Mojo UpDocs
Self-hosted AIOE

Publish the discovery record

Add the aioe-discover DNS record so a workbench finds your organisation from a person's work email.

When someone connects AI Workbench to their organisation, they type their work email. The workbench takes the domain, looks up aioe-discover.<domain> in DNS, and from the answer finds your AIOE. You publish that record once for each email domain your people use.

How discovery works

  1. A person enters ana@example.com in the workbench's Organisation settings.
  2. The workbench queries aioe-discover.example.com.
  3. The record names your API: either a CNAME to the API's host name, or a TXT record carrying its address.
  4. The workbench fetches https://<api-host>/.well-known/aioe.json, the discovery document. It names your organisation, the API and relay addresses, your identity provider's issuer, client ID and API scope, and what this deployment offers.
  5. The workbench starts enrolment, and the person approves it in the console.

The discovery document is public and carries no secrets. AIOE answers it only for a host name that matches your organisation's domains (AIOE_BOOTSTRAP_DOMAINS); for any other host it answers unknown_tenant.

Add the record

Use either form. The console shows both, filled in with your API's address, under Settings, Discovery record.

Point the name at your API's host name:

aioe-discover.example.com.  CNAME  aioe.example.com.

Use this form when nothing else needs the name.

Repeat for every email domain, for example aioe-discover.example.com.au as well. Each domain must also be in AIOE_BOOTSTRAP_DOMAINS (see Connect your identity provider).

Check it

Terminal
dig +short CNAME aioe-discover.example.com
dig +short TXT aioe-discover.example.com
curl https://aioe.example.com/.well-known/aioe.json

The document's organisation is your organisation's name and edition is enterprise. Responses may be cached for five minutes.

Without a DNS record

A person can also choose Enter the platform URL instead in the workbench and type the API's address (for example https://aioe.example.com). The workbench fetches the same discovery document from it. This is useful for a trial, or for a domain where you cannot add records yet.

What the document contains

FieldWhat it is
versionAlways 1.
tenantYour organisation's short name.
organisationIts display name.
apiUrlThe API's public address (PUBLIC_URL).
relayUrl<apiUrl>/relay/v1: where a workbench enrols and holds its relay connection.
meshUrl<apiUrl>/mesh/v1: the overlay's coordination service.
signingKeysUrl<apiUrl>/.well-known/aioe-jwks.json: the public keys the platform signs requests with.
authkind (oidc), issuer, clientId and apiScope of your identity provider.
capabilitiesWhat this deployment offers: ingest, catalogue, policy, relay, mesh, remote-control.
dpopSigningAlgsThe algorithms accepted for key-bound device tokens: ES256, EdDSA.
editionenterprise for self-hosted AIOE.

On this page