Skip to content

List M2M clients

GET
/oauth/clients
curl --request GET \
--url 'https://api.example.com/oauth/clients?status=active' \
--header 'Authorization: Bearer <token>'

Retrieve all M2M OAuth clients. Admin only — requires a Cognito ID token with Admin group membership (not an M2M client-credentials token).

status
string
default: active
Allowed values: active revoked all

Filter by client status.

Successfully retrieved client list.

Media type application/json
object
clients
Array<object>
object
clientId
string
/^[a-zA-Z0-9]{26}$/
clientName
string
>= 3 characters <= 100 characters
description
string
<= 500 characters
scopes
Array<string>
Allowed values: products.read products.write brands.read brands.write
status
string
Allowed values: active revoked
createdAt
string format: date-time
createdBy
object
userId
string
userName
string
expiresAt
string format: date-time
nullable
lastUsedAt
string format: date-time
nullable
usageCount
integer
revokedAt
string format: date-time
nullable
revokedBy
object
userId
string
userName
string
channel

Web-channel slug this client is bound to, if any. Absent/null means unbound.

string
nullable
count
integer
Example
{
"clients": [
{
"scopes": [
"products.read"
],
"status": "active"
}
]
}

Authentication required or failed.

Media type application/json
object
error

Machine-readable code. Best-effort — the generic 500 path carries none.

string
message
required
string
requestId

Unique request ID for tracing.

string
nullable
details
object
key
additional properties
any
Example
{
"error": "UNAUTHORIZED",
"message": "Valid authentication token required."
}

Insufficient permissions (missing scope or Admin role).

Media type application/json
object
error

Machine-readable code. Best-effort — the generic 500 path carries none.

string
message
required
string
requestId

Unique request ID for tracing.

string
nullable
details
object
key
additional properties
any
Example
{
"error": "FORBIDDEN",
"message": "Insufficient scope for this operation."
}