WorkOS logo

WorkOS

WorkOS provides enterprise identity and user management APIs for organizations, directory sync, connections, invitations, and users.

29 actions Integration catalog
Request access
Connect WorkOS once you're in Boring.
01 · WHAT THE AGENT CAN DO

Actions

Every capability is a discrete, logged action the agent calls by name — scoped to what you authorize and recorded in the run trace.

Create OrganizationWORKOS_CREATE_ORGANIZATION
Create a WorkOS organization in the connected environment.
Create Organization MembershipWORKOS_CREATE_ORGANIZATION_MEMBERSHIP
Grant an AuthKit user active membership in an organization. An existing inactive membership for the same user and organization is reactivated.
Create UserWORKOS_CREATE_USER
Create a passwordless AuthKit user record in the connected WorkOS environment. This tool does not accept plaintext or hashed passwords.
Delete OrganizationWORKOS_DELETE_ORGANIZATION
Permanently delete a WorkOS organization. This cannot be undone and should only target a confirmed organization ID.
Delete Organization MembershipWORKOS_DELETE_ORGANIZATION_MEMBERSHIP
Permanently remove an organization membership and its access. Prefer deactivation when access may need to be restored.
Delete UserWORKOS_DELETE_USER
Permanently delete an AuthKit user. This cannot be undone and may remove the user's access.
Get ConnectionWORKOS_GET_CONNECTION
Get one WorkOS connection by ID.
Get DirectoryWORKOS_GET_DIRECTORY
Get one WorkOS Directory Sync directory by ID.
Get Directory GroupWORKOS_GET_DIRECTORY_GROUP
Get one WorkOS Directory Sync group by its exact group ID.
Get Directory UserWORKOS_GET_DIRECTORY_USER
Get one WorkOS Directory Sync user by exact ID, including identity-provider attributes, roles, and any groups returned by WorkOS. For complete group memberships, use List Directory Groups filtered by this directory user ID.
Get InvitationWORKOS_GET_INVITATION
Get WorkOS AuthKit invitation status and metadata by invitation ID without exposing acceptance credentials.
Get OrganizationWORKOS_GET_ORGANIZATION
Get one WorkOS organization by its WorkOS ID or external ID.
Get Organization MembershipWORKOS_GET_ORGANIZATION_MEMBERSHIP
Get one WorkOS AuthKit organization membership by ID.
Get UserWORKOS_GET_USER
Get one WorkOS AuthKit user by WorkOS ID or external ID.
List ConnectionsWORKOS_LIST_CONNECTIONS
List one page of WorkOS SSO and OAuth connections, optionally filtered by connection type, domain, organization, or name.
List DirectoriesWORKOS_LIST_DIRECTORIES
List one page of WorkOS Directory Sync directories, optionally filtered by organization, directory name, or domain.
List Directory GroupsWORKOS_LIST_DIRECTORY_GROUPS
List one page of WorkOS Directory Sync groups for a directory, a directory user, or both.
List Directory UsersWORKOS_LIST_DIRECTORY_USERS
List one page of WorkOS Directory Sync users for a directory or group, optionally filtering a directory by exact identity-provider ID or primary email. WorkOS limits this endpoint to 4 requests per second per directory; on HTTP 429, honor Retry-After before retrying.
List InvitationsWORKOS_LIST_INVITATIONS
List one page of WorkOS AuthKit invitations by organization or exact recipient email without exposing acceptance credentials.
List Organization MembershipsWORKOS_LIST_ORGANIZATION_MEMBERSHIPS
List one page of WorkOS AuthKit organization memberships for a specific organization or user, optionally including inactive or pending memberships.
List OrganizationsWORKOS_LIST_ORGANIZATIONS
List one page of WorkOS organizations, optionally filtered by domain or organization name.
List UsersWORKOS_LIST_USERS
List one page of WorkOS AuthKit users, optionally filtered by organization or exact email address.
Resend InvitationWORKOS_RESEND_INVITATION
Send another real invitation email to the existing recipient of a pending WorkOS AuthKit invitation. This externally visible email delivery cannot be undone. The response excludes the invitation token and acceptance URL.
Revoke InvitationWORKOS_REVOKE_INVITATION
Revoke a pending AuthKit invitation so it can no longer be accepted.
Send InvitationWORKOS_SEND_INVITATION
Create an AuthKit invitation and immediately send a real invitation email to the recipient. This externally visible email delivery cannot be undone. Use only when the recipient and delivery are intentional. The output omits the sensitive acceptance token and acceptance URL.
Set Organization Membership StatusWORKOS_SET_ORGANIZATION_MEMBERSHIP_STATUS
Activate or deactivate a WorkOS organization membership without deleting it. Deactivation removes access but can be reversed by setting the status to active.
Update OrganizationWORKOS_UPDATE_ORGANIZATION
Update selected properties of an existing WorkOS organization.
Update Organization Membership RolesWORKOS_UPDATE_ORGANIZATION_MEMBERSHIP_ROLES
Replace the role assignment on an existing WorkOS organization membership.
Update UserWORKOS_UPDATE_USER
Update selected profile fields on an AuthKit user without invoking email delivery flows.