# WorkOS integration

> Enterprise auth and identity platform — SSO, Directory Sync (SCIM), User Management (AuthKit), Audit Logs, and an event stream.

- Authentication: apiKey

## Tools (89)

- **Accept an Invitation**: Accept an invitation and activate membership.
- **Authenticate a User**: Authenticate a user and mint a session (all grant types).
- **Challenge a Factor**: Create an MFA challenge for an enrolled factor.
- **Confirm Email Change**: Confirm a user's email change with the emailed one-time code.
- **Create a CORS Origin**: Add an allowed CORS origin for the environment.
- **Create a Magic Auth**: Generate and email a one-time Magic Auth code.
- **Create an Audit Log Event**: Emit an audit log event for an organization.
- **Create an Audit Log Export**: Start an audit log export for a date range.
- **Create an Audit Log Schema**: Create a validation schema for an audit log action.
- **Create an Organization**: Create a new organization.
- **Create an Organization Domain**: Add a domain to an organization.
- **Create an Organization Membership**: Add a user to an organization.
- **Create a Passwordless Session**: Create a Magic Link passwordless session.
- **Create a Password Reset**: Create a one-time password-reset token for a user.
- **Create a User**: Create a new User Management user.
- **Deactivate an Organization Membership**: Deactivate an active organization membership.
- **Delete a Connection**: Permanently delete an SSO connection.
- **Delete a Directory**: Permanently delete a directory.
- **Delete a Factor**: Permanently delete a standalone MFA factor.
- **Delete an Authorized Application**: Revoke a user's authorization for a Connect application.
- **Delete an Organization**: Permanently delete an organization.
- **Delete an Organization Domain**: Permanently delete an organization domain.
- **Delete an Organization Membership**: Permanently remove a user from an organization.
- **Delete a User**: Permanently delete a User Management user.
- **Disconnect a Connected Account**: Disconnect a user's connected account for a provider.
- **Enroll a Factor**: Enroll a standalone MFA factor (TOTP or SMS).
- **Enroll an Authentication Factor**: Enroll an MFA authentication factor for a user.
- **Generate a Portal Link**: Generate a short-lived Admin Portal link for an organization.
- **Get a Connected Account**: Retrieve a user's connected account for a provider.
- **Get a Connection**: Retrieve a single SSO connection by ID.
- **Get a Directory**: Retrieve a single directory by ID.
- **Get a Directory Group**: Retrieve a single directory group by ID.
- **Get a Directory User**: Retrieve a single directory user by ID.
- **Get a Factor**: Retrieve a standalone MFA factor by ID.
- **Get a Magic Auth**: Retrieve a Magic Auth record by ID.
- **Get an Audit Log Export**: Retrieve an audit log export and its download URL.
- **Get an Email Verification**: Retrieve an email verification record by ID.
- **Get an Invitation**: Retrieve an invitation by ID.
- **Get an Invitation by Token**: Retrieve an invitation using its acceptance token.
- **Get an Organization**: Retrieve a single organization by ID.
- **Get an Organization by External ID**: Retrieve an organization by the external ID you assigned.
- **Get an Organization Domain**: Retrieve a single organization domain by ID.
- **Get an Organization Membership**: Retrieve an organization membership by ID.
- **Get an SSO Profile**: Fetch a user's SSO profile using an access token.
- **Get a Password Reset**: Retrieve a password-reset record by ID.
- **Get a Profile and Token**: Exchange the SSO authorization code for a profile and access token.
- **Get a User**: Retrieve a single User Management user by ID.
- **Get a User by External ID**: Retrieve a User Management user by external ID.
- **Get a Widget Token**: Mint a scoped token for embedding a WorkOS widget.
- **Get JWKS**: Fetch the JSON Web Key Set for verifying WorkOS-issued tokens.
- **Get Logout URL**: Build the AuthKit logout redirect URL (browser flow).
- **Get SSO Authorization URL**: Build the SSO authorization redirect URL (browser flow).
- **Get SSO Logout URL**: Generate an RP-initiated SSO logout token and redirect (legacy standalone SSO).
- **Import a Connected Account**: Import a connected account for a user by supplying OAuth tokens.
- **List Audit Log Actions**: List audit log actions in the environment.
- **List Audit Log Schemas**: List the schemas for an audit log action.
- **List a User's Identities**: List a user's linked identity-provider identities.
- **List Authentication Factors**: List a user's enrolled MFA factors.
- **List Authorized Applications**: List the Connect applications a user has authorized.
- **List Connections**: List SSO connections with filtering and pagination.
- **List CORS Origins**: List allowed CORS origins with pagination.
- **List Directories**: List directories with filtering and pagination.
- **List Directory Groups**: List directory-synced groups with filtering and pagination.
- **List Directory Users**: List directory-synced users with filtering and pagination.
- **List Events**: Pull the ordered stream of environment events (poll by cursor).
- **List Groups for a Membership**: List the directory groups tied to an organization membership.
- **List Invitations**: List invitations with filtering and pagination.
- **List Organization Memberships**: List organization memberships with filtering and pagination.
- **List Organization Roles**: List roles available to a specific organization.
- **List Organizations**: List organizations with filtering and pagination.
- **List Roles**: List environment-level roles.
- **List Sessions**: List a user's active sessions.
- **List Users**: List User Management users with filtering and pagination.
- **Reactivate an Organization Membership**: Reactivate an inactive organization membership.
- **Resend an Invitation**: Resend a pending invitation email.
- **Reset the Password**: Set a new password using a password-reset token.
- **Revoke an Invitation**: Cancel a pending invitation.
- **Revoke a Session**: Revoke an active user session.
- **Send an Invitation**: Invite a user by email to sign up or join an organization.
- **Send a Passwordless Session**: Email the Magic Link for a passwordless session.
- **Send Email Change**: Send a one-time code to verify a user's requested new email.
- **Send Verification Email**: Send a one-time email-verification code to a user.
- **Update a Connected Account**: Update a user's connected account tokens, scopes, or state.
- **Update an Organization**: Update an existing organization.
- **Update an Organization Membership**: Update an organization membership's roles.
- **Update a User**: Update a User Management user.
- **Verify a Challenge**: Verify an MFA challenge with the user's code.
- **Verify an Organization Domain**: Start verification for an organization domain.
- **Verify Email Code**: Confirm a user's email with the emailed code.

## Triggers (1)

- **New Event in WorkOS**: Triggers on new events in the WorkOS environment event stream (e.g. user.created, connection.activated, dsync.user.created). Filter by event type or leave empty to fire on every event.

Connect WorkOS in General Input: https://www.generalinput.com/apps/workos