Skip to main content
POST
Register an OAuth client from the dashboard

Authorizations

Authorization
string
header
required

JWT token authentication

Headers

NexSpace-Version
string

Pin the request to a dated API version (e.g. 2026-05-10). Applied by app-level middleware to every /api route (server/routes/index.ts → apiVersionMiddleware), which echoes the resolved value back in the NexSpace-Version response header. Omit to get the latest version. Discover the catalog at GET /.well-known/api-versions.

Pattern: ^\d{4}-\d{2}-\d{2}$
Idempotency-Key
string

Replay guard for write requests. Applied by app-level middleware to every /api route (server/routes/index.ts → idempotencyMiddleware), which only acts on POST/PUT/PATCH — GET, DELETE and OPTIONS ignore the header. Re-sending the same key with an identical body within 24 hours replays the original response; the same key with a different body returns 409.

Maximum string length: 255

Body

application/json
clientName
string
required
Required string length: 1 - 120
redirectUris
string<uri>[]
required
Minimum array length: 1
scopes
string[]
required

Requested scopes. Filtered to the headless catalog (shared/headless-scopes.ts) before storage.

Minimum array length: 1
isPublic
boolean
default:true

true (default) mints a public PKCE client with no secret. false mints a confidential client and returns a one-time clientSecret.

clientUri
string<uri>
logoUri
string<uri>

Response

Client registered

A registered OAuth client, as returned by the dashboard-managed /api/oauth-clients endpoints. The client secret is never included — only its one-time value on creation carries it.

id
integer

Row id, used in DELETE /api/oauth-clients/{id}.

clientId
string

Public client identifier (cli_…).

clientName
string
redirectUris
string<uri>[]
isPublic
boolean

Public (PKCE, no secret) vs confidential (secret-bearing).

scopes
string[]

Granted scopes, already filtered to the headless catalog.

metadata
object | null

client_uri / logo_uri as submitted.

registeredById
integer | null

The operator who registered it; null for RFC 7591 self-registration.

registeredByName
string | null
registrationSource
enum<string>

dashboard when registeredById is set (created via POST /api/oauth-clients), dynamic when the client self-registered via POST /oauth/register.

Available options:
dashboard,
dynamic
createdAt
string<date-time> | null
updatedAt
string<date-time> | null
clientSecret
string

Confidential clients only. Shown exactly once — it is stored hashed and can never be read back.