Update M2M client
const url = 'https://api.example.com/oauth/clients/example';const options = { method: 'PUT', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"clientName":"example","description":"example","scopes":["products.read"],"channel":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request PUT \ --url https://api.example.com/oauth/clients/example \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "clientName": "example", "description": "example", "scopes": [ "products.read" ], "channel": "example" }'Rename, rescope, or rebind an M2M OAuth client. Admin only. All fields are optional but at least one must be provided. A revoked client cannot be updated — create a new client instead.
Updating scopes re-issues the Cognito client’s allowed OAuth scopes
(existing access tokens keep their original scopes until they expire).
channel binds the client to a web channel by slug (see
GET /company-settings/web-channels for the registry); passing
channel: null explicitly unbinds it.
Authorizations
Section titled “Authorizations ”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters ”The unique client ID (26 alphanumeric characters).
Request Body required
Section titled “Request Body required ”All fields optional, but at least one must be provided.
object
Kebab-case web-channel slug to bind this client to, or null to
unbind it. Must match a slug in the web channels registry.
Responses
Section titled “ Responses ”Client updated successfully.
object
object
object
Web-channel slug this client is bound to, if any. Absent/null means unbound.
Example
{ "scopes": [ "products.read" ], "status": "active"}Invalid request parameters or body.
object
Machine-readable code. Best-effort — the generic 500 path carries none.
Unique request ID for tracing.
object
Example
{ "error": "INVALID_PARAMETER", "message": "Client name must be at least 3 characters long."}Authentication required or failed.
object
Machine-readable code. Best-effort — the generic 500 path carries none.
Unique request ID for tracing.
object
Example
{ "error": "UNAUTHORIZED", "message": "Valid authentication token required."}Insufficient permissions (missing scope or Admin role).
object
Machine-readable code. Best-effort — the generic 500 path carries none.
Unique request ID for tracing.
object
Example
{ "error": "FORBIDDEN", "message": "Insufficient scope for this operation."}Resource not found.
object
Machine-readable code. Best-effort — the generic 500 path carries none.
Unique request ID for tracing.
object
Example
{ "error": "NOT_FOUND", "message": "Product not found"}Internal server error.
object
Machine-readable code. Best-effort — the generic 500 path carries none.
Unique request ID for tracing.
object
Example
{ "error": "INTERNAL_ERROR", "message": "An unexpected error occurred"}