Components
Flex Gateway
A Solution's public API. Named endpoints run saved queries, Flows, Agents and file operations, each protected by the Identity you choose.
- Everyone
- Technical
Last reviewed
A Flex Gateway is a Solution's public API. It turns what is inside the Solution (saved queries, published Flows, published Agents and File Stores) into named web endpoints on the apps address. A generated app calls its own address, other systems call the same endpoints, and the gateway checks who is calling before it runs anything.
Note
In one sentence: the Flex Gateway is the only way a generated app or an outside system reaches a Solution's data and automations, and every call runs under least privilege.
Why it matters
- One front door. Apps, partner systems and scripts all use the same endpoints, with the same checks.
- Sign-in you choose. Each gateway uses an Identity: your company's single sign-on, a customer identity provider, API keys, signatures or client certificates.
- Least privilege. The gateway runs on a restricted database identity. It can run a saved query under a Fact Base role, but it cannot read datasets directly.
- Changes without rebuilds. Point an app's gateway at a different Identity and the app's sign-in changes with it. Endpoint and sign-in changes take effect at the gateway as soon as they are saved (within about 30 seconds if a change notice is missed).
Key concepts
| Term | What it means |
|---|---|
| Endpoint | A name, a path, a kind (query, flow, agent or file), a target and an auth mode. |
| Auth mode | Per endpoint: Inherit (the default: protected when an Identity is attached), Required or Anonymous. |
| Identity | How a caller proves who they are, and which provider they use. |
| Dynamic mode | One gateway routes each caller to the Identity that matches their token's issuer, so it can serve several identity providers. |
| Rules | Required scopes, required claims and allowed email domains. A failed rule answers "forbidden" and names the rule, never "sign in again". |
| Runtime SDK | The script in every served page (window.Flexday) with api, flows, agent, files and auth. It never names a host. |
How it works
- Call. The app's SDK posts to its own address,
<workspace>.apps.<domain>/api/<gateway>/<endpoint>. There are no cross-origin calls and no API address in the app. - Resolve. On a workspace address, the workspace comes from the address itself. An address that names no workspace is refused, never guessed. The endpoint catalogue loads.
- Reserved first. The sign-in operations (discovery, finding the provider's sign-in page, completing and refreshing a sign-in, the report a Microsoft sign-in sends, and sign-out) and download links are matched before any endpoint, so no endpoint can take their place.
- Verify. The credential is checked against the attached Identity, or the one matching its issuer in dynamic mode. A bad credential is refused.
- Authorise. Required scopes, claims and email domains, plus the endpoint's own scopes. A failed rule is refused with its name.
- Limit and dispatch. Rate limits per address for anonymous callers and per person for signed-in ones. If the person's sign-in hasn't been handled yet, for example a token the app got elsewhere, the gateway handles it first: it records them, applies any invitation waiting for them and runs the Identity's On sign-in Flow, so even a first call carries their access tags. Then the endpoint kind decides what runs.
- Respond. Rows for a query, a result for a Flow, a reply or stream for an Agent, or a file as an attachment.
Four endpoint kinds
| Kind | What it runs |
|---|---|
| Query | A saved Fact Base query under the endpoint's Fact Base role. Table permissions and row policies apply to the caller. |
| Flow | A published Flow. The result is returned, or an execution token for an interactive Flow. The Flow's on/off switch governs only self-firing triggers. A Flow with a Set access tags step can't be put on an endpoint, because whoever calls it would choose whose access changes; choose it on the Identity instead. |
| Agent | Create a session, send a message and stream the reply. Audiences are worked out again on every signed-in message. |
| File | Upload, list, read metadata and download from a File Store. Nothing is served before a clean scan verdict. |
A query endpoint answers in one consistent envelope:
{ "success": true, "queryId": "open_tickets", "data": [ ... ], "meta": { "rowCount": 42 } }
Where you work with it
Gateways are listed under Executors → Flex Gateways. A gateway's page shows its endpoints, its Identity and its settings. The Builder creates an endpoint for every saved query automatically, and you add flow, agent and file endpoints as you need them.
Works with
- LaunchPad: calls it through the SDK. A LaunchPad is pinned to one gateway.
- Fact Base: query endpoints run its saved queries under a role.
- Flow, Agent and File Store: the targets of flow, agent and file endpoints.
- Identity: one Identity can protect many gateways; a gateway uses one, or picks one per caller's issuer.
- Bot: does not go through endpoints, but its Teams webhook lives on the same apps address.
Governance and limits
| Area | What applies |
|---|---|
| Boundary | Endpoints reach only targets in the same Solution. The gateway process runs on a least-privilege database identity. |
| Access | Auth is decided per endpoint, and an endpoint's scopes can only narrow the Identity's. API keys are stored only as fingerprints, shown once and revocable at once. |
| Live changes | Endpoint changes apply within about 30 seconds everywhere, and a running app refreshes its catalogue before it reports an error. |
| Safety | Downloads are always attachments with a neutral type. Where a provider needs a client secret, sign-in is completed on the server and the secret stays sealed. Staff impersonation tokens are never accepted here. |
| Limits | Download links last 15 minutes. Uploads up to 100 MB through the gateway and 5 GB direct to storage. |