Start guide
Get from a signed event to a waiting task, then read the lead back.
Connect ingests partner events, runs durable workflows, and lets operators decide waiting work in the portal. This guide covers the three first-success paths.
PartnerPOST
OperatorReview
IntegratorGET
Partner — post a signed event
Use this when an external system should start work without logging into Authentik.
- An operator registers a webhook app on Portal Webhooks → Apps and copies the HMAC secret (shown once).
- Sign the raw request body with HMAC-SHA256 and send
X-Partner-Signature: sha256=<hex>. - POST to
https://connect.intronsoft.com/api/v1/webhooks/partners/{appId}/events. - First accept returns 202. The event appears on Webhooks → Events. A matching catalog workflow starts under the same correlation id.
BODY='{"eventType":"contact.lead","externalId":"lead-1001","data":"{\"email\":\"ada@example.com\"}"}'
SIG=$(echo -n "$BODY" | openssl dgst -sha256 -hmac "$HMAC_SECRET" | awk '{print $2}')
curl -sS -D - -o /tmp/connect-webhook.json \
-X POST "https://connect.intronsoft.com/api/v1/webhooks/partners/acme/events" \
-H "Content-Type: application/json" \
-H "X-Partner-Signature: sha256=$SIG" \
-d "$BODY"Full header contract: Sign requests.
Operator — review a waiting task
Use this when a workflow is waiting on a person.
- Sign in to the management portal.
- Open Tasks. Waiting runs with an operator prompt appear here.
- Open the run, or act from the composer: Approve, Reject, or Submit form data.
- The run graph marks the taken exit. Approve on
contact-leadcreates a Plane issue. Reject or timeout skips Plane; the run still Completed.
Integrator — read leads with an API key
Use this when another product needs approved leads.
- An operator creates a consumer on Portal Consumers and grants
contact-leads. - Copy the API key once.
- Call Experience APIs with
X-API-KEY.
curl -sS \
-H "X-API-KEY: $CONNECT_API_KEY" \
"https://connect.intronsoft.com/api/v1/leads?limit=10"What you will see
AcceptedDuplicateWaitingCompleted
| In Portal | Meaning |
|---|---|
| Webhooks → Events, Accepted | HMAC verified; workflow start pending or running |
| Webhooks → Events, Duplicate | Same (partnerId, externalId) — no second run |
| Tasks / Runs, Waiting | A listen hop needs Review |
| Runs, Completed | Terminal success, including reject/timeout on contact-lead |
Next
- Concepts — how the objects compose
- Sign requests — HMAC details
- Try the API — OpenAPI playground