Skip to main content
POST
Create a scoped client

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Body

application/json
name
string
required

A label shown to administrators.

kind
enum<string>
required

A confidential client has a secret; a publishable one is held to its allowed origins instead.

Available options:
confidential,
publishable
scopes
string[]
required

The resource:verb scopes the client may hold; may be empty. A publishable client may hold only the scopes a public token could (dam:upload, dam:browse, dam:unsplash, dam:ai_generate, media:read, products:read, enrollments:read, playlists:read, forms:read); any other is refused with 422 and needs a confidential client.

allowed_origins
string[]

Required for a publishable client, refused for a confidential one. Each entry is scheme://host[:port].

expires_at
string<date-time> | null

When the client stops authenticating, or null for never.

Response

Created. Cache-Control is no-store; the secret is never shown again.

A client and, from a create or a rotate of a confidential client, its one-time secret.

client
object
required

A scoped client as the identity service's lifecycle API describes it (ScopedClient in services/identity/api/openapi.yaml), passed through by Rails. It never carries a secret or a digest.

client_secret
string

Shown once. Absent for a publishable client.

status
integer
meta
object