No-Code SaaS Automation Platform · View 20 of 21 · Assurance
What this view proves
- The Author API never sees the credential: it hands the grant code to custody and gets back a connection id. That keeps the long-lived material inside one zone from the first second.
- Refresh is single-flighted per connection. Without it, a thousand concurrent runs on one connection produce a thousand refreshes and a provider-side refresh-token rotation race — a self-inflicted credential death.
- The flow deliberately ends on the revocation path, because that is the branch journey 05 is about and the one most identity diagrams omit.
Assumptions
- Revocation from the platform takes effect within 60 s, and credential-use audit is retained 7 years.
- Tokens issued to the governor are scoped to one connection and one run, so their useful lifetime is the run's deadline rather than the provider's token TTL.
Trade-off
- Caching the exchanged token for the run's duration cuts a cross-account hop from every step and widens the revocation window to that run's deadline. Taken knowingly; the 60-second revocation promise is about new runs.