Storyden
Auth

O Auth Client Update

Update an OAuth client created by the authenticated account. Allowed scopes must remain within the authenticated account's current permissions. If the account has `ADMINISTRATOR`, it may configure any Storyden permission scope because `ADMINISTRATOR` implicitly grants all permissions. Changing allowed scopes affects future grants and refreshes but does not immediately invalidate already-issued JWT access tokens.

PATCH/auth/oauth/clients/{oauth_client_id}

Update an OAuth client created by the authenticated account.

Allowed scopes must remain within the authenticated account's current permissions. If the account has ADMINISTRATOR, it may configure any Storyden permission scope because ADMINISTRATOR implicitly grants all permissions.

Changing allowed scopes affects future grants and refreshes but does not immediately invalidate already-issued JWT access tokens.

storyden-session<token>

In: cookie

Path Parameters

oauth_client_id*string

OAuth client ID.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

curl -X PATCH "https://example.com/auth/oauth/clients/cc5lnd2s1s4652adtu50" \  -H "Content-Type: application/json" \  -d '{}'
{
  "id": "cc5lnd2s1s4652adtu50",
  "createdAt": "2019-08-24T14:15:22Z",
  "updatedAt": "2019-08-24T14:15:22Z",
  "account_id": "cc5lnd2s1s4652adtu50",
  "registration_approved_by_account_id": "cc5lnd2s1s4652adtu50",
  "dcr_iat_id": "cc5lnd2s1s4652adtu50",
  "client_id": "string",
  "name": "string",
  "type": "public",
  "scope_policy": "explicit",
  "redirect_uris": [
    "http://example.com"
  ],
  "allowed_scopes": [
    "string"
  ],
  "allowed_grants": [
    "string"
  ]
}
Empty
Empty
Empty
{
  "type": "string",
  "title": "string",
  "detail": "string",
  "trace_id": "string",
  "metadata": {}
}

O Auth Client Register POST

RFC 7591 OAuth 2.0 Dynamic Client Registration. Ordinary Authorization Code clients are tenant-owned and must use PKCE. Only an explicit grant_types: [client_credentials] request provisions a bot account and a separate OAuth client atomically, with client_name as its handle. It requires private_key_jwt and public JWKS. Mixed autonomous and delegated grants are rejected. Delegated private_key_jwt clients create no account. Autonomous clients inherit the bot account's current role permissions. Client credentials token requests without scope receive those permissions; explicit token scopes may narrow them. The optional runtime setting services.oauth.autonomous_registration_role_id assigns an additional role atomically at provisioning; deleted role references are skipped. Autonomous registration is controlled by the runtime setting services.oauth.autonomous_registration_mode: disabled rejects it, protected requires an Initial Access Token in Authorization: Bearer, and open permits it without a token. Supplied tokens must always be valid and authorize autonomous registration only. One use is consumed atomically with successful account and client creation. Invalid metadata or handle collisions do not consume a use. Ordinary DCR does not require an IAT. This endpoint is rate limited. In approval mode, a valid IAT permits immediate registration. Otherwise, autonomous clients must opt in with registration_mode: [approval] and receive 202 with a registration_code and verification challenge. Poll this endpoint with registration_code; metadata supplied on a poll is ignored. Approval returns 201 on a subsequent poll. Early polls return 429 with Retry-After. Denial, expiry, and unknown or consumed codes return 400. Send registration_code and cancel_registration: true to cancel a pending request (204). No account or client exists while approval is pending. Implements draft-dellaert-oauth-approval-based-dcr-00 (experimental).

O Auth Device Authorisation POST

Start the OAuth 2.0 Device Authorization Grant for clients that cannot receive a browser redirect directly, such as CLIs, terminals, and desktop tools. The `scope` parameter follows OAuth 2.0 and is optional. Storyden applies additional client policy after parsing the request: - Built-in first-party device clients, such as the default Storyden CLI client, must request exactly `openid profile offline_access`. On approval Storyden expands the issued scope to the approving account's current permissions. - Third-party explicit-scope clients may omit `scope`; omitted scope means no requested scopes. `verification_uri` and `verification_uri_complete` point at the configured frontend consent page, not at an API-rendered HTML page. Custom frontends can change this URL with `OAUTH_DEVICE_AUTHORISATION_CONSENT_URL`.