Skip to main content
Version: v0.25.0 (Latest)

Register clients

Step 3 of 4 in Configure the authorization server.

Loading example...

For Postman or a backend service, register a confidential client with client_credentials, no redirect URIs, explicit audiences and an explicit token endpoint authentication method:

{
"clientId": "acme-service",
"clientName": "Acme developer service",
"clientType": "confidential",
"enabled": true,
"grantTypes": ["client_credentials"],
"responseTypes": [],
"redirectUris": [],
"tokenEndpointAuthMethod": "client_secret_post",
"principalRoles": ["tenant-admin"],
"allowedAccessTokenAudiences": ["enterprise-tenant-as", "enterprise-issuer", "enterprise-verifier"]
}
Loading example...

The secret is write-only: store it when the response returns it. client_secret_post and client_secret_basic are not interchangeable, and a mismatch returns invalid_client. Browser and native clients use authorization_code with exact HTTPS redirect URIs and PKCE S256; they never receive client_credentials or a service role.

Read a client back after registration to confirm grants, redirects and audiences:

Loading example...

Next​

Continue with step 4, Tune token and grant settings.