Authorization servers: Clients
The Clients tab manages OAuth clients below one hosted authorization-server UUID. Client identifiers are unique within that resource. External resources do not host clients and therefore do not show this tab.
Open the tab
| Navigation | Protocols, Authorization Servers, select a hosted resource, Clients |
| Resource link | #tenant={tenantId}&surface=as&instance={authorizationServerId}&tab=clients |
| Scope | Customer tenant and selected hosted resource |
Register a public client
Choose Add client, select Public, then configure its client ID, redirect URIs, grants, response types, and allowed scopes. Public browser and native clients must use authorization code with PKCE. A public client has no client secret.
Redirect URIs are exact values. Scheme, host, port, path, query, and trailing slash differences are significant. Register every supported callback explicitly.
Register a confidential client
Select Confidential, configure the protocol fields, then choose one credential method:
- Write a new client secret. The value is accepted once, stored through secret management, and never returned by a later read.
- Select an existing typed secret reference.
- Configure private-key JWT with a tenant-visible KMS resource and key alias when the client authentication method permits it.
The response confirms only the credential type and reference metadata. It cannot be used to recover a raw secret or private key.
Rotate credentials
Use Replace credential to write a new secret or select a new typed reference. Rotation is an explicit operation. Editing redirect URIs or display metadata does not rotate a credential.
After rotation, update the client application and verify a complete token exchange. Retire the old managed secret according to the tenant's secret-management policy.
Update and remove clients
Updates use the current resource revision and fail on stale edits. A client cannot enable grants or scopes that the hosted authorization server does not allow.
Deleting a client prevents new authorization and token requests. Existing token validity follows the hosted token policy; deletion does not rewrite already issued tokens.
REST operations
The tab uses these UUID-scoped operations:
GET /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/clients
POST /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/clients
GET /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/clients/{clientId}
PUT /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/clients/{clientId}
DELETE /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/clients/{clientId}
See the Platform Config REST reference for the exact public and confidential client schemas.