OAuth Clients

Register OAuth client

Register a new OAuth client for third-party application integration.

The generated client_id and client_secret are returned in the response. The secret is shown only once — store it securely.

post/admin/oauth-clients

Request body

allowed_scopesstring[] nullable

If set, restricts which scopes this client may request. An empty list denies all non-OIDC scopes. Null means unrestricted (all scopes permitted).

descriptionstring nullable

Optional description of the client.

namestring required

Human-readable name for the client.

redirect_urisstring[] required

Allowed OAuth callback URLs. At least one required.

require_consentboolean

Whether to show a consent screen during authorization. Set to false for trusted first-party integrations.

Example request

{
  "description": "My application production deployment",
  "name": "my-app-production",
  "redirect_uris": [
    "https://app.example.com/auth/callback"
  ],
  "require_consent": true
}

Response

Successful Response

activeboolean required
allowed_scopesstring[] nullable required

Scopes this client may request. Null means unrestricted.

client_idstring required

Public client identifier used in OAuth flows.

client_secretstring required

The client secret. Shown only once at creation — store it securely.

created_atstring date-time required
created_bystring nullable required
descriptionstring nullable required
idstring required

Internal ID (ksuid).

namestring required
redirect_urisstring[] required
require_consentboolean required

Whether a consent screen is shown during authorization.

updated_atstring date-time nullable required

Example response

{
  "active": true,
  "client_id": "oc_abc123...",
  "created_at": "2026-08-18T12:00:00Z",
  "created_by": "usr_abc123",
  "description": "My application production deployment",
  "id": "oac_2NxYz...",
  "name": "my-app-production",
  "redirect_uris": [
    "https://app.example.com/auth/callback"
  ],
  "require_consent": true
}

Changes

Changed in 1 of the 85 revisions of this API.1