---
title: "Update OAuth client"
method: PATCH
path: "/admin/oauth-clients/{id}"
tags: ["OAuth Clients"]
---

# Update OAuth client

`PATCH /admin/oauth-clients/{id}`

Update an OAuth client's name, description, redirect_uris, or active status.

## Path parameters

- `id` string, required

## Request body

- OAuthClientUpdateRequest — Request body for updating an OAuth client.
  - `active` boolean, nullable
  - `allowed_scopes` string[], nullable — Scope restriction list. Null means no change; an empty list denies all non-OIDC scopes; the wildcard ``["*"]`` resets to unrestricted.
  - `description` string, nullable
  - `name` string, nullable
  - `redirect_uris` string[], nullable
  - `require_consent` boolean, nullable

## Response `200`

Successful Response

- OAuthClientResponse — An OAuth client in API responses.
  - `active` boolean, required
  - `allowed_scopes` string[], nullable, required — Scopes this client may request. Null means unrestricted.
  - `approval_status` string, required — Admin approval lifecycle: ``pending``, ``approved``, or ``denied``. Only approved clients may enter OAuth flows; ``active`` remains the independent kill switch.
  - `client_id` string, required — Public client identifier used in OAuth flows.
  - `consent_model` string, required — What a user's consent grants for this client: ``user`` or ``agent``.
  - `created_at` string, date-time, required
  - `created_by` string, nullable, required
  - `description` string, nullable, required
  - `id` string, required — Internal ID (ksuid).
  - `name` string, required
  - `redirect_uris` string[], required
  - `registration_source` string, required — How the client entered the registry: ``admin`` or ``dcr``.
  - `require_consent` boolean, required — Whether a consent screen is shown during authorization.
  - `software_id` string, nullable, required — RFC 7591 software identifier claimed at registration, if any.
  - `token_endpoint_auth_method` string, required — Client authentication method at the token endpoint: ``client_secret_basic`` (confidential) or ``none`` (public, PKCE-only).
  - `updated_at` string, date-time, nullable, required

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found
- `422` — Unprocessable Entity
- `500` — Internal Server Error
- `503` — Service Unavailable

## Changes

- **2026-09-01** `52699e827836` — 5 info
  - added the required property `approval_status` to the response with the `200` status
  - added the required property `consent_model` to the response with the `200` status
  - added the required property `registration_source` to the response with the `200` status
  - added the required property `software_id` to the response with the `200` status
  - …1 more
- **2026-08-31** `170ab6ea6e23` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/jentic/apis/jentic-control-plane-api/changes/admin/oauth-clients/:id/patch.md)

---

[API](https://skmtc.dev/jentic/apis/jentic-control-plane-api.md) · [All operations](https://skmtc.dev/jentic/apis/jentic-control-plane-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/jentic/jentic-control-plane-api/revisions/dceddff07ff7/schema)
