Skip to main content
POST
Rotate a scoped client's secret

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

client_id
string
required

The scoped client's id.

Body

application/json
previous_secret_ttl
integer

Seconds the replaced secret keeps working.

Required range: 0 <= x <= 604800

Response

Success. Cache-Control is no-store; the secret is never shown again.

A client and, from a create or a rotate of a confidential client, its one-time secret.

client
object
required

A scoped client as the identity service's lifecycle API describes it (ScopedClient in services/identity/api/openapi.yaml), passed through by Rails. It never carries a secret or a digest.

client_secret
string

Shown once. Absent for a publishable client.

status
integer
meta
object