Skip to content

Create M2M client

POST
/oauth/clients
curl --request POST \
--url https://api.example.com/oauth/clients \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "clientName": "example", "description": "example", "scopes": [ "products.read" ], "expiresInDays": 1 }'

Create a new M2M OAuth client with specified scopes. Admin only.

⚠️ IMPORTANT: The clientSecret is returned ONLY ONCE in this response. Store it securely — it cannot be retrieved later.

Media type application/json
object
clientName
required
string
>= 3 characters <= 100 characters /^[a-zA-Z0-9\s\-_]+$/
description
string
<= 500 characters
scopes
required
Array<string>
>= 1 items
Allowed values: products.read products.write brands.read brands.write
expiresInDays
integer
>= 1 <= 365

Client created successfully.

Media type application/json
object
clientId
string
/^[a-zA-Z0-9]{26}$/
clientName
string
>= 3 characters <= 100 characters
description
string
<= 500 characters
scopes
Array<string>
Allowed values: products.read products.write brands.read brands.write
status
string
Allowed values: active revoked
createdAt
string format: date-time
createdBy
object
userId
string
userName
string
expiresAt
string format: date-time
nullable
lastUsedAt
string format: date-time
nullable
usageCount
integer
revokedAt
string format: date-time
nullable
revokedBy
object
userId
string
userName
string
channel

Web-channel slug this client is bound to, if any. Absent/null means unbound.

string
nullable
clientSecret
required

ONE-TIME DISPLAY — store securely; cannot be retrieved later.

string
tokenEndpoint
required
string format: uri
warning
required
string
Example
{
"scopes": [
"products.read"
],
"status": "active"
}

Invalid request parameters or body.

Media type application/json
object
error

Machine-readable code. Best-effort — the generic 500 path carries none.

string
message
required
string
requestId

Unique request ID for tracing.

string
nullable
details
object
key
additional properties
any
Example
{
"error": "INVALID_PARAMETER",
"message": "Client name must be at least 3 characters long."
}

Authentication required or failed.

Media type application/json
object
error

Machine-readable code. Best-effort — the generic 500 path carries none.

string
message
required
string
requestId

Unique request ID for tracing.

string
nullable
details
object
key
additional properties
any
Example
{
"error": "UNAUTHORIZED",
"message": "Valid authentication token required."
}

Insufficient permissions (missing scope or Admin role).

Media type application/json
object
error

Machine-readable code. Best-effort — the generic 500 path carries none.

string
message
required
string
requestId

Unique request ID for tracing.

string
nullable
details
object
key
additional properties
any
Example
{
"error": "FORBIDDEN",
"message": "Insufficient scope for this operation."
}

Internal server error.

Media type application/json
object
error

Machine-readable code. Best-effort — the generic 500 path carries none.

string
message
required
string
requestId

Unique request ID for tracing.

string
nullable
details
object
key
additional properties
any
Example
{
"error": "INTERNAL_ERROR",
"message": "An unexpected error occurred"
}