Skip to content

basalt / core/src / BasaltHooks

Interface: BasaltHooks ​

Defined in: core/src/hooks.ts:11

Global hook registry for the ecosystem. Packages add their typed hooks via module augmentation:

declare module '@basaltkit/core' { interface BasaltHooks { 'tenancy:switched': { tenantId: string } } }

Indexable ​

> [hook: string]: unknown

Properties ​

app:booted ​

> app:booted: object

Defined in: core/src/app.ts:23

app ​

> app: BasaltApp


app:registered ​

> app:registered: object

Defined in: core/src/app.ts:22

app ​

> app: BasaltApp


app:shutdown ​

> app:shutdown: object

Defined in: core/src/app.ts:24

app ​

> app: BasaltApp


auth:account_linked ​

> auth:account_linked: object

Defined in: auth/src/plugin.ts:58

A provider account (its stable subject) was linked to this account on its first social login.

provider ​

> provider: string

user ​

> user: PublicUser


auth:apikey_issued ​

> auth:apikey_issued: object

Defined in: auth/src/apikeys-plugin.ts:13

id ​

> id: string

tenantId? ​

> optional tenantId?: string

userId? ​

> optional userId?: string


auth:apikey_rejected ​

> auth:apikey_rejected: object

Defined in: auth/src/apikeys-plugin.ts:21

A presented API key was refused: unknown/revoked/expired (invalid), used outside the tenant it is bound to (tenant_mismatch), used on a session-only route (not_allowed) or beyond its scopes (scope). Never carries the key itself.

id? ​

> optional id?: string

reason ​

> reason: "scope" | "invalid" | "tenant_mismatch" | "not_allowed"

tenantId? ​

> optional tenantId?: string


auth:apikey_revoked ​

> auth:apikey_revoked: object

Defined in: auth/src/apikeys-plugin.ts:14

id ​

> id: string


auth:email_verified ​

> auth:email_verified: object

Defined in: auth/src/plugin.ts:39

user ​

> user: PublicUser


auth:locked_out ​

> auth:locked_out: object

Defined in: auth/src/plugin.ts:48

A login was refused because the account (or the client ip) is locked.

email ​

> email: string

ip? ​

> optional ip?: string


auth:login ​

> auth:login: object

Defined in: auth/src/plugin.ts:34

user ​

> user: PublicUser


auth:login_failed ​

> auth:login_failed: object

Defined in: auth/src/plugin.ts:35

email ​

> email: string


auth:logout ​

> auth:logout: object

Defined in: auth/src/plugin.ts:36

user ​

> user: PublicUser


auth:mfa_disabled ​

> auth:mfa_disabled: object

Defined in: auth/src/plugin.ts:44

user ​

> user: PublicUser


auth:mfa_enabled ​

> auth:mfa_enabled: object

Defined in: auth/src/plugin.ts:43

user ​

> user: PublicUser


auth:mfa_failed ​

> auth:mfa_failed: object

Defined in: auth/src/plugin.ts:46

A wrong MFA code was presented for this user (login or social login).

userId ​

> userId: string


auth:password_reset ​

> auth:password_reset: object

Defined in: auth/src/plugin.ts:42

user ​

> user: PublicUser


auth:password_reset_requested ​

> auth:password_reset_requested: object

Defined in: auth/src/plugin.ts:41

Password reset requested — the app emails the token as a link.

token ​

> token: string

user ​

> user: PublicUser


auth:refresh_reused ​

> auth:refresh_reused: object

Defined in: auth/src/plugin.ts:50

A consumed refresh token came back; its whole family was revoked (theft indicator).

familyId ​

> familyId: string

userId ​

> userId: string


auth:register_existing_email ​

> auth:register_existing_email: object

Defined in: auth/src/plugin.ts:33

Someone tried to register an email that already has an account. Emitted by the enumeration-safe register endpoint so the app can email the address ("you already have an account — sign in or reset your password") instead of revealing existence in the HTTP response. Only the email is provided.

email ​

> email: string


auth:registered ​

> auth:registered: object

Defined in: auth/src/plugin.ts:26

user ​

> user: PublicUser


auth:social_account_adopted ​

> auth:social_account_adopted: object

Defined in: auth/src/plugin.ts:56

A provider-verified social login took over an account whose email had never been verified; its previous password, sessions, refresh tokens and MFA and account links were revoked.

user ​

> user: PublicUser


auth:verify_requested ​

> auth:verify_requested: object

Defined in: auth/src/plugin.ts:38

Email verification requested — the app emails the token as a link.

token ​

> token: string

user ​

> user: PublicUser


billing:canceled ​

> billing:canceled: object

Defined in: subscriptions/src/plugin.ts:36

subscription ​

> subscription: SubscriptionRecord


billing:checkout_started ​

> billing:checkout_started: object

Defined in: subscriptions/src/plugin.ts:39

billableId ​

> billableId: string

plan ​

> plan: string

url ​

> url: string


billing:subscribed ​

> billing:subscribed: object

Defined in: subscriptions/src/plugin.ts:34

subscription ​

> subscription: SubscriptionRecord


billing:swapped ​

> billing:swapped: object

Defined in: subscriptions/src/plugin.ts:35

from ​

> from: string

subscription ​

> subscription: SubscriptionRecord


billing:trial_expired ​

> billing:trial_expired: object

Defined in: subscriptions/src/plugin.ts:37

subscription ​

> subscription: SubscriptionRecord


billing:webhook ​

> billing:webhook: object

Defined in: subscriptions/src/plugin.ts:38

event ​

> event: WebhookEvent


comment:created ​

> comment:created: object

Defined in: comments/src/plugin.ts:9

comment ​

> comment: Comment


comment:deleted ​

> comment:deleted: object

Defined in: comments/src/plugin.ts:11

id ​

> id: string

resourceId ​

> resourceId: string

resourceType ​

> resourceType: string

tenantId ​

> tenantId: string


comment:mentioned ​

> comment:mentioned: object

Defined in: comments/src/plugin.ts:15

One per mentioned user — wire to notifications.

comment ​

> comment: Comment

userId ​

> userId: string


comment:reopened ​

> comment:reopened: object

Defined in: comments/src/plugin.ts:13

comment ​

> comment: Comment


comment:resolved ​

> comment:resolved: object

Defined in: comments/src/plugin.ts:12

comment ​

> comment: Comment


comment:updated ​

> comment:updated: object

Defined in: comments/src/plugin.ts:10

comment ​

> comment: Comment


drive:connected ​

> drive:connected: object

Defined in: drives/src/drives.ts:86

connectionId ​

> connectionId: string

label ​

> label: string

provider ​

> provider: string

tenantId ​

> tenantId: string


drive:credentials_invalid ​

> drive:credentials_invalid: object

Defined in: drives/src/drives.ts:97

connectionId ​

> connectionId: string

provider ​

> provider: string

reason ​

> reason: string

tenantId ​

> tenantId: string


drive:credentials_refreshed ​

> drive:credentials_refreshed: object

Defined in: drives/src/drives.ts:96

connectionId ​

> connectionId: string

provider ​

> provider: string

rotated ​

> rotated: boolean

tenantId ​

> tenantId: string


drive:disconnected ​

> drive:disconnected: object

Defined in: drives/src/drives.ts:87

connectionId ​

> connectionId: string

provider ​

> provider: string

revocation ​

> revocation: DriveRevocationOutcome

Why, when it was not — see DriveRevocationOutcome.

revoked ​

> revoked: boolean

Whether the grant was actually revoked at the provider.

tenantId ​

> tenantId: string


drive:item_imported ​

> drive:item_imported: object

Defined in: drives/src/import.ts:21

connectionId ​

> connectionId: string

externalId ​

> externalId: string

strategy ​

> strategy: DriveImportStrategy

targetId ​

> targetId: string

tenantId ​

> tenantId: string

version ​

> version: string


drive:item_skipped ​

> drive:item_skipped: object

Defined in: drives/src/import.ts:29

connectionId ​

> connectionId: string

externalId ​

> externalId: string

reason ​

> reason: DriveSkipReason

tenantId ​

> tenantId: string


drive:sync_completed ​

> drive:sync_completed: DriveSyncResult & object

Defined in: drives/src/sync.ts:128

Type Declaration ​

provider ​

> provider: string

tenantId ​

> tenantId: string


drive:sync_failed ​

> drive:sync_failed: object

Defined in: drives/src/sync.ts:129

connectionId ​

> connectionId: string

provider ​

> provider: string

reason ​

> reason: string

tenantId ​

> tenantId: string


drive:sync_started ​

> drive:sync_started: object

Defined in: drives/src/sync.ts:127

connectionId ​

> connectionId: string

mode ​

> mode: "delta" | "listing"

provider ​

> provider: string

tenantId ​

> tenantId: string


file:deleted ​

> file:deleted: object

Defined in: files/src/plugin.ts:12

id ​

> id: string

tenantId ​

> tenantId: string


file:scanned ​

> file:scanned: object

Defined in: files/src/plugin.ts:13

file ​

> file: FileRecord


file:uploaded ​

> file:uploaded: object

Defined in: files/src/plugin.ts:11

file ​

> file: FileRecord


notification:failed ​

> notification:failed: object

Defined in: notifications/src/index.ts:65

channel ​

> channel: string

error ​

> error: unknown

notification ​

> notification: string

recipientId ​

> recipientId: string


notification:sent ​

> notification:sent: object

Defined in: notifications/src/index.ts:64

channel ​

> channel: string

notification ​

> notification: string

recipientId ​

> recipientId: string


permission:delegated ​

> permission:delegated: object

Defined in: permissions/src/index.ts:61

gate.delegate() let one user act with a subset of another's authority.

expiresAt? ​

> optional expiresAt?: number

fromUserId ​

> fromUserId: string

permissions ​

> permissions: string[]

scope ​

> scope: string

toUserId ​

> toUserId: string


permission:denied ​

> permission:denied: object

Defined in: permissions/src/index.ts:46

A permission check refused the caller (authorize(), meta.can, audiences).

permission ​

> permission: string

scope ​

> scope: string

userId ​

> userId: string


permission:granted ​

> permission:granted: object

Defined in: permissions/src/index.ts:52

Permissions were granted — to a role (role) or directly to a user (userId).

expiresAt? ​

> optional expiresAt?: number

Set for time-boxed grants (grantTemporarily()).

permissions ​

> permissions: string[]

role? ​

> optional role?: string

scope ​

> scope: string

userId? ​

> optional userId?: string


permission:role_assigned ​

> permission:role_assigned: object

Defined in: permissions/src/index.ts:48

gate.assignRole() gave a user a role.

role ​

> role: string

scope ​

> scope: string

userId ​

> userId: string


permission:role_removed ​

> permission:role_removed: object

Defined in: permissions/src/index.ts:50

gate.removeRole() took a role away.

role ​

> role: string

scope ​

> scope: string

userId ​

> userId: string


reconciler:run ​

> reconciler:run: ReconcilerRunResult

Defined in: scheduler/src/reconciler.ts:24

One reconciler run finished (or was skipped).


team:invited ​

> team:invited: object

Defined in: teams/src/plugin.ts:15

An invitation was created — the app emails the token as a link.

invitation ​

> invitation: PublicInvitation

token ​

> token: string


team:joined ​

> team:joined: object

Defined in: teams/src/plugin.ts:16

membership ​

> membership: Membership


team:member_removed ​

> team:member_removed: object

Defined in: teams/src/plugin.ts:18

tenantId ​

> tenantId: string

userId ​

> userId: string


team:role_changed ​

> team:role_changed: object

Defined in: teams/src/plugin.ts:17

membership ​

> membership: Membership


tenancy:created ​

> tenancy:created: object

Defined in: tenancy/src/index.ts:85

A tenant was created AND provisioned — emitted by tenancy.create() after onProvision has resolved, so a listener may assume the tenant's storage exists and is usable (send the welcome email, seed demo data, notify the admin panel).

It does NOT fire if provisioning threw. That is deliberate: a listener that reacts to a half-built tenant is worse than one that never runs.

tenant ​

> tenant: Tenant


tenancy:destroyed ​

> tenancy:destroyed: object

Defined in: tenancy/src/index.ts:93

A tenant was removed — record and storage both gone.

Emitted after the record is deleted, so a listener that reacts by cleaning up rows of its own never finds the tenant still listed. It does NOT fire when deprovisioning threw and the record was kept.

tenant ​

> tenant: Tenant


tenancy:switched ​

> tenancy:switched: object

Defined in: tenancy/src/index.ts:75

Emitted whenever execution enters a tenant context.

tenant ​

> tenant: Tenant

Released under the MIT License.