Version: v0.25.0 (Latest)
Register clients
Step 3 of 4 in Configure the authorization server.
Loading example...
For Postman or a backend service, register a confidential client with client_credentials, no redirect
URIs, explicit audiences and an explicit token endpoint authentication method:
{
"clientId": "acme-service",
"clientName": "Acme developer service",
"clientType": "confidential",
"enabled": true,
"grantTypes": ["client_credentials"],
"responseTypes": [],
"redirectUris": [],
"tokenEndpointAuthMethod": "client_secret_post",
"principalRoles": ["tenant-admin"],
"allowedAccessTokenAudiences": ["enterprise-tenant-as", "enterprise-issuer", "enterprise-verifier"]
}
Loading example...
The secret is write-only: store it when the response returns it. client_secret_post and
client_secret_basic are not interchangeable, and a mismatch returns invalid_client. Browser and
native clients use authorization_code with exact HTTPS redirect URIs and PKCE S256; they never
receive client_credentials or a service role.
Read a client back after registration to confirm grants, redirects and audiences:
Loading example...
Next
Continue with step 4, Tune token and grant settings.