O Auth Client List
List OAuth clients created by the authenticated account. This is the member-facing "apps I created" view. OAuth clients are application definitions: client ID, client type, redirect URIs, allowed scopes, and allowed grants. This does not list built-in first-party clients or third-party apps the member has merely authorised. Use `/auth/oauth/tokens` for the "apps I have authorised" view.
/auth/oauth/clientsList OAuth clients created by the authenticated account.
This is the member-facing "apps I created" view. OAuth clients are application definitions: client ID, client type, redirect URIs, allowed scopes, and allowed grants.
This does not list built-in first-party clients or third-party apps the
member has merely authorised. Use /auth/oauth/tokens for the
"apps I have authorised" view.
Authorization
browser In: cookie
Response Body
application/json
application/json
curl -X GET "https://example.com/auth/oauth/clients"{
"clients": [
{
"id": "cc5lnd2s1s4652adtu50",
"createdAt": "2019-08-24T14:15:22Z",
"updatedAt": "2019-08-24T14:15:22Z",
"account_id": "cc5lnd2s1s4652adtu50",
"registration_approved_by_account_id": "cc5lnd2s1s4652adtu50",
"dcr_iat_id": "cc5lnd2s1s4652adtu50",
"client_id": "string",
"name": "string",
"type": "public",
"scope_policy": "explicit",
"redirect_uris": [
"http://example.com"
],
"allowed_scopes": [
"string"
],
"allowed_grants": [
"string"
]
}
]
}{
"type": "string",
"title": "string",
"detail": "string",
"trace_id": "string",
"metadata": {}
}O Auth Client Get GET
Read an OAuth client created by the authenticated account. Member-created clients are third-party application identities. They may be public or confidential but are never first-party inherited-permission clients.
O Auth Client Register POST
RFC 7591 OAuth 2.0 Dynamic Client Registration. Ordinary Authorization Code clients are tenant-owned and must use PKCE. Only an explicit grant_types: [client_credentials] request provisions a bot account and a separate OAuth client atomically, with client_name as its handle. It requires private_key_jwt and public JWKS. Mixed autonomous and delegated grants are rejected. Delegated private_key_jwt clients create no account. Autonomous clients inherit the bot account's current role permissions. Client credentials token requests without scope receive those permissions; explicit token scopes may narrow them. The optional runtime setting services.oauth.autonomous_registration_role_id assigns an additional role atomically at provisioning; deleted role references are skipped. Autonomous registration is controlled by the runtime setting services.oauth.autonomous_registration_mode: disabled rejects it, protected requires an Initial Access Token in Authorization: Bearer, and open permits it without a token. Supplied tokens must always be valid and authorize autonomous registration only. One use is consumed atomically with successful account and client creation. Invalid metadata or handle collisions do not consume a use. Ordinary DCR does not require an IAT. This endpoint is rate limited. In approval mode, a valid IAT permits immediate registration. Otherwise, autonomous clients must opt in with registration_mode: [approval] and receive 202 with a registration_code and verification challenge. Poll this endpoint with registration_code; metadata supplied on a poll is ignored. Approval returns 201 on a subsequent poll. Early polls return 429 with Retry-After. Denial, expiry, and unknown or consumed codes return 400. Send registration_code and cancel_registration: true to cancel a pending request (204). No account or client exists while approval is pending. Implements draft-dellaert-oauth-approval-based-dcr-00 (experimental).