Skip to main content
Version: v0.25.0 (Latest)

Authorization servers: Clients

The Clients tab manages OAuth clients below one hosted authorization-server UUID. Client identifiers are unique within that resource. External resources do not host clients and therefore do not show this tab.

Open the tab​

NavigationProtocols, Authorization Servers, select a hosted resource, Clients
Resource link#tenant={tenantId}&surface=as&instance={authorizationServerId}&tab=clients
ScopeCustomer tenant and selected hosted resource

Register a public client​

Choose Add client, select Public, then configure its client ID, redirect URIs, grants, response types, and allowed scopes. Public browser and native clients must use authorization code with PKCE. A public client has no client secret.

Redirect URIs are exact values. Scheme, host, port, path, query, and trailing slash differences are significant. Register every supported callback explicitly.

Register a confidential client​

Select Confidential, configure the protocol fields, then choose one credential method:

  • Write a new client secret. The value is accepted once, stored through secret management, and never returned by a later read.
  • Select an existing typed secret reference.
  • Configure private-key JWT with a tenant-visible KMS resource and key alias when the client authentication method permits it.

The response confirms only the credential type and reference metadata. It cannot be used to recover a raw secret or private key.

Rotate credentials​

Use Replace credential to write a new secret or select a new typed reference. Rotation is an explicit operation. Editing redirect URIs or display metadata does not rotate a credential.

After rotation, update the client application and verify a complete token exchange. Retire the old managed secret according to the tenant's secret-management policy.

Update and remove clients​

Updates use the current resource revision and fail on stale edits. A client cannot enable grants or scopes that the hosted authorization server does not allow.

Deleting a client prevents new authorization and token requests. Existing token validity follows the hosted token policy; deletion does not rewrite already issued tokens.

REST operations​

The tab uses these UUID-scoped operations:

GET    /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/clients
POST /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/clients
GET /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/clients/{clientId}
PUT /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/clients/{clientId}
DELETE /api/platform/config/v1/tenants/{tenantId}/authorization-servers/{authorizationServerId}/clients/{clientId}

See the Platform Config REST reference for the exact public and confidential client schemas.