API
Preview workflows
Preview workflows. This applies the validated business action to the selected tenant or platform resource.
/api/workflows/transform/previewPreview workflows. This applies the validated business action to the selected tenant or platform resource.
Operation IDpostapiWorkflowsTransformPreviewOperation details
Purpose
Preview workflows. This applies the validated business action to the selected tenant or platform resource.
When to use it
Use this when the documented business action or resource creation is the intended next step.
When not to use it
Do not repeat the request blindly after an uncertain outcome. Read the resulting resource or background operation state first.
Contract
Availability
- Product version
- Next Product release
- Licence
- An active Product licence is required except for health, authentication, and licence remediation operations.
- Entitlements
- workflow.enabled
- Service roles
- workflow
- Deployment
- customer managed installation
- Feature state
- preview
Security
Access
Sign in: Use a session cookie or Bearer session token.
- Actor
- Authenticated Pūnaha actor authorised for the selected tenant and resource
- Permission
- workflows.manage
- Resource
- workflow / create
- Tenant rule
- Tenant scoped unless the selected actor is performing an explicitly documented platform action. The x organization id header or authenticated session context selects the tenant. It does not grant access.
- Explicit deny
- An applicable explicit deny overrides an allow. Knowing or supplying a resource identifier never grants access.
Address, query and header fields
| Field | Location | Presence | Type | Meaning | Limits and example |
|---|---|---|---|---|---|
x-request-id | header | Optional | string | Optional caller supplied correlation identifier. Pūnaha returns the effective value in the response header. | Minimum length: 1. Maximum length: 200. Example: example request 001 |
Request body
Content type: application/json. Presence: Required.
Operation request. Every property documents omission, null, sensitivity, source, mutability, availability, access, and lifecycle semantics through JSON Schema and x punaha-* annotations.
Request fields3 documented fields
Request fields
| Field | Presence | Type | Meaning | Empty and default | Limits and example | Access, sensitivity and lifecycle |
|---|---|---|---|---|---|---|
configuration | required | object | Keys are defined by the selected configuration, provider, or resource type. Values follow the documented field schema. | The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present. | Example: {} | Inherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release. |
input | required | JSON value | A JSON value whose shape is explicitly determined by the selected configuration, provider, or operation. | The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present. | Example: example value | Inherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release. |
variables | required | object | Keys are defined by the selected configuration, provider, or resource type. Values follow the documented field schema. | The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present. | Example: {} | Inherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release. |
Complete representative request using synthetic data
{
"configuration": {},
"input": "example-value",
"variables": {}
}Smallest schema valid request
{
"configuration": {},
"input": "example-value",
"variables": {}
}Responses
| Status | Meaning and correction boundary | Body |
|---|---|---|
200 | The operation completed and the response contains the current operation specific representation. | application/json, object |
400 | The operation failed with HTTP 400. Inspect error.code and error.details, apply the documented correction, and retain x request id. | application/json, APIError |
401 | The operation failed with HTTP 401. Inspect error.code and error.details, apply the documented correction, and retain x request id. | application/json, APIError |
402 | The operation failed with HTTP 402. Inspect error.code and error.details, apply the documented correction, and retain x request id. | application/json, APIError |
403 | The operation failed with HTTP 403. Inspect error.code and error.details, apply the documented correction, and retain x request id. | application/json, APIError |
409 | The operation failed with HTTP 409. Inspect error.code and error.details, apply the documented correction, and retain x request id. | application/json, APIError |
423 | The operation failed with HTTP 423. Inspect error.code and error.details, apply the documented correction, and retain x request id. | application/json, APIError |
500 | The operation failed with HTTP 500. Inspect error.code and error.details, apply the documented correction, and retain x request id. | application/json, APIError |
503 | The operation failed with HTTP 503. Inspect error.code and error.details, apply the documented correction, and retain x request id. | application/json, APIError |
200 response fields2 documented fields
200 response fields
| Field | Presence | Type | Meaning | Empty and default | Limits and example | Access, sensitivity and lifecycle |
|---|---|---|---|---|---|---|
data | required | object | The operation specific result. | The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present. | Example: {} | Inherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release. |
data.output | required | JSON value | A JSON value whose shape is explicitly determined by the selected configuration, provider, or operation. | The field is present. Empty strings or collections are valid only when the field constraints and operation rules allow them. Default: No client default is assumed unless a JSON Schema default is present. | Example: example value | Inherits the operation access rules. Inherits the operation availability unless an operation specific rule says otherwise. No special sensitivity is marked. No special handling is inferred beyond normal tenant access, audit, retention, and data classification controls. Lifecycle: Next Product release. |
Successful response using synthetic data
{
"data": {
"output": "example-value"
}
}Effects
Behaviour and other effects
- Changes
- Validates access and input, then applies the operation specific state change. A failed validation or authorisation check does not intentionally apply the requested change.
- Audit events
- The mutation is subject to the Product audit policy. The exact event name is operation owned and must be reviewed before publication.
- Background work
- No background work is inferred. The success response represents completion of the HTTP action.
- External effects
- No external call is inferred from the route name. Operation specific service behaviour remains authoritative.
- Transaction boundary
- The HTTP success or error describes the synchronous boundary. Background operations have their own observable lifecycle and may outlive the request.
Operation
Reliability
- Idempotent
- No
- Retry
- Do not retry automatically after a timeout or lost response. Read current state first.
- Concurrency
- Use documented If Match or resource revision fields where exposed. Otherwise read current state before changing it and handle HTTP 409 conflicts.
- Consistency
- The response reflects the synchronous operation boundary. Background and provider backed state can converge later and must be read through its status operation.
- Timeout
- Client timeouts do not cancel completed or already started server work unless the operation explicitly supports cancellation.
- Request ID
- Send or record x request id and retain the returned value for diagnosis.
Errors and corrections
| Status | Code | Cause | Correction | Retryable | Partial work |
|---|---|---|---|---|---|
400 | INVALID_REQUEST_BODY | The request body or supplied field values are invalid. | Correct the named field or rule in error.details, then submit a new request. Retrying an unchanged request will not help. | No unchanged retry | No requested mutation is expected before this failure boundary. |
401 | AUTHENTICATION_REQUIRED | A valid authenticated session or supported token is required. | Authenticate again using a supported mechanism and confirm that the credential is current. | No unchanged retry | No requested mutation is expected before this failure boundary. |
402 | FEATURE_NOT_LICENSED | The active licence does not include a required entitlement. | Use an operation covered by the active entitlement or ask the System Owner to review the signed licence. | No unchanged retry | No requested mutation is expected before this failure boundary. |
403 | PERMISSION_REQUIRED | The authenticated actor does not have the exact permission or resource action. | Select the correct tenant and resource, then ask an authorised administrator to grant the exact documented action if appropriate. | No unchanged retry | No requested mutation is expected before this failure boundary. |
409 | STATE_CONFLICT | Current resource state or a dependency prevents the requested change. | Read current state, resolve the named dependency or lifecycle conflict, and submit a deliberate new request. | No unchanged retry | The caller must read current resource or background operation state before retrying because work may have started before the failure became observable. |
423 | LICENCE_REMEDIATION_REQUIRED | The installation is restricted and permits only licence remediation actions. | Complete the indicated licence or membership remediation before retrying Product work. | No unchanged retry | The caller must read current resource or background operation state before retrying because work may have started before the failure became observable. |
500 | INTERNAL_ERROR | Pūnaha could not complete the operation because of an unexpected internal failure. | Retain x request id and the stable error code, avoid blind retries, and investigate the operation or contact support. Code: INTERNAL_ERROR. | No unchanged retry | The caller must read current resource or background operation state before retrying because work may have started before the failure became observable. |
503 | DEPENDENCY_UNAVAILABLE | A required node, database, provider, or service is temporarily unavailable. | Retain x request id, check health and the named dependency, then retry with bounded backoff when safe. | Yes, with the documented safeguards | The caller must read current resource or background operation state before retrying because work may have started before the failure became observable. |
Code examples
Use a supported credential and synthetic data. Do not disable TLS checks or retry a request that changes state blindly.
curl --request POST "$PUNAHA_URL/api/workflows/transform/preview" \
--header "Authorization: Bearer $PUNAHA_TOKEN" \
--header "x-request-id: example-request-001" \
--header "Content-Type: application/json" \
--data '{"configuration":{},"input":"example-value","variables":{}}'const response = await fetch(`${PUNAHA_URL}/api/workflows/transform/preview`, {
method: "POST",
headers: {
"x-request-id": "example-request-001",
"Authorization": "Bearer ${PUNAHA_TOKEN}",
"Content-Type": "application/json"
},
body: JSON.stringify({
"configuration": {},
"input": "example-value",
"variables": {}
})
});
if (!response.ok) throw new Error(`Pūnaha request failed: ${response.status}`);
const result = response.status === 204 ? undefined : await response.json();using System.Net.Http.Headers;
using System.Text;
using var client = new HttpClient { BaseAddress = new Uri(punahaUrl) };
client.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Bearer", punahaToken);
using var request = new HttpRequestMessage(HttpMethod.Post, "/api/workflows/transform/preview");
request.Headers.Add("x-request-id", "example-request-001");
var json = "{\"configuration\":{},\"input\":\"example-value\",\"variables\":{}}";
request.Content = new StringContent(json, Encoding.UTF8, "application/json");
using var response = await client.SendAsync(request);
response.EnsureSuccessStatusCode();$headers = @{ Authorization = "Bearer $env:PUNAHA_TOKEN"; "x-request-id" = "example-request-001" }
$body = @'
{
"configuration": {},
"input": "example-value",
"variables": {}
}
'@
Invoke-RestMethod -Method POST `
-Uri "$env:PUNAHA_URL/api/workflows/transform/preview" `
-Headers $headers `
-ContentType "application/json" `
-Body $bodyRelated APIs
deleteapiWorkflowsWorkflowId, same domaindeleteapiWorkflowsWorkflowIdRunsRunId, same domaindeleteapiWorkflowsWorkflowIdStar, same domaingetapiWorkflows, read or monitorgetapiWorkflowsBpmnConformance, read or monitorgetapiWorkflowsBpmnConformanceReport, read or monitor
Version history
- Next Product release: Operation documented from the current registered Go route and handler contract.
Was this page helpful?
Your answer helps us improve the documentation.
Do not include personal information, customer information, passwords, or keys.