OAuth Clients

Update OAuth client

Update an OAuth client's name, description, redirect_uris, or active status.

patch/admin/oauth-clients/{id}

Path parameters

idstring required

Request body

activeboolean nullable
allowed_scopesstring[] nullable

Scope restriction list. Null means no change; an empty list denies all non-OIDC scopes; the wildcard ["*"] resets to unrestricted.

descriptionstring nullable
namestring nullable
redirect_urisstring[] nullable
require_consentboolean nullable

Response

Successful Response

activeboolean required
allowed_scopesstring[] nullable required

Scopes this client may request. Null means unrestricted.

approval_statusstring required

Admin approval lifecycle: pending, approved, or denied. Only approved clients may enter OAuth flows; active remains the independent kill switch.

client_idstring required

Public client identifier used in OAuth flows.

consent_modelstring required

What a user's consent grants for this client: user or agent.

created_atstring date-time required
created_bystring nullable required
descriptionstring nullable required
idstring required

Internal ID (ksuid).

namestring required
redirect_urisstring[] required
registration_sourcestring required

How the client entered the registry: admin or dcr.

require_consentboolean required

Whether a consent screen is shown during authorization.

software_idstring nullable required

RFC 7591 software identifier claimed at registration, if any.

token_endpoint_auth_methodstring required

Client authentication method at the token endpoint: client_secret_basic (confidential) or none (public, PKCE-only).

updated_atstring date-time nullable required

Example response

{
  "active": true,
  "approval_status": "approved",
  "client_id": "oc_abc123...",
  "consent_model": "user",
  "created_at": "2026-08-18T12:00:00Z",
  "created_by": "usr_abc123",
  "description": "My application production deployment",
  "id": "oac_2NxYz...",
  "name": "my-app-production",
  "redirect_uris": [
    "https://app.example.com/auth/callback"
  ],
  "registration_source": "admin",
  "require_consent": true,
  "token_endpoint_auth_method": "client_secret_basic"
}

Changes