List integrated accounts ​
Integrated accounts are created when a customer connects an app with Truto. You can use this endpoint to list all the integrated accounts that have been created for your Truto account.
Integrated accounts for a specific customer ​
You can filter the integrated accounts by specifying the tenant_id attribute in the query string. This is useful when you want to look up an integrated account for a specific customer.
Endpoint ​
GET /integrated-accountQuery parameters ​
Refer Specifying query parameters in Truto APIs
The ID of the tenant you want to filter the integrated accounts by.
acme-1Whether the integrated account is in sandbox mode or not. Sandbox integrated accounts do not allow any "write" operations.
The name of the integration you want to filter the integrated accounts by.
zendeskFilter the integrated accounts by the ones using SuperQuery. The value will be the SuperQuery region.
apacwnam
apacFilter the integrated accounts by status.
activeconnectingpost_install_errorvalidation_errorneeds_reauth
activeFilter the integrated accounts by the date and time when they were created.
2021-08-10T10:00:00.000ZFilter the integrated accounts by the date and time when they were last updated.
2021-08-10T10:00:00.000ZResponse Body ​
The ID of the integrated account.
1ba1f401-7183-47c5-9e39-e8e257e3c795The ID of the tenant.
acme-1The ID of the environment integration (installed integration).
b179ad55-db02-4bd4-b7a4-d2c173eee9aeThe context of the integrated account. You can find these in the Variables section of an integrated account in the Truto UI.
{
"zendesk_subdomain": "truto"
}Status of the integrated account.
active- Everything is fine and the account should workconnecting- Post install and validation steps are being runpost_install_error- There was an error while running post install stepsvalidation_error- There was an error while running validation stepsneeds_reauth- There was an error while refreshing the credentials in case of OAuth authentication or the credentials are no longer valid in other authentication methods. The integrated account needs to be reauthorized.
activeconnectingpost_install_errorvalidation_errorneeds_reauth
The last error that occurred while running the post install or validation steps.
The results of the post install and validation steps that ran on the integrated account.
The date and time when the integrated account was created.
2021-08-10T10:00:00.000ZThe date and time when the integrated account was last updated.
2021-08-10T10:00:00.000ZWhether the integrated account is in sandbox mode or not. Sandbox integrated accounts do not allow any "write" operations.
Type of authentication used.
oauth2api_keyoauth2_client_credentialskeka_oauth
The region where the integrated account is placed.
wnamenamapaceu
wnamThe ID of the environment this integrated account belongs to.
8a2b104d-74a6-47f2-b93e-c6b611e82391The integration associated with this integrated account.
The ID of the integration.
4a4de828-f4db-4c9e-adfd-434e0864c3c7The name of the integration.
zendeskThe category of the integration.
helpdeskWhether the integration is in beta or not. Beta integrations might not have been tested completely and are not recommended for production environments.
The configuration object defining the underlying API of the integration.
{
"base_url": "https://api.example.com",
"label": "Example API Integration",
"logo": "https://example.com/logo.png",
"icon": "https://example.com/icon.png",
"headers": {
"Content-Type": "application/json",
"Accept": "application/json",
"User-Agent": "truto"
},
"query": {
"search": "{{search_query}}",
"filter": "{{filter_criteria}}"
},
"query_array_format": "comma",
"actions": {
"sync_users": {
"type": "request",
"config": {
"method": "post",
"path": "/sync/users",
"headers": {
"Authorization": "Bearer {{oauth.token.access_token}}"
},
"body": {
"users": "{{context.users}}"
}
}
}
},
"credentials": {
"oauth2": {
"format": "oauth2",
"config": {
"client": {
"id": "your-client-id",
"secret": "your-client-secret"
},
"auth": {
"tokenHost": "https://auth.example.com",
"tokenPath": "/oauth/token",
"refreshPath": "/oauth/refresh"
},
"options": {
"scopeSeparator": " ",
"authorizationMethod": "header",
"bodyFormat": "form"
},
"fields": [
{
"name": "client_id",
"label": "Client ID",
"type": "text",
"required": true
},
{
"name": "client_secret",
"label": "Client Secret",
"type": "password",
"required": true
}
],
"tokenParams": {
"grant_type": "client_credentials"
},
"refreshParams": {
"grant_type": "refresh_token"
},
"tokenExpiryDuration": "3600"
}
}
},
"authorization": {
"format": "bearer",
"config": {
"token": "{{oauth.token.access_token}}"
}
},
"pagination": {
"format": "page",
"config": {
"page_key": "page",
"limit_key": "per_page"
}
},
"rate_limit": {
"is_rate_limited": true,
"retry_after_header_expression": "Retry-After",
"rate_limit_header_expression": "X-RateLimit-Remaining"
},
"resources": {
"users": {
"list": {
"method": "get",
"path": "/users",
"response_path": "data.users",
"headers": {
"Authorization": "Bearer {{oauth.token.access_token}}"
},
"query": {
"page": "{{pagination.page}}",
"per_page": "{{pagination.per_page}}"
},
"pagination": {
"format": "page",
"config": {
"page_key": "page",
"limit_key": "per_page"
}
},
"authorization": {
"format": "bearer",
"config": {
"token": "{{oauth.token.access_token}}"
}
},
"rate_limit": {
"is_rate_limited": true,
"retry_after_header_expression": "Retry-After",
"rate_limit_header_expression": "X-RateLimit-Remaining"
},
"examples": {
"response": "{\n \"data\": {\n \"users\": [\n {\n \"id\": \"123e4567-e89b-12d3-a456-426614174000\",\n \"name\": \"John Doe\",\n \"email\": \"john.doe@example.com\"\n }\n ]\n }\n}\n"
}
}
},
"orders": {
"create": {
"method": "post",
"path": "/orders",
"body": {
"user_id": "{{context.user_id}}",
"items": "{{context.items}}"
},
"response_path": "data.order",
"headers": {
"Authorization": "Bearer {{oauth.token.access_token}}"
},
"authorization": {
"format": "bearer",
"config": {
"value": "{{oauth.token.access_token}}"
}
}
}
}
},
"webhook": {
"signature_verification": {
"format": "hmac",
"config": {
"secret": "{{environment_variables.WEBHOOK_SECRET}}",
"algorithm": "sha256",
"string_type": "hex",
"compare_with": "{{headers.x-signature}}",
"parts": [
"raw_body"
]
}
},
"handle_verification": "{ 'type': webhook_type = 'verify' ? 'verify' : 'payload', 'verification_response': webhook_type = 'verify' ? { 'body': { 'challenge': body.challenge } } }"
},
"error_expression": "status >= 400 ? { 'status': status, 'message': data.error.message }"
}Default base URL prepended to every resource method's path.
https://api.example.comHuman-readable name shown in the Truto Dashboard and Link UI.
Example APIURL to the integration logo (square, recommended 256x256).
URL to a smaller monochrome icon used in catalog listings.
Default HTTP headers merged into every outbound request. Values may be templated with JSONata placeholders.
Default query-string params merged into every outbound request.
commabracketsindicesrepeat
Named integration actions. Reserved keys (post_install, post_connect_user_form, refresh_token, validation) hook into specific platform lifecycle events; custom names are callable from the proxy/sync runtime.
Either a single credential definition (when the integration only supports one auth format) or a map keyed by auth format (when an integration supports multiple, e.g. api_key and oauth2). For multi-format integrations, the customer picks one in the Link UI.
How Truto applies the resolved credential to outbound HTTP requests. The format discriminator selects which config shape applies.
All string values support Truto placeholders ({{path}}) resolved against the runtime context. Common placeholder roots: {{api_key}} for fields collected at connect time, {{oauth.token.access_token}} for OAuth2 access tokens, {{environment_variables.MY_KEY}} for env-vars set at the environment-integration level.
Pagination strategy for an integration or a single resource method. The format discriminator selects which config shape applies.
How Truto detects and reacts to upstream rate-limiting. All fields are JSONata expressions evaluated against the upstream response.
JSONata expression returning a truthy value when the response should be treated as rate-limited. When omitted, Truto falls back to status === 429.
Input: IntegrationRateLimitExpressionContext. Output: boolean.
status = 429JSONata expression returning the seconds to wait before retrying. When omitted, Truto reads the standard Retry-After header.
Input: IntegrationRateLimitExpressionContext. Output: number (seconds).
$number(headers.`retry-after`)JSONata expression returning the current rate-limit window state. Truto forwards this as RateLimit-Limit / RateLimit-Remaining / RateLimit-Reset headers in the proxy response.
Input: IntegrationRateLimitExpressionContext. Output: IntegrationRateLimitHeaderValues.
{ "limit": headers.`x-ratelimit-limit`, "remaining": headers.`x-ratelimit-remaining`, "reset": headers.`x-ratelimit-reset` }
Resource → method tree (e.g. resources.users.list). The inner key is one of the canonical methods (list, get, create, update, delete) or a custom method name. Each method definition matches IntegrationResourceMethod.
Optional tag arrays per resource, surfaced via the Truto MCP tools listing.
How Truto receives and verifies inbound webhooks for this integration. Not to be confused with WebhookSchema elsewhere in this spec, which describes Truto's outbound webhook delivered to your application.
Strategy used to verify the webhook signature before accepting it. Runs after payload_transform and after handle_verification returns { type: 'payload' }.
JSONata expression evaluated on every inbound webhook before signature verification. Use to:
- Respond to handshake pings (return
{ type: 'verify', verification_response: { status_code, body, headers } }). - Surface meta-events that should not fan out (return
{ type: 'meta' }). - Update the integrated account context (return
{ type: 'verify' \| 'payload' \| 'meta', update_context: { ... } }). - Pass through to fan-out (return
{ type: 'payload' }or omit entirely — defaults topayload).
Input: IntegrationWebhookPayloadContext. Output: IntegrationWebhookHandleVerificationResult.
JSONata expression that transforms the raw inbound payload before handle_verification and signature_verification see it. Use to normalize vendor-specific envelopes (e.g. unwrap a Salesforce payloads[] array, decode a base64 body).
Input: IntegrationWebhookPayloadContext. Output: IntegrationWebhookPayloadContext (the same shape — what you return becomes the new payload).
Integration-wide JSONata expression evaluated on every response. Use to detect errors in successful (2xx) responses, normalize error messages, or transform "errors" with < 400 status into successful responses. Overridden by per-method IntegrationResourceMethod.error_expression when set.
Input: IntegrationErrorExpressionContext. Output: IntegrationErrorExpressionResult — return null/undefined to indicate "no error", or a { status, message?, headers?, metadata?, result? } object.
The ID of the team that owns this integration.
05daecaf-4365-42e8-8370-8127de5dd717The sharing policy of the integration.
allowaskdeny
allowThe date and time when the integration was created.
2021-08-10T10:00:00.000ZThe date and time when the integration was last updated.
2021-08-10T10:00:00.000ZThe list of context fields that are stored in the object store.