Skip to content

Get secret rotation instructions

POST
/oauth/clients/{clientId}/rotate-secret
curl --request POST \
--url https://api.example.com/oauth/clients/example/rotate-secret \
--header 'Authorization: Bearer <token>'

Get instructions for rotating client credentials. Admin only. Due to Cognito limitations, secret rotation requires AWS Console access; this endpoint returns step-by-step instructions.

clientId
required
string
/^[a-zA-Z0-9]{26}$/

Rotation instructions.

Media type application/json
object
message
string
instructions
Array<string>
consoleUrl
string format: uri
Example generated
{
"message": "example",
"instructions": [
"example"
],
"consoleUrl": "https://example.com"
}

Authentication required or failed.

Media type application/json
object
error

Machine-readable code. Best-effort — the generic 500 path carries none.

string
message
required
string
requestId

Unique request ID for tracing.

string
nullable
details
object
key
additional properties
any
Example
{
"error": "UNAUTHORIZED",
"message": "Valid authentication token required."
}

Insufficient permissions (missing scope or Admin role).

Media type application/json
object
error

Machine-readable code. Best-effort — the generic 500 path carries none.

string
message
required
string
requestId

Unique request ID for tracing.

string
nullable
details
object
key
additional properties
any
Example
{
"error": "FORBIDDEN",
"message": "Insufficient scope for this operation."
}