API reference
Sign-in clients
Register OpenID Connect clients that let people sign in to a project's app.
Client secrets are returned once, when a client is created or its secret is replaced. See Sign in with for the flow your app runs.
GET /v1/orgs/:orgId/projects/:projectId/oauth-clients
The project's sign-in clients (never their secrets), with the issuer and its discovery URL.
Auth: user access token or platform agent key · Scope: projects:read
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
:projectId | Project id (prj_…). |
Response 200
{
issuer: string
discovery: string
clients: {
clientId: string
name: string
redirectUris: string[]
createdAt?: number
updatedAt?: number
lastUsedAt?: number
}[]
}Errors
| Status | Message |
|---|---|
404 | Project not found |
POST /v1/orgs/:orgId/projects/:projectId/oauth-clients
Registers a client; the secret is in this response only.
Auth: user access token or platform agent key · Scope: projects:write
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
:projectId | Project id (prj_…). |
Request body
| Field | Type | Required | Notes |
|---|---|---|---|
name | string | Yes | 1–64 characters; trimmed |
redirectUris | string[] | Yes | 1–10 items; each 1–2,048 characters, trimmed |
Response 201
{
client: {
clientId: string
name: string
redirectUris: string[]
createdAt?: number
updatedAt?: number
lastUsedAt?: number
}
clientSecret: string
}Errors
| Status | Message |
|---|---|
400 | A project can have up to 10 sign-in clients. |
404 | Project not found |
PATCH /v1/orgs/:orgId/projects/:projectId/oauth-clients/:clientId
Renames a sign-in client or replaces its redirect URIs.
Auth: user access token or platform agent key · Scope: projects:write
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
:projectId | Project id (prj_…). |
:clientId | Sign-in client id (cli_…). |
Request body
| Field | Type | Required | Notes |
|---|---|---|---|
name | string | No | 1–64 characters; trimmed |
redirectUris | string[] | No | 1–10 items; each 1–2,048 characters, trimmed |
Also checked: Nothing to update.
Response 200
{
client: {
clientId: string
name: string
redirectUris: string[]
createdAt?: number
updatedAt?: number
lastUsedAt?: number
}
}Errors
| Status | Message |
|---|---|
404 | Client not found |
POST /v1/orgs/:orgId/projects/:projectId/oauth-clients/:clientId/secret
Replaces the secret (the old one stops working at once); the new one is in this response only.
Auth: user access token or platform agent key · Scope: projects:write
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
:projectId | Project id (prj_…). |
:clientId | Sign-in client id (cli_…). |
Response 200
{
client: {
clientId: string
name: string
redirectUris: string[]
createdAt?: number
updatedAt?: number
lastUsedAt?: number
}
clientSecret: string
}Errors
| Status | Message |
|---|---|
404 | Client not found |
DELETE /v1/orgs/:orgId/projects/:projectId/oauth-clients/:clientId
Deletes the client: sign-ins and refreshes with it stop at once.
Auth: user access token or platform agent key · Scope: projects:write
| Path parameter | Description |
|---|---|
:orgId | Organization id (org_…). |
:projectId | Project id (prj_…). |
:clientId | Sign-in client id (cli_…). |
Response 204 with no body.
Errors
| Status | Message |
|---|---|
404 | Client not found |