Overview

Phase 5 introduces enterprise security features. All endpoints are exposed as tRPC procedures under the appRouter and require authentication. Organization-scoped procedures additionally require the caller to be a member of the target organization.

Base URL pattern: https://<org>.probeya.com/api/trpc/<router>.<procedure>


SSO Router (sso.*)

Manage Single Sign-On configuration for an organization. All procedures require the Owner or Admin role.

sso.getConfig

Type: Query (orgProcedure)

Returns the current SSO configuration for the organization. The client secret is masked and never returned in plaintext.

Response:

{
  "id": "sso_01HXK...",
  "provider": "oidc",
  "displayName": "Sign in with Company SSO",
  "isActive": true,
  "clientId": "abc-123",
  "clientSecret": "••••••••",
  "issuerUrl": "https://login.microsoftonline.com/.../v2.0",
  "attributeMapping": { ... },
  "groupRoleMapping": [ ... ]
}

sso.saveConfig

Type: Mutation (orgProcedure)

Create or update the SSO configuration. If a configuration already exists, it is updated in place. Leave clientSecret empty when updating to preserve the existing secret.

Input: provider, displayName, isActive, clientId, clientSecret, issuerUrl, authorizationUrl, tokenUrl, samlEntryPoint, samlCert, samlIssuer, metadataUrl, attributeMapping, groupRoleMapping

sso.deleteConfig

Type: Mutation (orgProcedure)

Delete the SSO configuration. The SSO login button is immediately removed from the login page.

sso.testConnection

Type: Mutation (orgProcedure)

Test the saved SSO configuration by fetching the OIDC discovery document or SAML metadata URL. Returns success or a detailed error message.

sso.activate

Type: Mutation (orgProcedure)

Activate SSO. The SSO login button becomes visible on the organization’s login page.

sso.deactivate

Type: Mutation (orgProcedure)

Deactivate SSO. The login button is hidden and enforcement is automatically disabled.

sso.toggleEnforcement

Type: Mutation (orgProcedure)

Enable or disable SSO enforcement. When enforced, email/password login is disabled for all non-owner members.

sso.uploadSamlMetadata

Type: Mutation (orgProcedure)

Upload or paste SAML IdP metadata XML. ProBeya parses the XML and auto-populates the SSO URL, certificate, and entity ID fields.

sso.downloadSpMetadata

Type: Query (orgProcedure)

Generate and return the ProBeya Service Provider SAML metadata XML for import into the customer’s identity provider.


MFA Router (mfa.*)

Manage TOTP-based multi-factor authentication for individual users and organization-wide enforcement.

mfa.getStatus

Type: Query (protectedProcedure)

Returns the current user’s MFA status: whether TOTP is enabled, configured, and when it was last verified.

mfa.setup

Type: Mutation (protectedProcedure)

Generate a new TOTP secret and return a QR code URI and manual key for the authenticated user.

mfa.verify

Type: Mutation (protectedProcedure)

Verify the 6-digit TOTP code to complete MFA enrollment. On success, MFA is activated and backup codes are generated.

Input: code (string, 6 digits)

mfa.disable

Type: Mutation (protectedProcedure)

Disable MFA on the authenticated user’s account. Requires password re-authentication.

Input: password (string)

mfa.regenerateBackupCodes

Type: Mutation (protectedProcedure)

Generate a fresh set of 10 backup codes. All previous codes are invalidated. Requires password re-authentication.

Input: password (string)

mfa.getOrgEnforcement

Type: Query (orgProcedure)

Returns the organization’s MFA enforcement policy (enabled/disabled, grace period days).

mfa.setOrgEnforcement

Type: Mutation (orgProcedure)

Update the organization’s MFA enforcement policy. Owner-only.

Input: enforced (boolean), gracePeriodDays (number, optional)

mfa.getOrgMfaStatus

Type: Query (orgProcedure)

Returns aggregate MFA enrollment statistics for the organization (total members, enabled count, disabled count).


Approvals Router (approvals.*)

Manage approval workflows, create approval requests, and record decisions.

approvals.createWorkflow

Type: Mutation (orgProcedure)

Create a new approval workflow for a board. Defines steps, trigger conditions, approvers, and e-signature requirements.

Input: boardId, name, steps[], triggerCondition, isActive

approvals.listWorkflows

Type: Query (orgProcedure)

List all approval workflows for a board.

Input: boardId

approvals.getWorkflow

Type: Query (orgProcedure)

Get a single approval workflow by ID with full step details.

Input: workflowId

approvals.updateWorkflow

Type: Mutation (orgProcedure)

Update an existing approval workflow. Changes apply to new requests only.

Input: workflowId, name, steps[], triggerCondition, isActive

approvals.deleteWorkflow

Type: Mutation (orgProcedure)

Delete an approval workflow. Historical approval records are preserved.

Input: workflowId

approvals.requestApproval

Type: Mutation (orgProcedure)

Create a new approval request for an entity (e.g., an action). Starts the workflow at step 0.

Input: entityType, entityId, workflowId

approvals.decide

Type: Mutation (orgProcedure)

Record an approve or reject decision on the current step. If the step requires e-signature, password and optional MFA code are validated.

Input: requestId, decision (“approve” | “reject”), password (for e-signature), mfaCode (optional), signatureMeaning (optional)

approvals.getMyPendingApprovals

Type: Query (orgProcedure)

List all approval requests where the authenticated user is a designated approver for the current step.

approvals.getRequestStatus

Type: Query (orgProcedure)

Get the current status of an approval request including all step decisions.

Input: requestId

approvals.getEntityApprovalStatus

Type: Query (orgProcedure)

Check whether an entity has an active or completed approval request.

Input: entityType, entityId


Board Permissions Router (boardPermissions.*)

Fine-grained access control at the board level.

boardPermissions.getForBoard

Type: Query (orgProcedure)

List all explicit permissions set on a board, including grantee type (user or role), permission level, and source.

Input: boardId

boardPermissions.setPermission

Type: Mutation (orgProcedure)

Grant or update a permission for a user or role on a board.

Input: boardId, granteeType (“user” | “role”), granteeId, permissionLevel (“no_access” | “view” | “edit_items” | “edit_all” | “full_control”)

boardPermissions.removePermission

Type: Mutation (orgProcedure)

Remove an explicit permission, reverting the grantee to the inherited organization default.

Input: permissionId

boardPermissions.getMyPermission

Type: Query (orgProcedure)

Get the effective permission level for the authenticated user on a specific board, considering both explicit grants and inherited role-based permissions.

Input: boardId


Sessions Router (sessions.*)

Session lifecycle management and organization-level session policies.

sessions.listActive

Type: Query (protectedProcedure)

List all active sessions for the authenticated user, including IP address, user agent, and last activity timestamp.

sessions.revoke

Type: Mutation (protectedProcedure)

Revoke a specific session by ID. The targeted session is immediately invalidated.

Input: sessionId

sessions.revokeAll

Type: Mutation (protectedProcedure)

Revoke all active sessions except the current one. Returns the count of revoked sessions.

sessions.getLoginHistory

Type: Query (protectedProcedure)

Paginated list of login attempts (successful and failed) for the authenticated user.

Input: limit (number, default 20), cursor (string, optional)

sessions.forceLogout

Type: Mutation (orgProcedure)

Force-logout a specific user by invalidating all their active sessions. Owner/Admin only.

Input: userId

sessions.setOrgSessionPolicy

Type: Mutation (orgProcedure)

Configure the organization’s session timeout and maximum concurrent sessions. Owner only.

Input: sessionTimeoutMinutes (number), maxConcurrentSessions (number)