Sign in with Orkestia
Your app authenticates end-users against Orkestia and lets them run workflows scoped to themselves.
Orkestia2 min readUpdated
Orkestia is the backbone that connects software, AI, and the real world. Sign in with Orkestia is how your app authenticates its end-users. The user signs in on a hosted login. Their token is the token that starts the workflows you exposed to them. One identity, one history, scoped to that person, not to your operator console.
This is public core, next to SPAD, Runners, and Kaoitos. Your app keeps its UI. Orkestia keeps login, permission, and the run.
What you provision
You provision an identity app. The call returns a public client key and the PKCE endpoints. You wire a PKCE flow in your app. End-users never see the operator console. An end-user token must not work on member surfaces.
The recipe in the MCP docs is one call: provision, then wire. The namespace
instructions call it identity.app.provision. Confirm against
get_workflow_schema before you start it. The live names are in
the catalog, identity domain.
Install the SDK:
npm i github:ltinteg/ltinteg-orkestia-auth-sdk
Create an account, subscribe, provision the app, put the callback URL where the schema says.
What the end-user can run
Only the workflows you marked as available to them. A charge, an Omie title, a Bling list, whatever you exposed. The run is recorded as that end-user. Your operator members still have the console. The two classes do not mix.
AppData is where the app stores records for those users: AppData: records that belong to the app.
Seats
End-user seats are on the published plan. Amounts live on pricing. How seats work: Billing and seats. Do not invent a second price list.
From MCP, as the builder
whoami()
list_workflow_types(prefix="identity.")
get_workflow_schema("identity.app.provision")
start_workflow(workflow_type="identity.app.provision", initial_data={...})
If that exact type name has moved, list_workflow_types(prefix="identity.")
is the source of truth. The catalog wins.
PKCE, not a password form you built
The hosted login is the page the end-user sees. Your app starts PKCE, the user signs in, your app receives the callback. You do not store their password. You do not send them to the Orkestia operator console.
The token you get back is the token you pass when that user starts a workflow you exposed. "Charge this card" and "list my orders" are then attributed to that person, rate-limited as that person, and blocked if you never marked the type as available to end-users.
A first afternoon:
- Subscribe. Provision the identity app. Put the client key in your app config, not in a public repo if the schema says it is secret. The public client key is public. Anything else is not.
- Wire PKCE with the SDK. Complete one sign-in as a fake end-user.
- Start one exposed read-only workflow as that user. Open the history as the operator. The actor should be the end-user, not you.
If provision's exact type name differs from identity.app.provision, the
catalog wins. Call list_workflow_types(prefix="identity.").
What to read next
- identity
- apps
