Organisation provisioning

Signing up a new customer of your product usually means several writes that have to succeed together. Provisioning does them in one call.

What one call creates

The call creates the organisation and its brand. It can also create the organisation's settings record, add its first member and mint an API key confined to it. You choose which of those steps to include.

Safe to retry

You supply an id for the provision. Sending the same id with the same request resumes from the first step that did not finish, and a provision that already completed does nothing. Two calls made at the same moment produce one organisation.

The key is shown once

If you ask for a key, its secret comes back on the call that minted it and never again, because Fóir stores only a hash. The key's permissions are capped at those of the credential that requested it.

Where you can call it from

Provisioning is available over the API, from the CLI as foir orgs provision, and to an agent connected over MCP. Each step needs the permission its own write would need, so a credential that may create organisations cannot use provisioning to mint a key unless it may also manage keys.

Read the detail

The provisioning guide lists every step, the permission each needs and what a retry returns.