API reference

Sign-in clients

Register OpenID Connect clients that let people sign in to a Serverless App Service's app.

Client secrets are returned once, when a client is created or its secret is replaced. See Sign in with for the flow your app runs.

GET /v1/orgs/:orgId/projects/:projectId/oauth-clients

The project's sign-in clients (never their secrets), with the issuer and its discovery URL.

Auth: user access token or platform agent key · Scope: projects:read

Path parameterDescription
:orgIdOrganization id (org_…).
:projectIdServerless App Service id (prj_…).

Response 200

{
  issuer: string
  discovery: string
  clients: {
    createdAt?: number
    updatedAt?: number
    lastUsedAt?: number
    secretExpiresAt?: number
    assignmentRequired: boolean
    clientId: string
    name: string
    redirectUris: string[]
    subjectType: "public" | "pairwise"
  }[]
}

Errors

StatusMessage
404Serverless App Service not found

POST /v1/orgs/:orgId/projects/:projectId/oauth-clients

Registers a client; the secret is in this response only.

Auth: user access token or platform agent key · Scope: projects:write

Path parameterDescription
:orgIdOrganization id (org_…).
:projectIdServerless App Service id (prj_…).

Request body

FieldTypeRequiredDefaultNotes
namestringYes1–64 characters; trimmed
redirectUrisstring[]Yes1–10 items; each 1–2,048 characters, trimmed
subjectType"pairwise" | "public"No"pairwise"
clientUristringNoup to 512 characters; trimmed
logoUristringNoup to 512 characters; trimmed
policyUristringNoup to 512 characters; trimmed
tosUristringNoup to 512 characters; trimmed

Response 201

{
  client: {
    createdAt?: number
    updatedAt?: number
    lastUsedAt?: number
    secretExpiresAt?: number
    assignmentRequired: boolean
    clientId: string
    name: string
    redirectUris: string[]
    subjectType: "public" | "pairwise"
  }
  clientSecret: string
}

Errors

StatusMessage
400A Serverless App Service can have up to 10 sign-in clients.
404Serverless App Service not found

PATCH /v1/orgs/:orgId/projects/:projectId/oauth-clients/:clientId

Renames a sign-in client or replaces its redirect URIs.

Auth: user access token or platform agent key · Scope: projects:write

Path parameterDescription
:orgIdOrganization id (org_…).
:projectIdServerless App Service id (prj_…).
:clientIdSign-in client id (cli_…).

Request body

FieldTypeRequiredNotes
namestringNo1–64 characters; trimmed
redirectUrisstring[]No1–10 items; each 1–2,048 characters, trimmed
clientUristringNoup to 512 characters; trimmed
logoUristringNoup to 512 characters; trimmed
policyUristringNoup to 512 characters; trimmed
tosUristringNoup to 512 characters; trimmed

Also checked: Nothing to update.

Response 200

{
  client: {
    createdAt?: number
    updatedAt?: number
    lastUsedAt?: number
    secretExpiresAt?: number
    assignmentRequired: boolean
    clientId: string
    name: string
    redirectUris: string[]
    subjectType: "public" | "pairwise"
  }
}

Errors

StatusMessage
404Client not found

POST /v1/orgs/:orgId/projects/:projectId/oauth-clients/:clientId/secret

Replaces the secret (the old one stops working at once); the new one is in this response only.

Auth: user access token or platform agent key · Scope: projects:write

Path parameterDescription
:orgIdOrganization id (org_…).
:projectIdServerless App Service id (prj_…).
:clientIdSign-in client id (cli_…).

Response 200

{
  client: {
    createdAt?: number
    updatedAt?: number
    lastUsedAt?: number
    secretExpiresAt?: number
    assignmentRequired: boolean
    clientId: string
    name: string
    redirectUris: string[]
    subjectType: "public" | "pairwise"
  }
  clientSecret: string
}

Errors

StatusMessage
404Client not found

DELETE /v1/orgs/:orgId/projects/:projectId/oauth-clients/:clientId

Deletes the client: sign-ins and refreshes with it stop at once.

Auth: user access token or platform agent key · Scope: projects:write

Path parameterDescription
:orgIdOrganization id (org_…).
:projectIdServerless App Service id (prj_…).
:clientIdSign-in client id (cli_…).

Response 204 with no body.

Errors

StatusMessage
404Client not found