Publish the discovery record
Add the aioe-discover DNS record so a workbench finds your organisation from a person's work email.
When someone connects AI Workbench to their organisation, they type their work email. The workbench takes the domain, looks up aioe-discover.<domain> in DNS, and from the answer finds your AIOE. You publish that record once for each email domain your people use.
How discovery works
- A person enters
ana@example.comin the workbench's Organisation settings. - The workbench queries
aioe-discover.example.com. - The record names your API: either a CNAME to the API's host name, or a TXT record carrying its address.
- The workbench fetches
https://<api-host>/.well-known/aioe.json, the discovery document. It names your organisation, the API and relay addresses, your identity provider's issuer, client ID and API scope, and what this deployment offers. - The workbench starts enrolment, and the person approves it in the console.
The discovery document is public and carries no secrets. AIOE answers it only for a host name that matches your organisation's domains (AIOE_BOOTSTRAP_DOMAINS); for any other host it answers unknown_tenant.
Add the record
Use either form. The console shows both, filled in with your API's address, under Settings, Discovery record.
Point the name at your API's host name:
aioe-discover.example.com. CNAME aioe.example.com.Use this form when nothing else needs the name.
Repeat for every email domain, for example aioe-discover.example.com.au as well. Each domain must also be in AIOE_BOOTSTRAP_DOMAINS (see Connect your identity provider).
Check it
dig +short CNAME aioe-discover.example.com
dig +short TXT aioe-discover.example.com
curl https://aioe.example.com/.well-known/aioe.jsonThe document's organisation is your organisation's name and edition is enterprise. Responses may be cached for five minutes.
Without a DNS record
A person can also choose Enter the platform URL instead in the workbench and type the API's address (for example https://aioe.example.com). The workbench fetches the same discovery document from it. This is useful for a trial, or for a domain where you cannot add records yet.
What the document contains
| Field | What it is |
|---|---|
version | Always 1. |
tenant | Your organisation's short name. |
organisation | Its display name. |
apiUrl | The API's public address (PUBLIC_URL). |
relayUrl | <apiUrl>/relay/v1: where a workbench enrols and holds its relay connection. |
meshUrl | <apiUrl>/mesh/v1: the overlay's coordination service. |
signingKeysUrl | <apiUrl>/.well-known/aioe-jwks.json: the public keys the platform signs requests with. |
auth | kind (oidc), issuer, clientId and apiScope of your identity provider. |
capabilities | What this deployment offers: ingest, catalogue, policy, relay, mesh, remote-control. |
dpopSigningAlgs | The algorithms accepted for key-bound device tokens: ES256, EdDSA. |
edition | enterprise for self-hosted AIOE. |