Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

Roll secret on an OAUTH client

Issues a new client secret, returned once; the old one verifies until `grace_period` ends.

This method is not served on the public API. api.sylphx.com does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

Issues a new client secret, returned once; the old one verifies until grace_period ends.

  • Path POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/oauth_clients/oauth-client:rollSecret
  • Scope auth:write
  • Effect write — a successful call changes state.
  • Collection oauth_clients
  • Validate-only validate_only=true runs every check and writes nothing

#Request

FieldTypeWhat it is
namestringThe name of the OAuth client. Required.
grace_perioddurationHow long the old secret keeps verifying; default 24h.
etagstringAct only if the current etag matches.
validate_onlyboolValidate without writing anything.

#Response

FieldTypeWhat it is
namestringorgs/{org}/projects/{project}/envs/{env}/oauth_clients/{oauth_client}.
uidstringocl_<cell><ulid>; never reused. Output only.
metaResourceMetaResource metadata.
specOauthClientSpecDesired state. Required.
statusOauthClientStatusObserved state. Output only.

#ResourceMeta

FieldTypeWhat it is
generationint64Increases by one on every change to spec. Output only.
etagstringStrong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as If-Match or etag to make Update and Delete conditional; a mismatch fails with ABORTED / 409 ETAG_MISMATCH. Output only.
create_timetimestampWhen the Resource was created. Output only.
update_timetimestampWhen the Resource last changed. Output only.
delete_timetimestampSet while the Resource is being deleted. Output only.
labelsmap<string, string>Caller-writable, indexed labels (AIP-122 label rules).
annotationsmap<string, string>Caller-writable, unindexed annotations.
display_namestringCaller-writable human-readable name.
creatorstringThe principal that created the Resource. Output only.

#OauthClientSpec

FieldTypeWhat it is
client_typeOauthClientTypeConfidential or public. Required. One of confidential, public.
token_endpoint_auth_methodTokenEndpointAuthMethodHow the client authenticates at the token endpoint. Required. One of none, client_secret_basic, private_key_jwt.
redirect_urisstring[]Exact redirect URIs.
grant_typesGrantType[]Allowed grants. Required. One of authorization_code, refresh_token, device_code, client_credentials.
scopesstring[]Scopes the client may request.
jwks_uristringThe client's JWKS URI, for private_key_jwt.
dpop_requiredboolRequire DPoP-bound tokens (RFC 9449).
access_token_ttldurationAccess token lifetime; default 1h.
refresh_token_ttldurationRefresh token lifetime; default 30d.

#OauthClientStatus

FieldTypeWhat it is
observed_generationint64The generation this status was computed from. Output only.
conditionsCondition[]Ready, Reconciling, Stalled. Output only.
client_idstringThe OAuth client_id. Output only.
client_secretstringThe client secret, for client_secret_basic; set only in the responses of Create and RollSecret. Output only. Never returned again.
client_secret_last4stringThe last four characters of the client secret. Output only.

#Condition

FieldTypeWhat it is
typestringThe condition type, for example Ready.
statusConditionStatusWhether the condition holds. One of true, false, unknown.
observed_generationint64The generation this observation was made against.
reasonstringA machine-readable UpperCamelCase reason.
messagestringA customer-safe human-readable message.
severitySeverityHow severe a FALSE condition is. One of info, warning, error.
transition_timetimestampWhen status last changed.

#Errors

Every error arrives in the body Errors describes.

#Examples

curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/oauth_clients/oauth-client:rollSecret" \
  -H "Authorization: Bearer $SYLPHX_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{}'