Figma OAuth Grant Table
Overview
Organization-level Figma OAuth credential used by the wf2des scheduler. One row exists per organization.
The Admin API owns authorization, encryption, storage, and refresh. The wf2des worker has no PostgreSQL credentials and requests a valid access token from the Admin API only when it needs to call Figma.
This table is separate from figma_token, which stores per-user Personal Access Tokens (PATs) and has no refresh token.
Table Definition
| Logical Name | Physical Name | Column Name | Data Type | Primary Key | Relation | Unique | Nullable | Default Value | Remarks |
|---|---|---|---|---|---|---|---|---|---|
| Figma OAuth Grant | figma_oauth_grant | organization_id | integer | โฏ | organization:id | One grant per organization | |||
| access_token | text | AES-256-GCM encrypted at rest | |||||||
| refresh_token | text | AES-256-GCM encrypted at rest; OAuth grant only, never stored in figma_token |
|||||||
| expires_at | datetime | Access-token expiry | |||||||
| scopes | string | Space-separated OAuth scopes | |||||||
| authorized_user_id | string | Figma user that authorized the grant; audit only | |||||||
| created_at | datetime | ||||||||
| updated_at | datetime | ||||||||
| deleted_at | datetime | โฏ | |||||||
| created_by | string | user:cognito_sub | Admin that authorized the grant | ||||||
| updated_by | string | user:cognito_sub | |||||||
| deleted_by | string | user:cognito_sub | โฏ |
Relations
organization_idโorganization.idwith cascade deletecreated_by/updated_by/deleted_byโuser.cognito_sub
Indexes
- PRIMARY KEY (
organization_id)
Notes
- The Admin API encrypts both tokens with the platform
ENCRYPTION_KEYbefore writing them. - Refresh is serialized per organization with a PostgreSQL transaction advisory lock. No persistent refresh-marker column is required.
- The Admin API refreshes an access token before expiry and retains the existing refresh token when Figma's refresh response does not include one.
- The internal token-provider response contains only the current access token and its expiry. The refresh token, OAuth client secret, encryption key, and PostgreSQL credentials never enter the AI runtime.
- Reauthorization upserts the organization's row.