OAuth 2.0 Dynamic Client Registration
Service for OAuth 2.0 Dynamic Client Registration Protocol that can be used for the most common use cases.
Dynamic Client Registration uses the following endpoint:
/<loginapp-uri>/rest/public/tech-client-registration/oauth2/<as-identifier>/register
clientIdGenerator) clientSecretGenerator) In addition, a "Token Endpoint Auth Method Processor" is required to determine the authentication method.
additionalProcessors) returnTechClientId) If enabled, the technical client ID is included in the registration response.
The technical client ID is not identical to the client ID that is also sent with the response. The technical client ID can be used to further administer the newly created client, e.g. via Adminapp REST API.
authorizationCodeGrant) If enabled, Authorization Code Grant is supported.
The registered client will be enabled to perform the authorization code grant in any of the following cases:
- If the "grant_types" requested by the client include "authorization_code". In this case a "redirect_uri" must be present.
- If the requested "response_types" include "code". In this case a "redirect_uri" must be present.
- If the client requests no "grant_types" and no "response_types", but supplies a "redirect_uri".
If this property is disabled, authorization code grant is never enabled for the client.
Note: this is not enforced at runtime. Whether the resulting client can actually use this grant is governed solely by the Authorization Server's own grant configuration, which applies identically to every client regardless of DCR registration.
implicitGrant) If enabled, Implicit Grant is supported.
The registered client will be enabled to perform implicit grant in any of the following cases:
- If the "grant_types" requested by the client include "implicit". In this case, a "redirect_uri" must be present.
- If the requested "response_types" include "token". In this case, a "redirect_uri" must also be present.
- If the client requests no "grant_types" and no "response_types", but supplies a "redirect_uri".
If this property is disabled, implicit grant is never enabled for the client.
Note: this is not enforced at runtime. Whether the resulting client can actually use this grant is governed solely by the Authorization Server's own grant configuration, which applies identically to every client regardless of DCR registration.
clientCredentialsGrant) If enabled, Client Credentials Grant is supported.
The registered client will be enabled to perform client credentials grant in any of the following cases:
- If the "grant_types" requested by the client include "client_credentials".
- If the client specifies no "grant_types" in the registration request.
If this property is disabled, client credentials grant is never enabled for the client.
Note: this is not enforced at runtime. Whether the resulting client can actually use this grant is governed solely by the Authorization Server's own grant configuration, which applies identically to every client regardless of DCR registration.
accessTokenRefresh) If enabled, refreshing an access token is supported.
The registered client will be enabled to refresh access tokens in any of the following cases:
- If the "grant_types" requested by the client include "refresh_token".
- If the client specifies no "grant_types" in the registration request.
If this property is disabled, refreshing of access tokens is never enabled for the client.
Note: this is not enforced at runtime. Whether the resulting client can actually use this grant is governed solely by the Authorization Server's own grant configuration, which applies identically to every client regardless of DCR registration.
type: DefaultOAuth2ClientRegistration
id: DefaultOAuth2ClientRegistration-xxxxxx
displayName:
comment:
properties:
accessTokenRefresh: true
additionalProcessors:
authorizationCodeGrant: true
clientCredentialsGrant: false
clientIdGenerator:
clientSecretGenerator:
implicitGrant: false
returnTechClientId: false