basalt / core/src / BasaltHooks
Interface: BasaltHooks
Defined in: core/src/hooks.ts:11
Global hook registry for the ecosystem. Packages add their typed hooks via module augmentation:
declare module '@basaltkit/core' { interface BasaltHooks { 'tenancy:switched': { tenantId: string } } }
Indexable
> [hook: string]: unknown
Properties
app:booted
> app:booted: object
Defined in: core/src/app.ts:23
app
> app: BasaltApp
app:registered
> app:registered: object
Defined in: core/src/app.ts:22
app
> app: BasaltApp
app:shutdown
> app:shutdown: object
Defined in: core/src/app.ts:24
app
> app: BasaltApp
auth:account_linked
> auth:account_linked: object
Defined in: auth/src/plugin.ts:58
A provider account (its stable subject) was linked to this account on its first social login.
provider
> provider: string
user
> user: PublicUser
auth:apikey_issued
> auth:apikey_issued: object
Defined in: auth/src/apikeys-plugin.ts:13
id
> id: string
tenantId?
> optional tenantId?: string
userId?
> optional userId?: string
auth:apikey_rejected
> auth:apikey_rejected: object
Defined in: auth/src/apikeys-plugin.ts:21
A presented API key was refused: unknown/revoked/expired (invalid), used outside the tenant it is bound to (tenant_mismatch), used on a session-only route (not_allowed) or beyond its scopes (scope). Never carries the key itself.
id?
> optional id?: string
reason
> reason: "scope" | "invalid" | "tenant_mismatch" | "not_allowed"
tenantId?
> optional tenantId?: string
auth:apikey_revoked
> auth:apikey_revoked: object
Defined in: auth/src/apikeys-plugin.ts:14
id
> id: string
auth:email_verified
> auth:email_verified: object
Defined in: auth/src/plugin.ts:39
user
> user: PublicUser
auth:locked_out
> auth:locked_out: object
Defined in: auth/src/plugin.ts:48
A login was refused because the account (or the client ip) is locked.
email
> email: string
ip?
> optional ip?: string
auth:login
> auth:login: object
Defined in: auth/src/plugin.ts:34
user
> user: PublicUser
auth:login_failed
> auth:login_failed: object
Defined in: auth/src/plugin.ts:35
email
> email: string
auth:logout
> auth:logout: object
Defined in: auth/src/plugin.ts:36
user
> user: PublicUser
auth:mfa_disabled
> auth:mfa_disabled: object
Defined in: auth/src/plugin.ts:44
user
> user: PublicUser
auth:mfa_enabled
> auth:mfa_enabled: object
Defined in: auth/src/plugin.ts:43
user
> user: PublicUser
auth:mfa_failed
> auth:mfa_failed: object
Defined in: auth/src/plugin.ts:46
A wrong MFA code was presented for this user (login or social login).
userId
> userId: string
auth:password_reset
> auth:password_reset: object
Defined in: auth/src/plugin.ts:42
user
> user: PublicUser
auth:password_reset_requested
> auth:password_reset_requested: object
Defined in: auth/src/plugin.ts:41
Password reset requested — the app emails the token as a link.
token
> token: string
user
> user: PublicUser
auth:refresh_reused
> auth:refresh_reused: object
Defined in: auth/src/plugin.ts:50
A consumed refresh token came back; its whole family was revoked (theft indicator).
familyId
> familyId: string
userId
> userId: string
auth:register_existing_email
> auth:register_existing_email: object
Defined in: auth/src/plugin.ts:33
Someone tried to register an email that already has an account. Emitted by the enumeration-safe register endpoint so the app can email the address ("you already have an account — sign in or reset your password") instead of revealing existence in the HTTP response. Only the email is provided.
email
> email: string
auth:registered
> auth:registered: object
Defined in: auth/src/plugin.ts:26
user
> user: PublicUser
auth:social_account_adopted
> auth:social_account_adopted: object
Defined in: auth/src/plugin.ts:56
A provider-verified social login took over an account whose email had never been verified; its previous password, sessions, refresh tokens and MFA and account links were revoked.
user
> user: PublicUser
auth:verify_requested
> auth:verify_requested: object
Defined in: auth/src/plugin.ts:38
Email verification requested — the app emails the token as a link.
token
> token: string
user
> user: PublicUser
billing:canceled
> billing:canceled: object
Defined in: subscriptions/src/plugin.ts:36
subscription
> subscription: SubscriptionRecord
billing:checkout_started
> billing:checkout_started: object
Defined in: subscriptions/src/plugin.ts:39
billableId
> billableId: string
plan
> plan: string
url
> url: string
billing:subscribed
> billing:subscribed: object
Defined in: subscriptions/src/plugin.ts:34
subscription
> subscription: SubscriptionRecord
billing:swapped
> billing:swapped: object
Defined in: subscriptions/src/plugin.ts:35
from
> from: string
subscription
> subscription: SubscriptionRecord
billing:trial_expired
> billing:trial_expired: object
Defined in: subscriptions/src/plugin.ts:37
subscription
> subscription: SubscriptionRecord
billing:webhook
> billing:webhook: object
Defined in: subscriptions/src/plugin.ts:38
event
> event: WebhookEvent
comment:created
> comment:created: object
Defined in: comments/src/plugin.ts:9
comment
> comment: Comment
comment:deleted
> comment:deleted: object
Defined in: comments/src/plugin.ts:11
id
> id: string
resourceId
> resourceId: string
resourceType
> resourceType: string
tenantId
> tenantId: string
comment:mentioned
> comment:mentioned: object
Defined in: comments/src/plugin.ts:15
One per mentioned user — wire to notifications.
comment
> comment: Comment
userId
> userId: string
comment:reopened
> comment:reopened: object
Defined in: comments/src/plugin.ts:13
comment
> comment: Comment
comment:resolved
> comment:resolved: object
Defined in: comments/src/plugin.ts:12
comment
> comment: Comment
comment:updated
> comment:updated: object
Defined in: comments/src/plugin.ts:10
comment
> comment: Comment
drive:connected
> drive:connected: object
Defined in: drives/src/drives.ts:86
connectionId
> connectionId: string
label
> label: string
provider
> provider: string
tenantId
> tenantId: string
drive:credentials_invalid
> drive:credentials_invalid: object
Defined in: drives/src/drives.ts:97
connectionId
> connectionId: string
provider
> provider: string
reason
> reason: string
tenantId
> tenantId: string
drive:credentials_refreshed
> drive:credentials_refreshed: object
Defined in: drives/src/drives.ts:96
connectionId
> connectionId: string
provider
> provider: string
rotated
> rotated: boolean
tenantId
> tenantId: string
drive:disconnected
> drive:disconnected: object
Defined in: drives/src/drives.ts:87
connectionId
> connectionId: string
provider
> provider: string
revocation
> revocation: DriveRevocationOutcome
Why, when it was not — see DriveRevocationOutcome.
revoked
> revoked: boolean
Whether the grant was actually revoked at the provider.
tenantId
> tenantId: string
drive:item_imported
> drive:item_imported: object
Defined in: drives/src/import.ts:21
connectionId
> connectionId: string
externalId
> externalId: string
strategy
> strategy: DriveImportStrategy
targetId
> targetId: string
tenantId
> tenantId: string
version
> version: string
drive:item_skipped
> drive:item_skipped: object
Defined in: drives/src/import.ts:29
connectionId
> connectionId: string
externalId
> externalId: string
reason
> reason: DriveSkipReason
tenantId
> tenantId: string
drive:sync_completed
> drive:sync_completed: DriveSyncResult & object
Defined in: drives/src/sync.ts:128
Type Declaration
provider
> provider: string
tenantId
> tenantId: string
drive:sync_failed
> drive:sync_failed: object
Defined in: drives/src/sync.ts:129
connectionId
> connectionId: string
provider
> provider: string
reason
> reason: string
tenantId
> tenantId: string
drive:sync_started
> drive:sync_started: object
Defined in: drives/src/sync.ts:127
connectionId
> connectionId: string
mode
> mode: "delta" | "listing"
provider
> provider: string
tenantId
> tenantId: string
file:deleted
> file:deleted: object
Defined in: files/src/plugin.ts:12
id
> id: string
tenantId
> tenantId: string
file:scanned
> file:scanned: object
Defined in: files/src/plugin.ts:13
file
> file: FileRecord
file:uploaded
> file:uploaded: object
Defined in: files/src/plugin.ts:11
file
> file: FileRecord
notification:failed
> notification:failed: object
Defined in: notifications/src/index.ts:65
channel
> channel: string
error
> error: unknown
notification
> notification: string
recipientId
> recipientId: string
notification:sent
> notification:sent: object
Defined in: notifications/src/index.ts:64
channel
> channel: string
notification
> notification: string
recipientId
> recipientId: string
permission:delegated
> permission:delegated: object
Defined in: permissions/src/index.ts:61
gate.delegate() let one user act with a subset of another's authority.
expiresAt?
> optional expiresAt?: number
fromUserId
> fromUserId: string
permissions
> permissions: string[]
scope
> scope: string
toUserId
> toUserId: string
permission:denied
> permission:denied: object
Defined in: permissions/src/index.ts:46
A permission check refused the caller (authorize(), meta.can, audiences).
permission
> permission: string
scope
> scope: string
userId
> userId: string
permission:granted
> permission:granted: object
Defined in: permissions/src/index.ts:52
Permissions were granted — to a role (role) or directly to a user (userId).
expiresAt?
> optional expiresAt?: number
Set for time-boxed grants (grantTemporarily()).
permissions
> permissions: string[]
role?
> optional role?: string
scope
> scope: string
userId?
> optional userId?: string
permission:role_assigned
> permission:role_assigned: object
Defined in: permissions/src/index.ts:48
gate.assignRole() gave a user a role.
role
> role: string
scope
> scope: string
userId
> userId: string
permission:role_removed
> permission:role_removed: object
Defined in: permissions/src/index.ts:50
gate.removeRole() took a role away.
role
> role: string
scope
> scope: string
userId
> userId: string
reconciler:run
> reconciler:run: ReconcilerRunResult
Defined in: scheduler/src/reconciler.ts:24
One reconciler run finished (or was skipped).
team:invited
> team:invited: object
Defined in: teams/src/plugin.ts:15
An invitation was created — the app emails the token as a link.
invitation
> invitation: PublicInvitation
token
> token: string
team:joined
> team:joined: object
Defined in: teams/src/plugin.ts:16
membership
> membership: Membership
team:member_removed
> team:member_removed: object
Defined in: teams/src/plugin.ts:18
tenantId
> tenantId: string
userId
> userId: string
team:role_changed
> team:role_changed: object
Defined in: teams/src/plugin.ts:17
membership
> membership: Membership
tenancy:created
> tenancy:created: object
Defined in: tenancy/src/index.ts:85
A tenant was created AND provisioned — emitted by tenancy.create() after onProvision has resolved, so a listener may assume the tenant's storage exists and is usable (send the welcome email, seed demo data, notify the admin panel).
It does NOT fire if provisioning threw. That is deliberate: a listener that reacts to a half-built tenant is worse than one that never runs.
tenant
> tenant: Tenant
tenancy:destroyed
> tenancy:destroyed: object
Defined in: tenancy/src/index.ts:93
A tenant was removed — record and storage both gone.
Emitted after the record is deleted, so a listener that reacts by cleaning up rows of its own never finds the tenant still listed. It does NOT fire when deprovisioning threw and the record was kept.
tenant
> tenant: Tenant
tenancy:switched
> tenancy:switched: object
Defined in: tenancy/src/index.ts:75
Emitted whenever execution enters a tenant context.
tenant
> tenant: Tenant