Rotate client secret

POST/api/oauth/clients/{clientId}/rotate

Authorization

better-auth.session_token<token>

Cookie session from Better Auth. Requires X-Org-Id header for org-scoped routes.

In: cookie

Path Parameters

clientId*string

Header Parameters

X-Org-Id?string

Organization ID. Required for cookie auth. Not needed for API key auth (org resolved from key).

Formatuuid
curl -X POST "https://your-instance/api/oauth/clients/string/rotate"
{
  "id": "string",
  "clientId": "string",
  "name": "string",
  "level": "instance",
  "referencedOrgId": "string",
  "referencedSpaceId": "string",
  "redirectUris": [
    "http://example.com"
  ],
  "postLogoutRedirectUris": [
    "http://example.com"
  ],
  "scopes": [
    "string"
  ],
  "disabled": true,
  "isFirstParty": true,
  "allowSignup": true,
  "signupRole": "guest",
  "signupSpaceAssignments": [
    {
      "spaceId": "string",
      "preset_role": "admin",
      "custom_role_id": "string"
    }
  ],
  "createdAt": "string",
  "updatedAt": "string",
  "clientSecret": "string"
}
{
  "type": "https://docs.appstrate.dev/errors/forbidden",
  "title": "Forbidden",
  "status": 403,
  "detail": "Insufficient permissions",
  "code": "forbidden",
  "request_id": "req_abc123"
}
{
  "type": "https://docs.appstrate.dev/errors/not-found",
  "title": "Not Found",
  "status": 404,
  "detail": "Resource not found",
  "code": "not_found",
  "request_id": "req_abc123"
}
{
  "type": "https://docs.appstrate.dev/errors/rate-limited",
  "title": "Rate Limited",
  "status": 429,
  "detail": "Too many requests. Please try again shortly.",
  "code": "rate_limited",
  "request_id": "req_abc123",
  "retry_after": 30
}