Appearance
Entity: externalConnectorConfig
Entity Type: Database table
Description: Per-tenant configuration for a connection to an external data or billing provider — for example a market data feed or a supplier's invoice API. Holds the connection's credentials and settings. connectorType and providerCode together determine which provider-specific handler processes calls made through this connector; providerCode is looked up against the generic lookup table mechanism rather than a fixed enum, so a new provider can be added without a code change. Every call made through a connector is recorded on externalConnectorLog.
Data Attributes Table
| Attribute Name | Description | Data Type | Default Value | Required (= Nullable) | Unique | Format | Validations | Index | Example |
|---|---|---|---|---|---|---|---|---|---|
| id | Primary key of the entity. | UUID | Generated in code (app layer) | Yes | Yes | UUID v7 | Must be a unique identifier. | Primary Key | 018ed0b3-c298-7c7a-96d5-8b36f5a7f8d2 |
| tenantId | Tenant this connector configuration belongs to. | UUID | - | Yes | No | UUID v7 | Foreign Key → tenant | name: idx_externalConnectorConfig_tenantId, type: btree | 018fa51f-fda1-79f4-8461-2cb8f1cabc10 |
| connectorType | Category of connector, used to select the correct internal handler. | String | - | Yes | No | enum.externalConnectorType | One of: supplierBilling, marketData, openData. | - | supplierBilling |
| providerCode | The specific provider within the connector type. | String | - | Yes | No | Lookup key → lt.externalConnectorProvider | Must exist in the lookup table. | name: idx_externalConnectorConfig_tenantId_providerCode, type: btree, unique on (tenantId, providerCode) | prazskaPlynarenska |
| credentials | Provider credentials (API keys, OAuth client details, etc.); shape depends on connectorType/providerCode. | JSONB | - | Yes | No | JSON, encrypted at rest — no fixed shape documented | Never returned in plaintext through any API. | - | {"oauthClientId":"...","oauthClientSecret":"enc:..."} |
| baseUrl | Override for the provider's base URL, e.g. to target a test environment. | String | - | No | No | URL | - | - | https://api.example.com |
| enabled | Whether the connector is currently active. | Boolean | true | Yes | No | - | - | - | true |
| lastSuccessfulSyncAt | Timestamp of the last successful sync through this connector. | Timestamp with time zone | - | No | No | ISO 8601 | - | - | 2026-06-15T04:00:00Z |
| createdAt | Timestamp of when the record was created. Immutable after insert. | Timestamp with time zone | now() — set in code | Yes | No | ISO 8601 — YYYY-MM-DDTHH:mm:ss.SSSZ | Cannot be null; cannot be modified after creation. | - | 2026-06-15T04:00:00Z |
| updatedAt | Timestamp of the last update to the record. | Timestamp with time zone | now() — set in code | Yes | No | ISO 8601 — YYYY-MM-DDTHH:mm:ss.SSSZ | Cannot be null. | - | 2026-06-15T04:00:00Z |
| deletedAt | Timestamp of soft deletion. Null means the record is active. Once set, immutable. | Timestamp with time zone | - | No | No | ISO 8601 — YYYY-MM-DDTHH:mm:ss.SSSZ | Immutable once set. Active records: WHERE deletedAt IS NULL | - | null |
| createdBy | Identifier of the actor who created the record. | String | - | Yes | No | type:actor — e.g. user:uuid or system:migration | Non-empty. | - | user:018ed0b3-c298-7c7a-96d5-8b36f5a7f8d2 |
| updatedBy | Identifier of the actor who last updated the record. | String | - | Yes | No | type:actor — e.g. user:uuid or system:migration | Non-empty. | - | user:018ed0b3-c298-7c7a-96d5-8b36f5a7f8d2 |
Note on credentials. The source page describes this JSONB column's shape only as "depends on connectorType/providerCode", with a single illustrative example — no concrete per-provider schema is documented anywhere on the page. No JSON-DAT sibling file was created since there is no shape to document; flagged for the analyst rather than invented.
Audited fields
Recorded on created (in full), updated (changed only) and deleted (in full): connectorType, providerCode, baseUrl, enabled, lastSuccessfulSyncAt.
Excluded:
credentials— provider API keys / OAuth secrets, encrypted at rest and never returned in plaintext through any API (per this entity's own description); recording the value in a trail readable by anyone holding tenant-wideaudit:readwould defeat that protection. Still appears by name in the changed-fields list of any entry where it is set or rotated — excluded by value, not by silence, matching the same pattern used forfile.rawObjectKey/cleanObjectKey.
Not registered for entityName resolution — renders id-only in the audit trail (architecture 61-audit-log.md §7.4 in the code repo: a valid, permanent state, not a gap). If registered, providerCode is the natural candidate.