Skip to main content

systemprompt_identifiers/
lib.rs

1//! Typed newtype identifiers for systemprompt.io.
2//!
3//! Every entity in the platform is referenced through a wrapper newtype
4//! rather than a raw `String`.
5//!
6//! This crate provides both the macros that generate those wrappers
7//! ([`define_id!`], [`define_token!`]) and the canonical concrete types
8//! (`UserId`, `AgentId`, `TaskId`, `TraceId`, `ContextId`, `SessionId`,
9//! `McpServerId`, ...).
10//!
11//! Boundary types for talking to the database — [`DbValue`], [`ToDbValue`],
12//! [`FromDbValue`], [`JsonRow`] — also live here so that identifier modules
13//! can interoperate without depending on the database crate.
14//!
15//! # Construction
16//!
17//! ```ignore
18//! use systemprompt_identifiers::{TaskId, UserId};
19//!
20//! // A value already known to be valid (a decoded DB row).
21//! let task = TaskId::new("task_abc");
22//!
23//! // A value from outside (header, path segment, JWT claim): validate it.
24//! let user = UserId::try_new(raw_sub)?;
25//!
26//! // Mint a fresh UUID-backed identifier.
27//! let fresh = UserId::generate();
28//! ```
29//!
30//! Validated identifiers (`ContextId`, `Email`, `ProfileName`, `ValidatedUrl`,
31//! `ValidatedFilePath`, `RoleId`, ...) expose **only** the fallible `try_new`
32//! constructor returning [`error::IdValidationError`]; there is no
33//! infallible `new` that could panic on runtime input. Values
34//! minted by the platform itself (`ContextId::generate`, `AgentName::system`)
35//! come from dedicated constructors.
36//!
37//! Checked identifiers (`UserId`, `ServiceName`, `AgentName`, `McpServerId`,
38//! `McpToolName`, `PluginId`, `SkillId`, ...) have both: `try_new` validates
39//! input from outside, `new` accepts a value already known valid (a decoded
40//! row, a configuration key validated at load). They implement no
41//! `From<String>`, and their `Deserialize`/`FromStr` validate.
42//!
43//! "Absent" is `Option<Id>`, never a sentinel value such as `"unset"`,
44//! `"unknown"` or the empty string.
45//!
46//! [`gateway_hash`] is the deterministic prefix hash that mints a
47//! [`GatewayConversationId`] identically on both sides of the bridge boundary.
48//!
49//! # Feature flags
50//!
51//! | Feature | Effect |
52//! |---------|--------|
53//! | (default) | Pure-Rust types only. |
54//! | `sqlx` | Derives `sqlx::Type` on every identifier, allowing direct binding in `query_as!` macros. |
55//!
56//! Copyright (c) systemprompt.io — Business Source License 1.1.
57//! See <https://systemprompt.io> for licensing details.
58
59pub mod db_value;
60
61pub use db_value::{DbValue, FromDbValue, JsonRow, ToDbValue, parse_database_datetime};
62
63mod actor;
64mod agent;
65mod ai;
66mod auth;
67mod bridge;
68mod client;
69mod client_session;
70mod cloud;
71mod connection;
72mod content;
73mod context;
74mod email;
75mod engagement;
76mod events;
77mod execution;
78mod extension;
79mod gateway_boot;
80mod gateway_conversation;
81mod hook;
82mod instance;
83mod jobs;
84mod links;
85mod locale;
86mod managed;
87mod marketplace;
88mod mcp;
89mod oauth;
90mod path;
91mod plugin;
92mod policy;
93mod profile;
94mod provider_request;
95mod roles;
96mod scope;
97mod section;
98mod service;
99mod session;
100mod slack;
101mod task;
102mod teams;
103mod tenant;
104mod trace;
105mod url;
106mod user;
107mod webhook;
108
109pub mod error;
110pub mod gateway_hash;
111pub mod headers;
112pub mod macros;
113
114pub use actor::{Actor, ActorKind, ActorKindTag};
115pub use agent::{AgentId, AgentName, ExternalAgentId};
116pub use ai::{
117    AiGatewayPolicyId, AiQuotaBucketId, AiRequestId, AiSafetyFindingId, ConfigId, MessageId,
118};
119pub use auth::{
120    ApiKeyId, ApiKeySecret, CloudAuthToken, DeviceCertId, DeviceId, JwtToken, SessionToken,
121};
122pub use bridge::{
123    CommsMessageId, DeploymentOrganizationUuid, ElevatedJobId, HookSessionId, McpSessionId,
124};
125pub use client::{ClientId, ClientType};
126pub use client_session::ClientSessionId;
127pub use cloud::{CloudAppId, CloudUserId, PriceId};
128pub use connection::ConnectionId;
129pub use content::{CategoryId, ContentId, FileId, SkillId, SkillName, SourceId, TagId};
130pub use context::ContextId;
131pub use email::Email;
132pub use engagement::EngagementEventId;
133pub use events::EventOutboxId;
134pub use execution::{ArtifactId, ExecutionStepId, LogId, TokenId};
135pub use extension::ExtensionId;
136pub use gateway_boot::{DepartmentId, DepartmentName, ModelId, ProviderId, RouteId, SecretName};
137pub use gateway_conversation::GatewayConversationId;
138pub use hook::HookId;
139pub use instance::InstanceId;
140pub use jobs::{JobName, ScheduledJobId};
141pub use links::{CampaignId, LinkClickId, LinkId};
142pub use locale::LocaleCode;
143pub use managed::{
144    ConsumerInstallationId, DistributionId, InstallationReceiptId, InstallationSessionBindingId,
145    InventoryEntryId, ManagedReconciliationId, ManagedResourceId, ManagedSourceId, NativeSessionId,
146    PublicationId, PublicationReviewId, ResourceRevisionId, SourceSnapshotId, WithdrawalProposalId,
147};
148pub use marketplace::{LibraryArtifactId, MarketplaceId, MarketplaceRuleId, RuleName};
149pub use mcp::{AiToolCallId, McpExecutionId, McpServerId, McpToolName};
150pub use oauth::{AccessTokenId, AuthorizationCode, ChallengeId, RefreshTokenId};
151pub use path::ValidatedFilePath;
152pub use plugin::PluginId;
153pub use policy::{CallId, PolicyId, PolicyVersion, SecretPatternId};
154pub use profile::ProfileName;
155pub use provider_request::ProviderRequestId;
156pub use roles::RoleId;
157pub use scope::{ScopeDimension, validate_scope_dimension};
158pub use section::SectionId;
159pub use service::ServiceName;
160pub use session::{SessionId, SessionSource};
161pub use slack::{SlackChannelId, SlackUserId, SlackWorkspaceId};
162pub use task::TaskId;
163pub use teams::{TeamsAppId, TeamsConversationId, TeamsTenantId, TeamsUserId};
164pub use tenant::TenantId;
165pub use trace::TraceId;
166pub use url::ValidatedUrl;
167pub use user::UserId;
168pub use webhook::WebhookEndpointId;
169
170define_id!(RuleId, generate);
171pub use managed::ResourceInvocationId;