy, and signal names are the management API's call, surfaced per-action at apply.
func (*File) ClearanceYAML ¶
ClearanceYAML re-serialises the clearance block as a standalone document (`clearance: …`) for the import route.
func (*File) Empty ¶
Empty reports whether the file declares nothing to manage — almost always a mistake (wrong file), so the commands refuse it explicitly.
func (*File) HasClearance ¶
HasClearance reports whether the file declares a clearance: block.
type RedirectURI ¶
type RedirectURI struct {
URI string `yaml:"uri"`
Kind string `yaml:"kind"` // default oauth_callback
}
RedirectURI declares one allowed redirect URI. Identity: URI.
type RiskPolicy ¶
type RiskPolicy struct {
ThresholdStepUp int `yaml:"threshold_step_up"`
ThresholdBlock int `yaml:"threshold_block"`
SignalWeights map[string]int `yaml:"signal_weights"`
EnabledSignals []string `yaml:"enabled_signals"`
}
RiskPolicy declares the project's risk-engine policy (singleton, PUT /v1/risk/policy upsert).
type SSOConnection ¶
type SSOConnection struct {
OrganizationID string `yaml:"organization_id"`
ExternalID string `yaml:"external_id"`
Provider string `yaml:"provider"` // saml | oidc
DisplayName string `yaml:"display_name"`
IdPProvider string `yaml:"idp_provider"`
SAML map[string]any `yaml:"saml"`
OIDC map[string]any `yaml:"oidc"`
AttributeMap map[string]string `yaml:"attribute_map"`
JITProvisioning *bool `yaml:"jit_provisioning"`
DefaultRole string `yaml:"default_role"`
Status string `yaml:"status"`
}
SSOConnection declares one org SSO connection. Identity: organization_id + external_id (the management API's idempotent-create key). The saml/oidc config blocks are write-only from the API's list surface, so they are sent on create but cannot be drift-detected — changing IdP config on an existing connection is a dashboard job.
type Webhook ¶
type Webhook struct {
URL string `yaml:"url"`
Events []string `yaml:"events"` // default ["*"]
Description string `yaml:"description"`
OrganizationID string `yaml:"organization_id"`
}
Webhook declares one webhook endpoint. Identity: URL. The management API has no update endpoint — event/description drift is resolved by replace (revoke + recreate), which rotates the secret.