Metadata-Version: 2.5
Name: render-lab-tasks-workos
Version: 0.1.0
Summary: workos tasks for Render Workflows
Project-URL: Repository, https://github.com/render-lab/render-tasks-python
License-Expression: MIT
License-File: LICENSE
Requires-Python: >=3.12
Requires-Dist: httpx<0.29,>=0.28
Requires-Dist: render-lab-tasks-core<0.2,>=0.1.1
Requires-Dist: render-lab-triggers<0.2,>=0.1.0
Requires-Dist: render==1.0.1
Description-Content-Type: text/markdown

# render-lab-tasks-workos

Unreleased Python port: **12 registered tasks** from
[render-lab/render-tasks](https://github.com/render-lab/render-tasks/tree/45f9c2d44bd28e01ae9813e0d2ff56ee6c533816/packages/tasks-workos).
Python 3.12+, Render SDK 1.0.1. Requires core 0.1.1 or later.

From the repository root:

```sh
uv sync --all-packages --locked
```

Import `render_lab_tasks_workos.tasks` to register tasks. The package root is inert.
Compose the exported `app` with `Workflows.from_workflows`; call tasks through
`ctx.run`. Every operation also exports `*_impl(ctx, input, *, deps=None)` for
injection. `Client(http, env)` accepts a caller-owned HTTPX client, and
`Deps(workos=client)` injects it. Default dependencies open and close the HTTP
client per invocation; credentials are read lazily at use. No HTTP retries or
background vendor polling occur; `retry.py` owns the durable retry policies.

## Task surface

| Registered task | Python export |
| --- | --- |
| `workos.awaitEvent` | `await_event` |
| `workos.createInvitation` | `create_invitation` |
| `workos.createOrganization` | `create_organization` |
| `workos.createPortalLink` | `create_portal_link` |
| `workos.getDirectoryUser` | `get_directory_user` |
| `workos.listDirectories` | `list_directories` |
| `workos.listDirectoryGroups` | `list_directory_groups` |
| `workos.listDirectoryUsers` | `list_directory_users` |
| `workos.listEvents` | `list_events` |
| `workos.listGroupUsers` | `list_group_users` |
| `workos.revokeInvitation` | `revoke_invitation` |
| `workos.updateOrganization` | `update_organization` |

Typed JSON inputs and results are in `types.py`. Task names and JSON field names
match the pinned source; Python function names use snake_case.

## Environment

| Variable | Requirement |
| --- | --- |
| `WORKOS_API_KEY` | Required at first API call. |

## Behavior and limits

Directory pages preserve before/after cursors, validate limits 1–100, and omit embedded group expansion from directory-user DTOs. Event filters use repeated query keys. await_event reads at most 100 events and returns the first matching event plus its ID as the resume cursor. Organization/invitation/portal creates disable retries; revoke treats 404 as success. Directory resources and event fixtures need a real test organization.

## Verification

All registered tasks have hermetic contract fixtures executed independently against
the pinned TS implementation. SDK-backed tasks also have explicit HTTP request
fixtures. See `tests/test_batch3_contracts.py` and `tests/test_batch3_edges.py`.
These are not live vendor results.

Vendor webhooks subpaths and other registration-free TS exports are outside this
batch unless explicitly listed above. Full registered-task coverage does not
imply all supporting exports are ported.

Pending scopes, test resources, replay, and hosted checks are in the
[live-testing backlog](https://github.com/render-lab/render-tasks-python/issues/1)
and [verification tracker](../../docs/verification-tracker.md).

## Webhook adapter

`render_lab_tasks_workos.webhooks.workos_adapter(on_event, ...)` returns a
registration-free adapter for `render_lab_triggers`. The callback receives the
verified event and returns `{"task": "namespace.task", "args": [event]}` or `None`.
The signing credential `WORKOS_WEBHOOK_SECRET` is read inside verification unless
provided explicitly. Importing this module does not register tasks. Signature
checks use the raw body; live delivery remains in the testing backlog.

## Installation

```sh
pip install render-lab-tasks-workos==0.1.0
```
