Skip to content

Figma OAuth Grant Table

Overview

Organization-level Figma OAuth credential used by the wf2des scheduler. One row exists per organization.

The Admin API owns authorization, encryption, storage, and refresh. The wf2des worker has no PostgreSQL credentials and requests a valid access token from the Admin API only when it needs to call Figma.

This table is separate from figma_token, which stores per-user Personal Access Tokens (PATs) and has no refresh token.

Table Definition

Logical Name Physical Name Column Name Data Type Primary Key Relation Unique Nullable Default Value Remarks
Figma OAuth Grant figma_oauth_grant organization_id integer โ—ฏ organization:id One grant per organization
access_token text AES-256-GCM encrypted at rest
refresh_token text AES-256-GCM encrypted at rest; OAuth grant only, never stored in figma_token
expires_at datetime Access-token expiry
scopes string Space-separated OAuth scopes
authorized_user_id string Figma user that authorized the grant; audit only
created_at datetime
updated_at datetime
deleted_at datetime โ—ฏ
created_by string user:cognito_sub Admin that authorized the grant
updated_by string user:cognito_sub
deleted_by string user:cognito_sub โ—ฏ

Relations

  • organization_id โ†’ organization.id with cascade delete
  • created_by / updated_by / deleted_by โ†’ user.cognito_sub

Indexes

  • PRIMARY KEY (organization_id)

Notes

  • The Admin API encrypts both tokens with the platform ENCRYPTION_KEY before writing them.
  • Refresh is serialized per organization with a PostgreSQL transaction advisory lock. No persistent refresh-marker column is required.
  • The Admin API refreshes an access token before expiry and retains the existing refresh token when Figma's refresh response does not include one.
  • The internal token-provider response contains only the current access token and its expiry. The refresh token, OAuth client secret, encryption key, and PostgreSQL credentials never enter the AI runtime.
  • Reauthorization upserts the organization's row.