Part of fells-code/seamless-auth-api#334. Depends on fells-code/seamless-auth-api#336 (bulk import endpoint).
Problem
Moving an organization onto Seamless Auth starts with getting its users out of the current system. There is no tooling for that today.
Proposal
A seamless migrate command that reads users from a source, maps them, and imports them through the bulk import endpoint.
- Sources, in order:
- CSV (covers HR and payroll exports, and anything else as a fallback)
- Microsoft Entra ID (Microsoft Graph)
- Google Workspace
- Okta
- Auth0, AWS Cognito, Firebase Auth, Keycloak realm export
- Mapping file: which source fields become email, phone, display name, roles and organization, kept in the repo of the migration so it can be re-run
--dry-run by default on first run, showing what would be created, updated, skipped and rejected
- Report: a file (CSV and JSON) of every row and its outcome, written so it can be handed to the organization as a migration artifact
- Re-runnable: idempotent on the source system's user ID
- Never reads or exports passwords or password hashes, even where the source offers them
Notes
- Start with CSV and Entra ID. Each additional source can be its own follow-up issue.
- Source credentials (Graph app secret, Okta token) come from env vars or the profile, never flags, so they stay out of shell history.
Part of fells-code/seamless-auth-api#334. Depends on fells-code/seamless-auth-api#336 (bulk import endpoint).
Problem
Moving an organization onto Seamless Auth starts with getting its users out of the current system. There is no tooling for that today.
Proposal
A
seamless migratecommand that reads users from a source, maps them, and imports them through the bulk import endpoint.--dry-runby default on first run, showing what would be created, updated, skipped and rejectedNotes