Menu
Platform
AI
App store purchases
Database
Flags
Jobs and cron
Localization
Monitoring
Notifications
Payments
Queues
Sandboxes
Webhooks
Getting Started
Authentication
KV Store
Deploy & Infrastructure
Reference
Roll secret on an OAUTH client
Issues a new client secret, returned once; the old one verifies until `grace_period` ends.
This method is not served on the public API.
api.sylphx.comdoes not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.
Issues a new client secret, returned once; the old one verifies until grace_period ends.
- Path
POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/oauth_clients/oauth-client:rollSecret - Scope
auth:write - Effect
write— a successful call changes state. - Collection oauth_clients
- Validate-only
validate_only=trueruns every check and writes nothing
#Request
| Field | Type | What it is |
|---|---|---|
name | string | The name of the OAuth client. Required. |
grace_period | duration | How long the old secret keeps verifying; default 24h. |
etag | string | Act only if the current etag matches. |
validate_only | bool | Validate without writing anything. |
#Response
| Field | Type | What it is |
|---|---|---|
name | string | orgs/{org}/projects/{project}/envs/{env}/oauth_clients/{oauth_client}. |
uid | string | ocl_<cell><ulid>; never reused. Output only. |
meta | ResourceMeta | Resource metadata. |
spec | OauthClientSpec | Desired state. Required. |
status | OauthClientStatus | Observed state. Output only. |
#ResourceMeta
| Field | Type | What it is |
|---|---|---|
generation | int64 | Increases by one on every change to spec. Output only. |
etag | string | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as If-Match or etag to make Update and Delete conditional; a mismatch fails with ABORTED / 409 ETAG_MISMATCH. Output only. |
create_time | timestamp | When the Resource was created. Output only. |
update_time | timestamp | When the Resource last changed. Output only. |
delete_time | timestamp | Set while the Resource is being deleted. Output only. |
labels | map<string, string> | Caller-writable, indexed labels (AIP-122 label rules). |
annotations | map<string, string> | Caller-writable, unindexed annotations. |
display_name | string | Caller-writable human-readable name. |
creator | string | The principal that created the Resource. Output only. |
#OauthClientSpec
| Field | Type | What it is |
|---|---|---|
client_type | OauthClientType | Confidential or public. Required. One of confidential, public. |
token_endpoint_auth_method | TokenEndpointAuthMethod | How the client authenticates at the token endpoint. Required. One of none, client_secret_basic, private_key_jwt. |
redirect_uris | string[] | Exact redirect URIs. |
grant_types | GrantType[] | Allowed grants. Required. One of authorization_code, refresh_token, device_code, client_credentials. |
scopes | string[] | Scopes the client may request. |
jwks_uri | string | The client's JWKS URI, for private_key_jwt. |
dpop_required | bool | Require DPoP-bound tokens (RFC 9449). |
access_token_ttl | duration | Access token lifetime; default 1h. |
refresh_token_ttl | duration | Refresh token lifetime; default 30d. |
#OauthClientStatus
| Field | Type | What it is |
|---|---|---|
observed_generation | int64 | The generation this status was computed from. Output only. |
conditions | Condition[] | Ready, Reconciling, Stalled. Output only. |
client_id | string | The OAuth client_id. Output only. |
client_secret | string | The client secret, for client_secret_basic; set only in the responses of Create and RollSecret. Output only. Never returned again. |
client_secret_last4 | string | The last four characters of the client secret. Output only. |
#Condition
| Field | Type | What it is |
|---|---|---|
type | string | The condition type, for example Ready. |
status | ConditionStatus | Whether the condition holds. One of true, false, unknown. |
observed_generation | int64 | The generation this observation was made against. |
reason | string | A machine-readable UpperCamelCase reason. |
message | string | A customer-safe human-readable message. |
severity | Severity | How severe a FALSE condition is. One of info, warning, error. |
transition_time | timestamp | When status last changed. |
#Errors
UNAUTHENTICATED— No valid key or token was presented.PERMISSION_DENIED— The key lacks the method's permission.RESOURCE_NOT_FOUND— The named Resource does not exist or is not visible.INVALID_FIELD— A field failed validation.INVALID_STATE— The Resource is in a state that forbids the call.IDEMPOTENCY_KEY_REUSED— An Idempotency-Key was reused with another body.IDEMPOTENCY_IN_PROGRESS— The first call with this Idempotency-Key is still running.ETAG_MISMATCH— The etag sent does not match the Resource's current etag.
Every error arrives in the body Errors describes.
#Examples
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/oauth_clients/oauth-client:rollSecret" \
-H "Authorization: Bearer $SYLPHX_API_KEY" \
-H "Content-Type: application/json" \
-d '{}'