Discovery
How AI Workbench, nodes and the mobile app find an organisation's platform from a work email, and what the discovery document says.
A client that knows only a person's work email finds the organisation's platform in two steps.
1. DNS
The client takes the email's domain, for example example.com.au from alex@example.com.au, and looks up aioe-discover.example.com.au. Either record works:
| Record | Value |
|---|---|
CNAME | The host name of the organisation's AIOE API, for example aioe.example.com.au |
TXT | v=aioe1; url=https://aioe.example.com.au |
A TXT record holding just a host name or an https:// address is accepted too.
Setting the record up is described in DNS discovery. Mojo Up AI Cloud needs no record: the workbench's Sign in with Mojo Up goes straight to https://ai.mojoup.com.au.
2. The discovery document
The client then fetches https://<host>/.well-known/aioe.json. It is public, holds no secrets, and is cached for five minutes. It tells the client:
| Field | Meaning |
|---|---|
version | Always 1. |
tenant, organisation | The organisation's short id and display name. |
apiUrl | The API's base address. |
relayUrl | Where devices enrol and keep their relay connection. |
meshUrl | Self-hosted only: the overlay network's coordination address. |
signingKeysUrl | The public keys the platform signs remote-control requests with. |
auth | How people sign in: the OpenID Connect issuer, the public clientId and the apiScope to request. |
capabilities | What the platform offers, from ingest, catalogue, policy, relay, mesh and remote-control. |
dpopSigningAlgs | The DPoP proof algorithms accepted for device tokens. |
edition | enterprise for self-hosted AIOE, cloud for Mojo Up AI Cloud. |
Clients hide what capabilities and edition say is not there. The full schema: Discovery endpoint.