Create M2M client
const url = 'https://api.example.com/oauth/clients';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"clientName":"example","description":"example","scopes":["products.read"],"expiresInDays":1}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.example.com/oauth/clients \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "clientName": "example", "description": "example", "scopes": [ "products.read" ], "expiresInDays": 1 }'Create a new M2M OAuth client with specified scopes. Admin only.
⚠️ IMPORTANT: The clientSecret is returned ONLY ONCE in this
response. Store it securely — it cannot be retrieved later.
Authorizations
Section titled “Authorizations ”Request Body required
Section titled “Request Body required ”object
Responses
Section titled “ Responses ”Client created successfully.
object
object
object
Web-channel slug this client is bound to, if any. Absent/null means unbound.
ONE-TIME DISPLAY — store securely; cannot be retrieved later.
Example
{ "scopes": [ "products.read" ], "status": "active"}Invalid request parameters or body.
object
Machine-readable code. Best-effort — the generic 500 path carries none.
Unique request ID for tracing.
object
Example
{ "error": "INVALID_PARAMETER", "message": "Client name must be at least 3 characters long."}Authentication required or failed.
object
Machine-readable code. Best-effort — the generic 500 path carries none.
Unique request ID for tracing.
object
Example
{ "error": "UNAUTHORIZED", "message": "Valid authentication token required."}Insufficient permissions (missing scope or Admin role).
object
Machine-readable code. Best-effort — the generic 500 path carries none.
Unique request ID for tracing.
object
Example
{ "error": "FORBIDDEN", "message": "Insufficient scope for this operation."}Internal server error.
object
Machine-readable code. Best-effort — the generic 500 path carries none.
Unique request ID for tracing.
object
Example
{ "error": "INTERNAL_ERROR", "message": "An unexpected error occurred"}