API Reference WorkOS SDK for Elixir v#3.0.1

Copy Markdown View Source

Modules

WorkOS SDK for Elixir.

AccessTokenAgentRegistrationCredentialIssuedDataDetail model.

ActionAuthenticationDenied model.

ActionUserRegistrationDenied model.

AuthKit Actions request verification and response signing.

The user or API key that performed an action.

AddRolePermission model.

Operations for the AdminPortal API.

AgentAdminLinkClaimAttemptToExternalUserRequest model.

The user to attach to the claim attempt, identified by email and external ID.

AgentAdminValidateCredentialRequest model.

AgentAdminValidateCredentialRequestType enum.

AgentCredentialValidation model.

AgentRegistration model.

The agent identity associated with this registration.

AgentRegistrationClaim model.

AgentRegistrationClaimAttemptCreated model.

AgentRegistrationClaimClaimCompletion model.

AgentRegistrationClaimCompleted model.

The user who completed the claim.

AgentRegistrationCreated model.

The agent identity for this registration.

AgentRegistrationCreatedDataKind enum.

AgentRegistrationCreatedDataMethod enum.

AgentRegistrationCreatedDataStatus enum.

AgentRegistrationCredentialIssued model.

AgentRegistrationCredentialIssuedDataDetail model.

AgentRegistrationDeleted model.

AgentRegistrationExpired model.

AgentRegistrationKind enum.

AgentRegistrationOrganizationSwitched model.

AgentRegistrationRefreshed model.

AgentRegistrationRevoked model.

AgentRegistrationStatus enum.

Operations for the Agents API.

A non-2xx response from the API.

ApiKey model.

ApiKeyCreated model.

The event payload.

ApiKeyCreatedDataOwner model.

ApiKeyInstallation model.

ApiKeyOwner model.

ApiKeyRevoked model.

The event payload.

ApiKeyRevokedDataOwner model.

ApiKeyUpdated model.

The event payload.

ApiKeyUpdatedDataOwner model.

Previous API key attributes before the update.

ApiKeyValidationResponse model.

Operations for the ApiKeys API.

ApplicationCredentialsListItem model.

ApplicationsRegistrationTypes enum.

AssignRole model.

AuditLogAction model.

AuditLogConfiguration model.

The Audit Log Stream currently configured for the organization, if any.

AuditLogConfigurationLogStreamState enum.

AuditLogConfigurationLogStreamType enum.

AuditLogConfigurationState enum.

AuditLogEvent model.

AuditLogEventActor model.

AuditLogEventContext model.

AuditLogEventCreateResponse model.

AuditLogEventIngestion model.

AuditLogEventTarget model.

AuditLogExport model.

AuditLogExportCreation model.

AuditLogExportState enum.

AuditLogSchema model.

The metadata schema for the actor.

AuditLogSchemaActorInput model.

AuditLogSchemaInput model.

AuditLogSchemaTarget model.

AuditLogSchemaTargetInput model.

Operations for the AuditLogs API.

AuditLogsRetention model.

Higher-level AuthKit authentication flow helpers.

AuthMethodMismatchError model.

AuthenticateResponse model.

AuthenticateResponseAuthenticationMethod enum.

Information about the impersonator if this session was created via impersonation.

The OAuth tokens from the identity provider, if applicable.

AuthenticationChallenge model.

AuthenticationChallengeVerifyResponse model.

AuthenticationChallengesVerifyRequest model.

AuthenticationEmailVerificationFailed model.

Details about the authentication error.

AuthenticationEmailVerificationSucceeded model.

AuthenticationFactor model.

AuthenticationFactorEnrolled model.

SMS-based authentication factor details.

TOTP-based authentication factor details. Includes enrollment secrets only available at creation time.

AuthenticationFactorEnrolledType enum.

SMS-based authentication factor details.

TOTP-based authentication factor details.

AuthenticationFactorType enum.

AuthenticationFactorsCreateRequest model.

AuthenticationFactorsCreateRequestType enum.

AuthenticationMFAFailed model.

Details about the authentication error.

AuthenticationMFASucceeded model.

AuthenticationMagicAuthFailed model.

Details about the authentication error.

AuthenticationMagicAuthSucceeded model.

AuthenticationOAuthFailed model.

Details about the authentication error.

AuthenticationOAuthSucceeded model.

AuthenticationPasskeyFailed model.

Details about the authentication error.

AuthenticationPasskeySucceeded model.

AuthenticationPasswordFailed model.

Details about the authentication error.

AuthenticationPasswordSucceeded model.

AuthenticationRadarRiskDetected model.

AuthenticationRadarRiskDetectedDataAction enum.

AuthenticationReauthenticationSucceeded model.

AuthenticationSSOFailed model.

Details about the authentication error.

SSO connection details.

AuthenticationSSOStarted model.

SSO connection details.

AuthenticationSSOSucceeded model.

AuthenticationSSOTimedOut model.

Details about the authentication error.

SSO connection details.

Operations for the Authorization API.

AuthorizationAssignment enum.

AuthorizationCheck model.

AuthorizationCodeSessionAuthenticateRequest model.

AuthorizationPermission model.

AuthorizationResource model.

AuthorizedConnectApplicationListData model.

CORSOriginResponse model.

Nil-safe casting helpers used by generated from_map/1 and to_map/1 functions. Unexpected shapes pass through unchanged (lenient casting), so new or malformed API payloads never crash the SDK.

ChallengeAuthenticationFactor model.

CheckAuthorization model.

ClaimViewResponse model.

ClaimViewResponseOrganization model.

ClaimViewResponseStatus enum.

HTTP client for the WorkOS API.

Operations for the ClientApi API.

ClientApiToken model.

ClientApiTokenResponse model.

Missing or invalid client configuration (e.g. no API key). Raised from WorkOS.Client.new/1 — configuration problems are programmer errors, not runtime failures.

ConfigureDataIntegrationBody model.

ConfirmEmailChange model.

Operations for the Connect API.

ConnectApplication model.

ConnectApplicationM2M model.

ConnectApplicationOAuth model.

ConnectApplicationOAuthRedirectUris model.

ConnectApplicationRedirectUri model.

ConnectedAccount model.

ConnectedAccountAuthMethod enum.

ConnectedAccountInput model.

ConnectedAccountInputState enum.

ConnectedAccountState enum.

Connection model.

ConnectionActivated model.

The event payload.

ConnectionActivatedDataConnectionType enum.

ConnectionActivatedDataDomain model.

ConnectionActivatedDataState enum.

ConnectionActivatedDataStatus enum.

ConnectionDeactivated model.

ConnectionDeactivatedDataConnectionType enum.

ConnectionDeactivatedDataDomain model.

ConnectionDeactivatedDataState enum.

ConnectionDeactivatedDataStatus enum.

ConnectionDeleted model.

The event payload.

ConnectionDeletedDataConnectionType enum.

ConnectionDeletedDataState enum.

ConnectionDomain model.

ConnectionSAMLCertificateRenewalRequired model.

ConnectionSAMLCertificateRenewalRequiredDataCertificateCertificateType enum.

The connection with the expiring certificate.

ConnectionSAMLCertificateRenewed model.

The renewed SAML certificate details.

ConnectionSAMLCertificateRenewedDataCertificateCertificateType enum.

The connection with the renewed certificate.

ConnectionState enum.

ConnectionStatus enum.

ConnectionType enum.

ConnectionsConnectionType enum.

CreateApplicationSecret model.

CreateAuthorizationPermission model.

CreateAuthorizationResource model.

CreateCORSOrigin model.

CreateDataIntegration model.

CreateDataIntegrationAuthMethods enum.

CreateDataKeyRequest model.

CreateDataKeyResponse model.

CreateGroup model.

CreateGroupMembership model.

CreateGroupRoleAssignment model.

CreateM2MApplication model.

CreateMagicCodeAndReturn model.

CreateOAuthApplication model.

CreateObjectRequest model.

CreateOrganizationApiKey model.

CreateOrganizationDomain model.

CreateOrganizationRole model.

CreatePasswordReset model.

CreatePasswordResetToken model.

CreateRedirectUri model.

CreateRole model.

CreateUser model.

CreateUserApiKey model.

CreateUserInviteOptions model.

CreateUserInviteOptionsLocale enum.

CreateUserOrganizationMembership model.

CreateUserPasswordHashType enum.

CreateWebhookEndpoint model.

CreateWebhookEndpointEvents enum.

CustomProviderDefinition model.

CustomProviderDefinitionAuthenticateVia enum.

DataIntegration model.

DataIntegrationAccessTokenResponse model.

The access token object, present when active is true.

DataIntegrationAccessTokenResponseError enum.

DataIntegrationAuthMethods enum.

DataIntegrationAuthorizeUrlResponse model.

DataIntegrationConfigurationListResponse model.

DataIntegrationConfigurationResponse model.

The credentials configured for the Data Integration.

DataIntegrationCredentialType enum.

Organization-managed OAuth credential configuration. Present only for integrations whose credentials are supplied by the organization; absent otherwise.

DataIntegrationCredentialsCredentialsType enum.

DataIntegrationCredentialsInput model.

DataIntegrationCredentialsInputType enum.

DataIntegrationCredentialsResponse model.

The credential object containing the vended secret.

DataIntegrationCredentialsResponseError enum.

DataIntegrationCustomProvider model.

DataIntegrationCustomProviderAuthenticateVia enum.

DataIntegrationInstallation model.

DataIntegrationState enum.

DataIntegrationsGetDataIntegrationAuthorizeUrlRequest model.

DataIntegrationsGetUserTokenRequest model.

DataIntegrationsListResponse model.

DataIntegrationsListResponseData model.

DataIntegrationsListResponseDataAuthMethods enum.

DataIntegrationsListResponseDataConnectedAccount model.

DataIntegrationsListResponseDataConnectedAccountAuthMethod enum.

DataIntegrationsListResponseDataConnectedAccountState enum.

DataIntegrationsListResponseDataOwnership enum.

DataIntegrationsUpsertApiKeyRequest model.

DataIntegrationsVendCredentialsRequest model.

DecryptRequest model.

DecryptResponse model.

DeleteGroupRoleAssignmentsByCriteria model.

DeleteObjectResponse model.

DeviceAuthorizationResponse model.

DeviceCodeSessionAuthenticateRequest model.

Directory model.

DirectoryGroup model.

Aggregate counts of directory users and groups synced from the provider.

Counts of active and inactive directory users.

DirectoryState enum.

Operations for the DirectorySync API.

DirectoryType enum.

DirectoryUser model.

DirectoryUserEmail model.

DirectoryUserState enum.

DirectoryUserWithGroups model.

DirectoryUserWithGroupsEmail model.

DirectoryUserWithGroupsState enum.

DsyncActivated model.

The event payload.

DsyncActivatedDataDomain model.

DsyncActivatedDataState enum.

DsyncActivatedDataType enum.

DsyncDeleted model.

The event payload.

DsyncDeletedDataState enum.

DsyncDeletedDataType enum.

DsyncGroupCreated model.

DsyncGroupDeleted model.

DsyncGroupUpdated model.

The event payload.

DsyncGroupUserAdded model.

The event payload.

DsyncGroupUserRemoved model.

DsyncTokenCreated model.

The event payload.

DsyncTokenRevoked model.

The event payload.

DsyncUserCreated model.

DsyncUserDeleted model.

DsyncUserUpdated model.

The event payload.

DsyncUserUpdatedDataEmail model.

DsyncUserUpdatedDataState enum.

EmailChange model.

EmailChangeConfirmation model.

EmailVerification model.

EmailVerificationCodeSessionAuthenticateRequest model.

EmailVerificationCreated model.

EnrollUserAuthenticationFactor model.

Union of the error values SDK functions can return in {:error, error} tuples.

Error response body.

Additional context about the event.

The actor who performed the action.

EventContextActorSource enum.

EventContextGoogleAnalyticsSession model.

An event emitted by WorkOS.

Operations for the Events API.

ExpireApiKey model.

ExternalAuthCompleteResponse model.

FeatureFlag model.

FeatureFlagOwner model.

Operations for the FeatureFlags API.

Flag model.

FlagCreated model.

Additional context about the event.

The actor who performed the action.

FlagCreatedContextActorSource enum.

The event payload.

FlagCreatedDataOwner model.

FlagDeleted model.

Additional context about the event.

The actor who performed the action.

FlagDeletedContextActorSource enum.

The event payload.

FlagDeletedDataOwner model.

FlagOwner model.

FlagRuleUpdated model.

Additional context about the event.

FlagRuleUpdatedContextAccessType enum.

The actor who performed the action.

FlagRuleUpdatedContextActorSource enum.

The configured targets for the flag rule.

FlagRuleUpdatedContextConfiguredTargetOrganization model.

FlagRuleUpdatedContextConfiguredTargetUser model.

Attributes that changed from their previous values.

The previous context attributes of the flag rule.

FlagRuleUpdatedContextPreviousAttributeContextAccessType enum.

The previous configured targets for the flag rule.

FlagRuleUpdatedContextPreviousAttributeContextConfiguredTargetOrganization model.

FlagRuleUpdatedContextPreviousAttributeContextConfiguredTargetUser model.

The previous data attributes of the flag.

The event payload.

FlagRuleUpdatedDataOwner model.

FlagUpdated model.

Additional context about the event.

The actor who performed the action.

FlagUpdatedContextActorSource enum.

Attributes that changed from their previous values.

The previous data attributes of the flag.

The event payload.

FlagUpdatedDataOwner model.

GenerateLink model.

GenerateLinkIntent enum.

Group model.

GroupCreated model.

GroupDeleted model.

GroupMemberAdded model.

The event payload.

GroupMemberRemoved model.

The event payload.

GroupRoleAssignment model.

GroupRoleAssignmentList model.

The resource the role is assigned on.

GroupUpdated model.

Operations for the Groups API.

Invitation model.

InvitationAccepted model.

The event payload.

InvitationAcceptedDataState enum.

InvitationCreated model.

The event payload.

InvitationCreatedDataState enum.

InvitationResent model.

The event payload.

InvitationResentDataState enum.

InvitationRevoked model.

The event payload.

InvitationRevokedDataState enum.

InvitationState enum.

JWKS (JSON Web Key Set) helpers for token and session verification.

JWTTemplateResponse model.

JwksResponse model.

JwksResponseKeys model.

Cursor-based pagination metadata.

MFATotpSessionAuthenticateRequest model.

MagicAuth model.

MagicAuthCodeSessionAuthenticateRequest model.

MagicAuthCreated model.

The event payload.

MagicAuthSendMagicAuthCodeAndReturnResponse model.

Operations for the MultiFactorAuth API.

NewConnectApplicationSecret model.

Metadata for a stored encrypted object.

Summary of an encrypted object returned in list responses.

A static snapshot of an encrypted object.

An encrypted object's metadata (value excluded).

Organization model.

OrganizationApiKey model.

The entity that owns the API Key.

OrganizationApiKeyWithValue model.

The entity that owns the API Key.

OrganizationAuthorizedConnectApplicationListData model.

OrganizationCreated model.

The event payload.

OrganizationCreatedDataDomain model.

OrganizationCreatedDataDomainState enum.

OrganizationCreatedDataDomainVerificationStrategy enum.

OrganizationDeleted model.

The event payload.

OrganizationDeletedDataDomain model.

OrganizationDeletedDataDomainState enum.

OrganizationDeletedDataDomainVerificationStrategy enum.

OrganizationDomain model.

OrganizationDomainCreated model.

OrganizationDomainCreatedDataState enum.

OrganizationDomainCreatedDataVerificationStrategy enum.

OrganizationDomainData model.

OrganizationDomainDataState enum.

OrganizationDomainDeleted model.

OrganizationDomainDeletedDataState enum.

OrganizationDomainDeletedDataVerificationStrategy enum.

OrganizationDomainState enum.

OrganizationDomainUpdated model.

OrganizationDomainUpdatedDataState enum.

OrganizationDomainUpdatedDataVerificationStrategy enum.

OrganizationDomainVerificationFailed model.

The organization domain that failed verification.

OrganizationDomainVerificationFailedDataOrganizationDomainState enum.

OrganizationDomainVerificationFailedDataOrganizationDomainVerificationStrategy enum.

OrganizationDomainVerificationFailedDataReason enum.

OrganizationDomainVerificationStrategy enum.

OrganizationDomainVerified model.

OrganizationDomainVerifiedDataState enum.

OrganizationDomainVerifiedDataVerificationStrategy enum.

Operations for the OrganizationDomains API.

OrganizationInput model.

OrganizationMembership model.

OrganizationMembershipCreated model.

OrganizationMembershipCreatedDataStatus enum.

OrganizationMembershipDeleted model.

OrganizationMembershipDeletedDataStatus enum.

Operations for the OrganizationMembership API.

OrganizationMembershipStatus enum.

OrganizationMembershipUpdated model.

OrganizationMembershipUpdatedDataStatus enum.

OrganizationRoleCreated model.

OrganizationRoleDeleted model.

OrganizationRoleUpdated model.

OrganizationSelectionSessionAuthenticateRequest model.

OrganizationUpdated model.

The event payload.

OrganizationUpdatedDataDomain model.

OrganizationUpdatedDataDomainState enum.

OrganizationUpdatedDataDomainVerificationStrategy enum.

Operations for the Organizations API.

PKCE (Proof Key for Code Exchange, RFC 7636) utilities for public-client authentication flows.

A single page of results with lazy auto-pagination.

PaginationOrder enum.

PasswordReset model.

PasswordResetCreated model.

The event payload.

PasswordResetSucceeded model.

PasswordSessionAuthenticateRequest model.

Magic Link passwordless sessions.

A passwordless (Magic Link) session.

Permission model.

PermissionCreated model.

The event payload.

PermissionDeleted model.

The event payload.

PermissionUpdated model.

The event payload.

PipeConnectedAccount model.

PipeConnectedAccountState enum.

Operations for the Pipes API.

PipesConnectedAccountConnected model.

PipesConnectedAccountConnectionFailed model.

PipesConnectedAccountDisconnected model.

PipesConnectedAccountReauthorizationNeeded model.

Operations for the PipesProvider API.

PortalLinkResponse model.

Profile model.

ProfileConnectionType enum.

A client preset for public (PKCE-only) applications — no API key required.

Operations for the Radar API.

RadarChallenge model.

RadarChallengeCreated model.

RadarEmailChallengeCodeSessionAuthenticateRequest model.

RadarListAction enum.

RadarListEntryAlreadyPresentResponse model.

RadarListType enum.

RadarSmsChallengeCodeSessionAuthenticateRequest model.

RadarStandaloneAssessRequest model.

RadarStandaloneAssessRequestAction enum.

RadarStandaloneAssessRequestAuthMethod enum.

RadarStandaloneDeleteRadarListEntryRequest model.

RadarStandaloneResponse model.

RadarStandaloneResponseBlocklistType enum.

RadarStandaloneResponseControl enum.

RadarStandaloneResponseVerdict enum.

RadarStandaloneUpdateRadarAttemptRequest model.

RadarStandaloneUpdateRadarListRequest model.

RedirectUri model.

RedirectUriInput model.

RefreshTokenSessionAuthenticateRequest model.

RekeyRequest model.

RemoveRole model.

ReplaceGroupRoleAssignmentEntry model.

ReplaceGroupRoleAssignments model.

ResendUserInviteOptions model.

ResendUserInviteOptionsLocale enum.

ResetPasswordResponse model.

RevokeSession model.

Role model.

RoleCreated model.

The event payload.

RoleDeleted model.

The event payload.

RoleList model.

RoleType enum.

RoleUpdated model.

The event payload.

Operations for the SSO API.

End-to-end SSO logout: authorizes a short-lived logout token via WorkOS.SSO.authorize_logout/3, then builds the logout redirect URL.

PKCE helpers for the SSO authorization-code flow (public clients).

SSOAuthorizeUrlResponse model.

SSODeviceAuthorizationRequest model.

SSOLogoutAuthorizeRequest model.

SSOLogoutAuthorizeResponse model.

SSOProvider enum.

SSOTokenResponse model.

OAuth tokens issued by the identity provider, if available.

SendEmailChange model.

SendRadarSmsChallenge model.

SendRadarSmsChallengeResponse model.

SendVerificationEmailResponse model.

Sealed session-cookie management for AuthKit.

SessionCreated model.

The event payload.

SessionCreatedDataAuthMethod enum.

Information about the impersonator if this session was created via impersonation.

SessionCreatedDataStatus enum.

SessionRevoked model.

The event payload.

SessionRevokedDataAuthMethod enum.

Information about the impersonator if this session was created via impersonation.

SessionRevokedDataStatus enum.

SetRolePermissions model.

The primary role assigned to the user.

TokenQuery model.

A network-level failure (DNS, timeout, connection refused).

UpdateAuditLogsRetention model.

UpdateAuthorizationPermission model.

UpdateAuthorizationResource model.

UpdateCustomProviderDefinition model.

UpdateCustomProviderDefinitionAuthenticateVia enum.

UpdateDataIntegration model.

UpdateGroup model.

UpdateJWTTemplate model.

UpdateOAuthApplication model.

UpdateObjectRequest model.

UpdateOrganization model.

UpdateOrganizationRole model.

UpdateRole model.

UpdateUser model.

UpdateUserOrganizationMembership model.

UpdateUserPasswordHashType enum.

UpdateWebhookEndpoint model.

UpdateWebhookEndpointEvents enum.

UpdateWebhookEndpointStatus enum.

The user object.

UserApiKey model.

UserApiKeyCreatedDataOwner model.

The entity that owns the API Key.

UserApiKeyRevokedDataOwner model.

UserApiKeyUpdatedDataOwner model.

UserApiKeyWithValue model.

The entity that owns the API Key.

UserAuthenticationFactorEnrollResponse model.

UserConsentOption model.

UserConsentOptionChoice model.

UserCreateResponse model.

UserCreated model.

UserDeleted model.

UserIdentitiesGetItem model.

UserIdentitiesGetItemProvider enum.

UserInvite model.

UserInviteState enum.

Operations for the UserManagement API.

UserManagementAuthenticationProvider enum.

UserManagementAuthenticationScreenHint enum.

UserManagementLoginRequest model.

UserManagementOrganizationMembershipStatuses enum.

UserObject model.

UserOrganizationMembership model.

UserOrganizationMembershipBaseListData model.

UserOrganizationMembershipBaseListDataStatus enum.

UserOrganizationMembershipStatus enum.

UserRoleAssignment model.

The resource the role is assigned on.

The origin of the role assignment.

UserRoleAssignmentSourceType enum.

UserSessionsAuthMethod enum.

Information about the impersonator if this session was created via impersonation.

UserSessionsListItem model.

UserSessionsStatus enum.

UserUpdated model.

ValidateApiKey model.

Operations for the Vault API.

Client-side Vault encryption and decryption, layered on the WorkOS data-key API (WorkOS.Vault.create_data_key/3 and WorkOS.Vault.create_decrypt/3).

VaultByokKeyDeleted model.

The event payload.

VaultByokKeyProvider enum.

VaultByokKeyVerificationCompleted model.

VaultDataCreated model.

The event payload.

VaultDataCreatedDataActorSource enum.

VaultDataDeleted model.

The event payload.

VaultDataDeletedDataActorSource enum.

VaultDataRead model.

The event payload.

VaultDataReadDataActorSource enum.

VaultDataUpdated model.

The event payload.

VaultDataUpdatedDataActorSource enum.

VaultDekDecrypted model.

The event payload.

VaultDekDecryptedDataActorSource enum.

VaultDekRead model.

The event payload.

VaultDekReadDataActorSource enum.

VaultKekCreated model.

The event payload.

VaultKekCreatedDataActorSource enum.

VaultKekDeleted model.

The event payload.

VaultKekDeletedDataActorSource enum.

VaultMetadataRead model.

The event payload.

VaultMetadataReadDataActorSource enum.

VaultNamesListed model.

The event payload.

VaultNamesListedDataActorSource enum.

An encrypted object with its decrypted value and metadata.

VaultOrder enum.

VerifyEmailAddress model.

VerifyEmailResponse model.

VersionListResponse model.

WaitlistUser model.

WaitlistUserApproved model.

WaitlistUserCreated model.

WaitlistUserDenied model.

WaitlistUserState enum.

WebhookEndpoint model.

WebhookEndpointStatus enum.

Operations for the Webhooks API.

WorkOS webhook signature verification.

WidgetSessionToken model.

WidgetSessionTokenResponse model.

WidgetSessionTokenScopes enum.

Operations for the Widgets API.