Recued
Menu
← Back to packs

Identity and Access - Temporal Cloud

by recued-core v1 app_pack 15 views

Temporal Cloud users, service accounts, API keys, groups, custom roles, membership, and namespace access assignments. Generated from Temporal's byte- and hash-locked official v0.18.0 Cloud Ops OpenAPI (8eccf9183cd7…) at https://saas-api.tmprl.cloud/spec.json. This leaf carries 34 of all 87 official operations at the origin-pinned https://saas-api.tmprl.cloud boundary. Every call uses an encrypted Bearer API key inside the trusted connection adapter and remains subject to Temporal Cloud RBAC. All documented bodies are required bounded verbatim JSON objects; all responses are JSON with lossless unsafe integers. One-time API-key tokens and expiring billing-download URLs are labeled sensitive and excluded from reusable workflows. Documented page-token collections paginate at 100 records per request; a 1000 maximum is applied only where the provider declares it. Reads are uncached, every mutation requires approval, and provider failures receive no hidden retry. No control-plane namespace, identity, or project is misrepresented as a task, note, or user-work project Source.

What this pack installs

  • temporal-cloud-identity-access Ingredient

Trust & control

What installing this whole pack would let it do. Recued grants these permissions at install — review them there before approving.

What it's allowed to do

Destructive Web APIs temporal-cloud-identity-access external change
Read: api_keys.get_api_keys · No approvalDestructive: api_keys.create_api_key · Always asksRead: api_keys.get_api_key · No approvalDestructive: api_keys.update_api_key · Always asksDestructive: api_keys.delete_api_key · Always asksRead: custom_roles.get_custom_roles · No approvalDestructive: custom_roles.create_custom_role · Always asksRead: custom_roles.get_custom_role · No approvalDestructive: custom_roles.update_custom_role · Always asksDestructive: custom_roles.delete_custom_role · Always asksRead: service_accounts.get_service_account_namespace_assignments · No approvalDestructive: service_accounts.set_service_account_namespace_access · Always asksRead: users.get_user_namespace_assignments · No approvalRead: groups.get_user_group_namespace_assignments · No approvalDestructive: groups.set_user_group_namespace_access · Always asksDestructive: users.set_user_namespace_access · Always asksRead: service_accounts.get_service_accounts · No approvalDestructive: service_accounts.create_service_account · Always asksRead: service_accounts.get_service_account · No approvalDestructive: service_accounts.update_service_account · Always asksDestructive: service_accounts.delete_service_account · Always asksRead: groups.get_user_groups · No approvalDestructive: groups.create_user_group · Always asksRead: groups.get_user_group · No approvalDestructive: groups.update_user_group · Always asksDestructive: groups.delete_user_group · Always asksRead: groups.get_user_group_members · No approvalDestructive: groups.add_user_group_member · Always asksDestructive: groups.remove_user_group_member · Always asksRead: users.list_users · No approvalDestructive: users.create_user · Always asksRead: users.get_user · No approvalDestructive: users.update_user · Always asksDestructive: users.delete_user · Always asks

Data it touches

SurfacesWeb APIs

About

Tags

pack:temporal-cloudtemporal-cloudcontrol-planeidentityaccess-controlapi-keysrbacapicomposition