Skip to main content
Terraform reads the dev tenant and writes the matching code. You then tidy it into the module in Build the module from the generated code. Generating is the quickest way to start, but it’s optional. The blocks can also be written by hand from the resource docs on the Terraform Registry. In that case, configure dev as in step 1 below, then go straight to Build the module from the generated code and use its examples as the starting point.

Prerequisites

1. Configure dev in the portal

Create the dev tenant and configure it. Set up the authenticators before the flow, since the flow editor only offers verification methods that are already enabled.
Authenticators page, Email OTP enabled with Webhook selected and your dev endpoint URL filled in.

Email OTP enabled with a webhook

Authenticators page, Passkey enabled with the relying party and expected origins for your dev domain.

Passkey relying party and expected origins

Actions page, a sign-in flow open in the flow editor. A rule node checking for anonymous IPs, a verification node offering passkey and Email OTP, a block node and a complete node.

The sign-in flow in the flow editor

Branding settings with a logo uploaded, a blue primary button, a pale blue secondary button, and a light blue page background.

Branding for the pre-built UI

Message overrides settings, the Email OTP code entry screen with a custom heading and description.

A message override on the Email OTP code entry screen

2. Create a scratch folder

Terraform can only generate code for resources in the folder you run it from, not inside a module. Create a temporary scratch folder at the repository root, outside envs/, with this main.tf. It’s in .gitignore, so it isn’t committed. The scratch folder is only a place for Terraform to write the generated code. Planning there reads the dev tenant but doesn’t change it, and you delete the folder once the code is in the module.
Each import block tells Terraform to take over something that already exists in the tenant. to is the address the resource gets in the code: its resource type, then a name you choose, such as authsignal_flow.sign_in. id tells the provider which one to read from the tenant. Each resource’s page on the Terraform Registry gives the import ID it takes.

3. Generate the code

Set the environment variables for the dev tenant, then run:
terraform init downloads the Authsignal provider. -generate-config-out makes the plan write a resource block for each import into generated.tf. The plan ends with:
Don’t apply in this folder. It exists only to produce generated.tf, and applying would create a second state for dev here.

Verify

generated.tf has five resource blocks, one per import. Keep the scratch folder until Build the module from the generated code is done. If every import fails with Cannot import non-existent remote object, the host is wrong.