GraphQL reference: outbound-connectors
Generated from the schema this service serves, so it cannot fall behind it. The same schema is published as a file for tools and agents.
| Endpoint | https://<your-host>/api/outbound-connectors/graphql |
| Auth plane | tenant — The ordinary application plane. Obtain a tenant access token by calling login then selectTenant on user-management, and authorize each call with the capability it names (for example device:write). |
| Authorize with | tenant access token |
| Schema file | /schema/outbound-connectors.graphql |
| Described | 72 of 72 elements |
Queries
connector · connectorTypes · connectorVersions · connectors · outboundConnectorsInfo
connector
Returns the connector with the given token, or null if there is none. Requires connector:read.
Returns Connector
| Argument | Type | Description |
|---|---|---|
token | String! | Token of the connector to look up. |
connectorTypes
Lists the connector types this deployment recognizes, sorted alphabetically. A listed type is not necessarily deliverable: gcp_pubsub is recognized but has no delivery client in this build, so creating, updating to or publishing it is refused with extensions.code UNSUPPORTED, and a delivery attempt for one stored earlier is dead-lettered rather than dropped. Requires connector:read.
Returns [String!]!
connectorVersions
Lists the published versions of a connector, newest first, at most 1000 per call; use limit and offset to page. Returns an empty list if it has never been published or offset is past the last version; fails if no connector has the given token. Requires connector:read.
Returns [ConnectorVersion!]!
| Argument | Type | Description |
|---|---|---|
limit | Int | Maximum number of versions to return. Omitted, below 1 or above 1000, it is 1000. |
offset | Int | Number of newest versions to skip before the first one returned. Omitted or negative, it is 0. |
token | String! | Token of the connector. |
connectors
Searches the tenant's connectors, newest created first, optionally filtered by type. Returns an empty page when nothing matches. Requires connector:read.
Returns ConnectorSearchResults!
| Argument | Type | Description |
|---|---|---|
criteria | ConnectorSearchCriteria! | Filter and paging. |
outboundConnectorsInfo
Identifies the service answering. Requires no specific authority.
Returns ServiceInfo!
Mutations
createConnector · deleteConnector · publishConnector · renameConnector · rollbackConnector · updateConnector
createConnector
Creates a connector as an unpublished draft; it is not used for delivery until published. Rejects an unknown or undeliverable type, an invalid config, or a token already in use. Requires connector:write.
Returns Connector!
| Argument | Type | Description |
|---|---|---|
request | ConnectorCreateRequest! | The new connector's fields. |
deleteConnector
Permanently deletes the connector, all its published versions and its stored credential. Returns true if a connector was deleted and false if none has the token. A rule that still refers to the deleted connector can no longer deliver. Requires connector:write.
Returns Boolean!
| Argument | Type | Description |
|---|---|---|
token | String! | Token of the connector to delete. |
publishConnector
Publishes the connector's current draft as the next version and returns it; delivery uses the latest published version. Fails if no connector has the token, or if the connector's type cannot be delivered to in this build (extensions.code UNSUPPORTED). If expectedUpdatedAt is given and the draft has changed since, nothing is published and the call fails with the same "modified by another writer" message as updateConnector. Requires connector:write.
Returns ConnectorVersion!
| Argument | Type | Description |
|---|---|---|
description | String | Optional free-text note for the version. |
expectedUpdatedAt | String | The updatedAt value you last read, as an RFC 3339 timestamp. Omit it to publish whatever the draft currently holds. |
label | String | Optional label for the version, such as a release name. |
token | String! | Token of the connector to publish. |
renameConnector
Changes a connector's token and nothing else. The stored credential stays attached, but a rule that refers to the connector by its old token must be updated to the new one. Renaming to the token it already has succeeds without change. Fails if the new token is blank or is already used by another connector (extensions.code CONFLICT), or if no connector has the old token. Requires connector:write.
Returns Connector!
| Argument | Type | Description |
|---|---|---|
newToken | String! | The new token, which must be unused in the tenant. |
token | String! | Current token of the connector. |
rollbackConnector
Copies a published version's type and config back into the connector's draft and returns the connector. The credential is unchanged, no version is created or removed, and delivery keeps using the latest published version until you publish again. Fails if the connector or the version does not exist. Requires connector:write.
Returns Connector!
| Argument | Type | Description |
|---|---|---|
token | String! | Token of the connector. |
version | Int! | The version number to restore, as listed by connectorVersions. |
updateConnector
Partially updates a connector's draft; delivery keeps using the latest published version until you publish again. Fails if no connector has the token. If expectedUpdatedAt is given and the connector has changed since, nothing is written and the call fails with the message "connector was modified by another writer; reload and try again" (this error carries no code). Requires connector:write.
Returns Connector!
| Argument | Type | Description |
|---|---|---|
expectedUpdatedAt | String | The updatedAt value you last read, as an RFC 3339 timestamp. Omit it to overwrite unconditionally. |
request | ConnectorUpdateRequest! | The fields to change. |
token | String! | Current token of the connector to update. |
Objects
Connector · ConnectorSearchResults · ConnectorVersion · SearchResultsPagination · ServiceInfo
Connector
object
An outbound connector: a named, tenant-owned destination (an MQTT broker topic, a Kafka topic, an AWS SNS topic or an AWS SQS queue) that a rule's publish action delivers to. What you edit is the draft; publishConnector freezes it into an immutable ConnectorVersion, and delivery uses the latest published version. The credential is write-only: it is never returned, only whether one is set.
| Field | Type | Description |
|---|---|---|
config | String! | The connection settings for the connector type, as a JSON object serialized to a string. It never contains the credential; that is the separate write-only secret. |
createdAt | String | When the connector was created, as an RFC 3339 timestamp. |
description | String | Free-text description of what the connector delivers to. |
hasSecret | Boolean! | True when a credential is stored for this connector. The credential itself is never returned. |
id | ID! | Server-assigned identifier. Address a connector by its token, not by this. |
name | String | Human-readable name shown in connector lists. |
token | String! | Unique, caller-chosen identifier of the connector within the tenant. A rule's publish action refers to the connector by this value. Letters, digits, hyphens and underscores, starting with a letter or digit, at most 128 characters. |
type | String! | The connector type: one of the values returned by connectorTypes. It selects which transport delivers the message and which keys config takes. |
updatedAt | String | When the connector draft was last written, as an RFC 3339 timestamp. Pass it back as expectedUpdatedAt to make an update or publish conditional on nobody else having changed the draft since you read it. |
ConnectorSearchResults
object
One page of connectors and where it sits in the full result set.
| Field | Type | Description |
|---|---|---|
pagination | SearchResultsPagination! | Position of this page within the full result set. |
results | [Connector!]! | The connectors on this page, newest created first (ties broken by token). |
ConnectorVersion
object
An immutable snapshot of a connector's type and config, taken when it was published. Versions are numbered from 1 per connector and are kept until the connector is deleted. The credential is not part of a version: it belongs to the connector, so a rotated credential applies to every version.
| Field | Type | Description |
|---|---|---|
description | String | Optional free-text note supplied when the version was published. |
label | String | Optional caller-supplied label for the version, such as a release name; not interpreted. |
publishedAt | String! | When the version was published, as an RFC 3339 timestamp. |
publishedBy | String | Username of the identity that published the version, or its email when it has no username; null when neither is known. |
type | String! | The connector type at the time of publishing. |
version | Int! | The version number: 1 for the first publish, then increasing by 1 for each publish. |
SearchResultsPagination
object
Where a page of search results sits in the full result set. Positions are 1-based and inclusive.
| Field | Type | Description |
|---|---|---|
pageEnd | Int | Position of the last result on this page within the full result set (1-based, inclusive). |
pageStart | Int | Position of the first result on this page within the full result set (1-based). |
totalRecords | Int | Number of records matching the criteria across all pages. |
ServiceInfo
object
Identity of the service answering the request.
| Field | Type | Description |
|---|---|---|
area | String! | The functional area this service serves; for this service, the outbound connectors area. |
Input types
ConnectorCreateRequest · ConnectorSearchCriteria · ConnectorUpdateRequest
ConnectorCreateRequest
input
Fields for a new connector. The type must be one this deployment can deliver to, and the config must be valid for that type; either failing rejects the create.
| Input field | Type | Description |
|---|---|---|
config | String! | The connection settings for the type, as a JSON object serialized to a string of at most 64 KiB. Unknown keys are rejected. Keys by type: mqtt takes urls (required, one broker per entry), topic (required), qos (0, 1 or 2; default 1), clientId and username; kafka takes addresses (required, host:port each), topic (required), clientId, tls and sasl ({mechanism: PLAIN, SCRAM-SHA-256 or SCRAM-SHA-512, username}); aws_sns takes region, accessKeyId and topicArn (all required) and endpoint; aws_sqs takes region, accessKeyId and url (all required) and endpoint. mqtt urls (scheme://host:port) and kafka addresses must give an explicit port; the AWS endpoint and the SQS url are http or https URLs. The platform restricts which addresses a connector may reach. |
description | String | Free-text description of what the connector delivers to. |
name | String | Human-readable name shown in connector lists. |
secret | String | The credential: the broker password for mqtt, the SASL password for kafka, the secret access key for aws_sns and aws_sqs. Write-only; stored encrypted and never returned. Omit it, or send an empty string, for no credential. aws_sns and aws_sqs require one at delivery time, as does kafka when sasl is set. |
token | String! | Unique identifier for the new connector within the tenant. Letters, digits, hyphens and underscores, starting with a letter or digit, at most 128 characters. |
type | String! | The connector type; must be one of the values returned by connectorTypes that this deployment can deliver to. A recognized type with no delivery client in this build is refused with extensions.code UNSUPPORTED. |
ConnectorSearchCriteria
input
Filter and paging for the connectors query.
| Input field | Type | Description |
|---|---|---|
pageNumber | Int! | Page to return, starting at 1. A value below 1 is treated as 1. |
pageSize | Int! | Connectors per page. A value below 1 is treated as 100; a value above 1000 is capped at 1000. |
type | String | Return only connectors of this type. Omit it to return every type. |
ConnectorUpdateRequest
input
A partial update to a connector's draft. Omit a field to leave the stored value alone, send a value to set it, or send an explicit null to clear it (except where noted). The connector is named by the mutation's token argument, so there is no token here; use renameConnector to change the token.
| Input field | Type | Description |
|---|---|---|
config | String | New connection settings, as a JSON object serialized to a string of at most 64 KiB. Omit it to keep the stored config; an explicit null is refused. It is validated against the connector's type after this update is applied. |
description | String | New description, or null to clear it. |
name | String | New name, or null to clear it. |
secret | String | The write-only credential. Omit it to keep the stored credential, send a value to replace it, or send null or an empty string to delete it. |
type | String | New connector type. Omit it to keep the stored type; an explicit null is refused. The stored config is checked against the new type, so a change that leaves the config invalid for it is rejected. |