Skip to main content
MUTATION
appsAdd(name: String, userGroupId: String, workspaceId: String, expireDate: Date, allowAllPermission: Boolean, noExpire: Boolean): AppTokenResult

Arguments

name
String

Display name for the Developer dashboard and apps search. Strongly recommended for identifying credentials later.

userGroupId
String

User group that defines this app's permissions. Required unless allowAllPermission is true. Do not pass an empty string — omit the field when using allow-all. Locked after creation.

workspaceId
String

Optional workspace id for multi-workspace tenants. Usually inherited from the authenticated context — set only when targeting a specific workspace.

expireDate
Date

Token expiry when noExpire is false or omitted. Ignored when noExpire is true.

allowAllPermission
Boolean

When true, grants full workspace permissions and userGroupId may be omitted. Prefer a dedicated user group with least privilege for production. Locked after creation.

noExpire
Boolean

When true, the JWT does not expire (still revoke via appsRemove). When false or omitted, set expireDate for a finite lifetime.

_id
String

Id of the newly created app (same as App._id).

accessToken
String

Full JWT for the x-app-token header on public GraphQL and hosted MCP requests. Shown in full once — treat like a password. Later App reads expose only **** + last 4 characters.

Mutation
Response
آخر تعديل في ١١ أغسطس ٢٠٢٦