Skip to content

Update M2M client

PUT
/oauth/clients/{clientId}
curl --request PUT \
--url https://api.example.com/oauth/clients/example \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "clientName": "example", "description": "example", "scopes": [ "products.read" ], "channel": "example" }'

Rename, rescope, or rebind an M2M OAuth client. Admin only. All fields are optional but at least one must be provided. A revoked client cannot be updated — create a new client instead.

Updating scopes re-issues the Cognito client’s allowed OAuth scopes (existing access tokens keep their original scopes until they expire). channel binds the client to a web channel by slug (see GET /company-settings/web-channels for the registry); passing channel: null explicitly unbinds it.

clientId
required
string
/^[a-zA-Z0-9]{26}$/

The unique client ID (26 alphanumeric characters).

Media type application/json

All fields optional, but at least one must be provided.

object
clientName
string
>= 3 characters <= 100 characters /^[a-zA-Z0-9\s\-_]+$/
description
string
<= 500 characters
scopes
Array<string>
>= 1 items
Allowed values: products.read products.write brands.read brands.write
channel

Kebab-case web-channel slug to bind this client to, or null to unbind it. Must match a slug in the web channels registry.

string
nullable

Client updated successfully.

Media type application/json
object
clientId
string
/^[a-zA-Z0-9]{26}$/
clientName
string
>= 3 characters <= 100 characters
description
string
<= 500 characters
scopes
Array<string>
Allowed values: products.read products.write brands.read brands.write
status
string
Allowed values: active revoked
createdAt
string format: date-time
createdBy
object
userId
string
userName
string
expiresAt
string format: date-time
nullable
lastUsedAt
string format: date-time
nullable
usageCount
integer
revokedAt
string format: date-time
nullable
revokedBy
object
userId
string
userName
string
channel

Web-channel slug this client is bound to, if any. Absent/null means unbound.

string
nullable
Example
{
"scopes": [
"products.read"
],
"status": "active"
}

Invalid request parameters or body.

Media type application/json
object
error

Machine-readable code. Best-effort — the generic 500 path carries none.

string
message
required
string
requestId

Unique request ID for tracing.

string
nullable
details
object
key
additional properties
any
Example
{
"error": "INVALID_PARAMETER",
"message": "Client name must be at least 3 characters long."
}

Authentication required or failed.

Media type application/json
object
error

Machine-readable code. Best-effort — the generic 500 path carries none.

string
message
required
string
requestId

Unique request ID for tracing.

string
nullable
details
object
key
additional properties
any
Example
{
"error": "UNAUTHORIZED",
"message": "Valid authentication token required."
}

Insufficient permissions (missing scope or Admin role).

Media type application/json
object
error

Machine-readable code. Best-effort — the generic 500 path carries none.

string
message
required
string
requestId

Unique request ID for tracing.

string
nullable
details
object
key
additional properties
any
Example
{
"error": "FORBIDDEN",
"message": "Insufficient scope for this operation."
}

Resource not found.

Media type application/json
object
error

Machine-readable code. Best-effort — the generic 500 path carries none.

string
message
required
string
requestId

Unique request ID for tracing.

string
nullable
details
object
key
additional properties
any
Example
{
"error": "NOT_FOUND",
"message": "Product not found"
}

Internal server error.

Media type application/json
object
error

Machine-readable code. Best-effort — the generic 500 path carries none.

string
message
required
string
requestId

Unique request ID for tracing.

string
nullable
details
object
key
additional properties
any
Example
{
"error": "INTERNAL_ERROR",
"message": "An unexpected error occurred"
}