Register a confidential OAuth client (client_credentials)

​

Creates an OAuth client for autonomous machine-to-machine access. The client exchanges its client_secret for a short-lived access token at POST /v1/token (grant_type client_credentials). Restrict what it may request with scopes; omit for a full-access client. A scoped key can only create a client no broader than itself. The secret is shown only in this response.

Body·
application/json

Optional client metadata and allowed scopes.

  • name
    Type: string
    max length:  
    100

    Optional human-readable label.

  • scopes
    Type: array string[] 1…

    Scopes the client may request (subset of your own). Omit for a full-access client.

Responses
  • application/json
  • application/problem+json
  • application/problem+json
  • application/problem+json
Request Example for post/v1/clients
ffforms account create-client
{
  "id": "cli_8Fh2Lm4Qp9",
  "name": "ci-runner",
  "scopes": [
    "submissions:read"
  ],
  "createdAt": "string",
  "lastUsedAt": null,
  "revokedAt": null,
  "secret": "ffc_Qp9xYz0AbCdEf8Fh2Lm4"
}