Register an OAuth client
Register a new OAuth 2.1 client. Polymorphic across org (org-scoped, dashboard users) and space (space-scoped, end-users) levels. The plaintext clientSecret is returned exactly once. A referencedSpaceId naming a PERSONAL space is refused: a personal space belongs to one member and is removed when they leave, so a client pinned to it would outlive the space its end-users signed in to.
/api/oauth/clientsCookie session from Better Auth. Requires X-Org-Id header for org-scoped routes.
In: cookie
Header Parameters
Organization ID. Required for cookie auth. Not needed for API key auth (org resolved from key).
uuidUnique key for idempotent requests (max 255 chars). Prevents duplicate resource creation on retries. Cached for 24 hours, scoped to the organization and space: a repeat with the same method, URL and body replays the original response with Idempotent-Replayed: true, the same key with a different method, URL or body is 422 idempotency_conflict, and a concurrent duplicate is 409 idempotency_in_progress. Current permissions are checked again; run responses are projected using current visibility. This operation honours the header because it declares this parameter — operations that do not declare it refuse the header with 400 idempotency_not_supported rather than silently ignoring it (see the “Idempotency” section of the API description).
length <= 255Request Body
application/json
curl -X POST "https://your-instance/api/oauth/clients" \ -H "Content-Type: application/json" \ -d '{ "level": "org", "name": "string", "redirectUris": [ "http://example.com" ], "referencedOrgId": "string" }'{
"id": "string",
"clientId": "string",
"name": "string",
"level": "instance",
"referencedOrgId": "string",
"referencedSpaceId": "string",
"redirectUris": [
"http://example.com"
],
"postLogoutRedirectUris": [
"http://example.com"
],
"scopes": [
"string"
],
"disabled": true,
"isFirstParty": true,
"allowSignup": true,
"signupRole": "guest",
"signupSpaceAssignments": [
{
"spaceId": "string",
"preset_role": "admin",
"custom_role_id": "string"
}
],
"createdAt": "string",
"updatedAt": "string",
"clientSecret": "string"
}{
"type": "https://docs.appstrate.dev/errors/validation-failed",
"title": "Validation Failed",
"status": 400,
"detail": "name: Invalid input: expected string, received undefined (+2 more)",
"code": "validation_failed",
"request_id": "req_abc123",
"errors": [
{
"field": "name",
"code": "required",
"message": "Invalid input: expected string, received undefined"
},
{
"field": "email",
"code": "invalid_format",
"message": "Invalid email address"
},
{
"field": "age",
"code": "invalid_type",
"message": "Invalid input: expected number, received string"
}
]
}{
"type": "https://docs.appstrate.dev/errors/forbidden",
"title": "Forbidden",
"status": 403,
"detail": "Insufficient permissions",
"code": "forbidden",
"request_id": "req_abc123"
}{
"type": "https://docs.appstrate.dev/errors/not-found",
"title": "Not Found",
"status": 404,
"detail": "Resource not found",
"code": "not_found",
"request_id": "req_abc123"
}{
"type": "http://example.com",
"title": "string",
"status": 0,
"detail": "string",
"instance": "string",
"code": "string",
"request_id": "string",
"param": "string",
"retry_after": 0,
"errors": [
{
"field": "string",
"code": "string",
"message": "string",
"title": "string",
"candidate_connections": [
{
"id": "string",
"label": "string",
"account_id": "string",
"owned_by_actor": true,
"needs_reconnection": true
}
],
"connection_id": "string",
"missing_scopes": [
"string"
],
"owned_by_actor": true,
"required_scopes": [
"string"
],
"auth_key": "string",
"required_auth_key": "string",
"available_auth_keys": [
"string"
],
"connect_url": "http://example.com",
"expiresAt": "2019-08-24T14:15:22Z",
"packageId": "string"
}
]
}{
"type": "https://docs.appstrate.dev/errors/rate-limited",
"title": "Rate Limited",
"status": 429,
"detail": "Too many requests. Please try again shortly.",
"code": "rate_limited",
"request_id": "req_abc123",
"retry_after": 30
}