Skip to content
Esc
navigateopen⌘Jpreview
Dashboard

Create OAuth2 Client

POST/appid-{appId}/recipe/oauth/clients
Authorization
api-keyAPI key · headerrequired
The core service API token. If you are using a self-hosted core service and you have not generated a token, you can omit the header.
Header parameters
cdi-versionstring
X.Y of the X.Y.Z CDI version.
Request body
application/json
clientIdstring
clientNamestring
clientSecretstring
redirectUrisstring[]
grantTypesstring[]
responseTypesstring[]
scopestring
audiencestring[]
policyUristring
allowedCorsOriginsstring[]
tosUristring
clientUristring
logoUristring
tokenEndpointAuthMethodstring
createdAtstring<date-time>
updatedAtstring<date-time>
postLogoutRedirectUrisstring[]
metadataobject
authorizationCodeGrantAccessTokenLifespanstring | null
authorizationCodeGrantIdTokenLifespanstring | null
authorizationCodeGrantRefreshTokenLifespanstring | null
clientCredentialsGrantAccessTokenLifespanstring | null
implicitGrantAccessTokenLifespanstring | null
implicitGrantIdTokenLifespanstring | null
refreshTokenGrantIdTokenLifespanstring | null
refreshTokenGrantAccessTokenLifespanstring | null
refreshTokenGrantRefreshTokenLifespanstring | null
enableRefreshTokenRotationboolean
Responses
200OAuth2 Client Result
One of:
object
statusstatusOK
Allowed:OK
clientIdstring
clientNamestring
clientSecretstring
redirectUrisstring[]
grantTypesstring[]
responseTypesstring[]
scopestring
audiencestring[]
policyUristring
allowedCorsOriginsstring[]
tosUristring
clientUristring
logoUristring
tokenEndpointAuthMethodstring
createdAtstring<date-time>
updatedAtstring<date-time>
postLogoutRedirectUrisstring[]
metadataobject
authorizationCodeGrantAccessTokenLifespanstring | null
authorizationCodeGrantIdTokenLifespanstring | null
authorizationCodeGrantRefreshTokenLifespanstring | null
clientCredentialsGrantAccessTokenLifespanstring | null
implicitGrantAccessTokenLifespanstring | null
implicitGrantIdTokenLifespanstring | null
refreshTokenGrantIdTokenLifespanstring | null
refreshTokenGrantAccessTokenLifespanstring | null
refreshTokenGrantRefreshTokenLifespanstring | null
enableRefreshTokenRotationboolean
oauthError
statusstringrequired
Allowed:OAUTH_ERROR
errorstringrequired
errorDescriptionstringrequired
statusCodeintegerrequired
400error code 400
string
401error code 401
string
402error code 402
string
404error code 404
string
500error code 500
string
Try it
Server
Authorization
Parameters
Bodyapplication/json
Request
curl -X POST "/appid-{appId}/recipe/oauth/clients" \
  -H "api-key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
  "clientId": "stcl_c6dd9189-33b8-4ec0-8aea-a0ffdaf75fcb",
  "clientName": "Hello",
  "clientSecret": "T98n1YIMWqr4wOM.~bV4HOPFmO",
  "redirectUris": [
    "http://localhost:3000/auth/callback/ory"
  ],
  "grantTypes": [
    "authorization_code",
    "refresh_token"
  ],
  "responseTypes": [
    "code",
    "id_token"
  ],
  "scope": "offline_access openid email",
  "audience": [],
  "policyUri": "",
  "allowedCorsOrigins": [],
  "tosUri": "",
  "clientUri": "",
  "logoUri": "",
  "tokenEndpointAuthMethod": "client_secret_post",
  "createdAt": "2025-02-24T08:14:40Z",
  "updatedAt": "2025-02-24T08:14:40.362463Z",
  "postLogoutRedirectUris": [
    "http://localhost:3000"
  ],
  "metadata": {},
  "authorizationCodeGrantAccessTokenLifespan": "1h0m0s",
  "authorizationCodeGrantIdTokenLifespan": "1h0m0s",
  "authorizationCodeGrantRefreshTokenLifespan": "1h0m0s",
  "clientCredentialsGrantAccessTokenLifespan": "1h0m0s",
  "implicitGrantAccessTokenLifespan": "1h0m0s",
  "implicitGrantIdTokenLifespan": "1h0m0s",
  "refreshTokenGrantIdTokenLifespan": "1h0m0s",
  "refreshTokenGrantAccessTokenLifespan": "1h0m0s",
  "refreshTokenGrantRefreshTokenLifespan": "1h0m0s",
  "enableRefreshTokenRotation": false
}'
Response
{
  "status": "OK",
  "clientId": "stcl_c6dd9189-33b8-4ec0-8aea-a0ffdaf75fcb",
  "clientName": "Hello",
  "clientSecret": "T98n1YIMWqr4wOM.~bV4HOPFmO",
  "redirectUris": [
    "http://localhost:3000/auth/callback/ory"
  ],
  "grantTypes": [
    "authorization_code",
    "refresh_token"
  ],
  "responseTypes": [
    "code",
    "id_token"
  ],
  "scope": "offline_access openid email",
  "audience": [],
  "policyUri": "",
  "allowedCorsOrigins": [],
  "tosUri": "",
  "clientUri": "",
  "logoUri": "",
  "tokenEndpointAuthMethod": "client_secret_post",
  "createdAt": "2025-02-24T08:14:40Z",
  "updatedAt": "2025-02-24T08:14:40.362463Z",
  "postLogoutRedirectUris": [
    "http://localhost:3000"
  ],
  "metadata": {},
  "authorizationCodeGrantAccessTokenLifespan": "1h0m0s",
  "authorizationCodeGrantIdTokenLifespan": "1h0m0s",
  "authorizationCodeGrantRefreshTokenLifespan": "1h0m0s",
  "clientCredentialsGrantAccessTokenLifespan": "1h0m0s",
  "implicitGrantAccessTokenLifespan": "1h0m0s",
  "implicitGrantIdTokenLifespan": "1h0m0s",
  "refreshTokenGrantIdTokenLifespan": "1h0m0s",
  "refreshTokenGrantAccessTokenLifespan": "1h0m0s",
  "refreshTokenGrantRefreshTokenLifespan": "1h0m0s",
  "enableRefreshTokenRotation": false
}

API reference

API schema and response details