The identity and technical contract details declared by the specification.
ClientMyOrganizationResponseConfiguration
object
Configuration related to the My Organization Configuration for the client.
4 properties
2 required
ClientOrganizationRequireBehaviorEnum
string
Defines how to proceed during an authentication transaction when client.organizationusage: 'require'. Can be noprompt (default), preloginprompt or postloginpro…
ClientAsyncApprovalNotificationsChannelsAPIPatchConfiguration
arraynull
Array of notification channels for contacting the user when their approval is required. Valid values are guardian-push, email.
ClientAuthenticationMethodPrivateKeyJWTCredentials
array
A list of unique and previously created credential IDs enabled on the client for Private Key JWT authentication.
RotateClientSecretResponseContent
object
61 properties
ConnectionOptions
object
In order to return options in the response, the read:connectionsoptions scope must be present
CreateClientAuthenticationMethodSelfSignedTLSClientAuthCredentials
array
Fully defined credentials that will be enabled on the client for mTLS authentication utilizing self-signed certificate.
ClientRefreshTokenConfiguration
objectnull
Refresh token configuration
8 properties
2 required
ClientAddonLayer
object
Layer addon configuration.
5 properties
3 required
ClientCredentialAlgorithmEnum
string
Algorithm which will be used with the credential. Supported algorithms: RS256,RS384,PS256
PreviewCimdMetadataResponseContent
object
4 properties
ListClientsPaginatedResponseContent
object
2 properties
CreateClientResponseContent
object
61 properties
ClientAddonSharePoint
object
SharePoint SSO configuration.
2 properties
ClientAuthenticationMethodSelfSignedTLSClientAuth
object
Defines selfsignedtlsclientauth client authentication method. If the property is defined, the client is configured to use mTLS authentication method utilizing…
1 property
1 required
ClientOIDCBackchannelLogoutInitiators
object
Configuration for OIDC backchannel logout initiators
2 properties
CimdMappedClientAuthenticationMethods
object
Client authentication methods derived from the JWKS document
1 property
PostClientCredentialRequestContent
object
8 properties
1 required
ClientComplianceLevelEnum
stringnull
Defines the compliance level for this client, which may restrict it's capabilities
ClientTokenEndpointAuthMethodOrNullEnum
stringnull
Defines the requested authentication method for the token endpoint. Can be none (public client without a client secret), clientsecretpost (client uses HTTP POS…
ClientMobile
object
Additional configuration for native mobile apps.
2 properties
TokenQuota
object
1 property
1 required
ClientMyOrganizationPatchConfiguration
objectnull
Configuration related to the My Organization Configuration for the client.
4 properties
2 required
ClientDefaultOrganization
objectnull
Defines the default Organization ID and flows
2 properties
2 required
ClientMyOrganizationConfigurationAllowedStrategiesEnum
string
The allowed connection strategy values for the My Organization Configuration.
ClientAuthenticationMethodSelfSignedTLSClientAuthCredentials
array
A list of unique and previously created credential IDs enabled on the client for mTLS authentication utilizing self-signed certificate.
NativeSocialLoginApple
object
Native Social Login support for the Apple connection
1 property
ClientSessionTransferDeviceBindingEnum
string
Indicates whether device binding security should be enforced for the app. If set to 'ip', the app will enforce device binding by IP, meaning that consumption o…
ClientRedirectionPolicyEnum
string
Controls whether Auth0 redirects users to the application's callback URL on authentication errors or in email verification flows. openredirectprotection shows…
ClientEncryptionKey
objectnull
Encryption used for WsFed responses with this client.
3 properties
ClientAddonMSCRM
object
Microsoft Dynamics CRM SSO configuration.
1 property
1 required
NativeSocialLoginGoogle
object
Native Social Login support for the google-oauth2 connection
1 property
PublicKeyCredential
object
7 properties
2 required
RefreshTokenExpirationTypeEnum
string
Refresh token expiration types, one of: expiring, non-expiring
ClientSigningKey
object
3 properties
ClientMyOrganizationDeletionBehaviorEnum
string
The deletion behavior for this client.
ClientCreateAuthenticationMethod
object
Defines client authentication methods.
3 properties
NativeSocialLoginFacebook
object
Native Social Login support for the Facebook connection
1 property
SigningAlgorithmEnum
string
Algorithm used to sign JWTs. Can be HS256 (default) or RS256. PS256 available via addon.
ClientRefreshTokenPolicy
object
2 properties
2 required
ClientAddonSpringCM
object
SpringCM SSO configuration.
1 property
ClientOIDCBackchannelLogoutInitiatorsEnum
string
The selectedinitiators property contains the list of initiators to be enabled for the given application.
PreviewCimdMetadataRequestContent
object
1 property
1 required
ClientAuthenticationMethodPrivateKeyJWT
object
Defines privatekeyjwt client authentication method. If this property is defined, the client is enabled to use the Private Key JWT authentication method.
1 property
1 required
ClientAddonCloudBees
object
CloudBees SSO indicator (no configuration settings needed for CloudBees SSO).
ClientExternalMetadataTypeEnum
string
Indicates the type of external metadata used to register the client. This field is omitted for regular clients. The value cimd identifies clients registered vi…
ClientCredential
object
10 properties
ClientJwtConfiguration
object
Configuration related to JWTs for the client.
4 properties
ClientAuthenticationMethodTLSClientAuthCredentials
array
A list of unique and previously created credential IDs enabled on the client for CA-based mTLS authentication.
RefreshTokenRotationTypeEnum
string
Refresh token rotation types, one of: rotating, non-rotating
GetClientResponseContent
object
61 properties
ClientOrganizationUsagePatchEnum
stringnull
Defines how to proceed during an authentication transaction with regards an organization. Can be deny (default), allow or require.
UpdateClientRequestContent
object
53 properties
ListClientConnectionsResponseContent
object
2 properties
1 required
ConnectionStrategyEnum
string
ClientAddonZendesk
object
Zendesk SSO configuration.
1 property
LinkedClientConfiguration
object
Configuration for linked clients in the OIN Express Configuration feature.
1 property
1 required
TokenQuotaClientCredentials
object
The token quota configuration
3 properties
ClientSessionTransferConfiguration
objectnull
Native to Web SSO Configuration
7 properties
ClientAuthenticationMethod
objectnull
Defines client authentication methods.
3 properties
ClientAddonSAMLMapping
object
ClientAddonAzureBlob
object
Azure Blob Storage addon configuration.
13 properties
ClientSessionTransferDelegationConfiguration
objectnull
Configuration for delegation (impersonation) access using Session Transfer Tokens
2 properties
CimdMappedClientAuthenticationMethodsPrivateKeyJwt
object
Private Key JWT authentication configuration
1 property
1 required
ClientAddonOffice365
object
Microsoft Office 365 SSO configuration.
2 properties
ClientMobileAndroid
object
Android native app configuration.
2 properties
UpdateClientResponseContent
object
61 properties
ConnectionForList
object
11 properties
PublicKeyCredentialAlgorithmEnum
string
Algorithm which will be used with the credential. Can be one of RS256, RS384, PS256. If not specified, RS256 will be used. Applies to publickey credential type.
ClientOIDCBackchannelLogoutSessionMetadata
objectnull
Controls whether session metadata is included in the logout token. Default value is null.
1 property
CredentialId
object
1 property
1 required
ClientOIDCBackchannelLogoutInitiatorsModeEnum
string
The mode property determines the configuration method for enabling initiators. custom enables only the initiators listed in the selectedinitiators array, all e…
ClientCreateAuthenticationMethodPrivateKeyJWT
object
Defines privatekeyjwt client authentication method. If this property is defined, the client is enabled to use the Private Key JWT authentication method.
1 property
1 required
ClientAddonZoom
object
Zoom SSO configuration.
1 property
CreateClientAuthenticationMethodSelfSignedTLSClientAuth
object
Defines selfsignedtlsclientauth client authentication method. If the property is defined, the client is configured to use mTLS authentication method utilizing…
1 property
1 required
ClientAddonOAG
objectnull
Okta Access Gateway SSO configuration
ClientTokenExchangeConfigurationOrNull
objectnull
Configuration for token exchange.
1 property
ClientSessionTransferDelegationDeviceBindingEnum
string
Indicates the device binding enforcement for delegation (impersonation) access. If set to 'ip', device binding is enforced by IP. If set to 'asn', device bindi…
ListClientsOffsetPaginatedResponseContent
object
4 properties
ClientOIDCBackchannelLogoutSettings
object
Configuration for OIDC backchannel logout
3 properties
ClientAddonEgnyte
object
Egnyte SSO configuration.
1 property
ClientAuthenticationMethodTLSClientAuth
object
Defines tlsclientauth client authentication method. If the property is defined, the client is configured to use CA-based mTLS authentication method.
1 property
1 required
AsyncApprovalNotificationsChannelsEnum
string
ClientCreateAuthenticationMethodTLSClientAuth
object
Defines tlsclientauth client authentication method. If the property is defined, the client is configured to use CA-based mTLS authentication method.
1 property
1 required
PostClientCredentialResponseContent
object
10 properties
X509CertificateCredential
object
3 properties
2 required
ConnectionsMetadata
object
Metadata associated with the connection in the form of an object with string values (max 255 chars). Maximum of 10 metadata properties allowed.
CimdMappedClientFields
object
Auth0 client fields mapped from the Client ID Metadata Document
10 properties
CertificateSubjectDNCredential
object
4 properties
1 required
CertificateSubjectDNCredentialTypeEnum
string
ClientSignedRequestObjectWithCredentialId
object
JWT-secured Authorization Requests (JAR) settings.
2 properties
ClientAsyncApprovalNotificationsChannelsAPIPostConfiguration
array
Array of notification channels for contacting the user when their approval is required. Valid values are guardian-push, email.
ClientOrganizationDiscoveryEnum
string
Method for discovering organizations during the preloginprompt. email allows users to find their organization by entering their email address and performing do…
ClientMobileiOS
object
iOS native app configuration.
2 properties
ClientSignedRequestObjectWithPublicKey
object
JWT-secured Authorization Requests (JAR) settings.
2 properties
UpdateTokenQuota
objectnull
1 property
1 required
RegisterCimdClientResponseContent
object
Response after successfully registering or updating a CIMD client
3 properties
3 required
ClientTokenExchangeConfiguration
object
Configuration for token exchange.
1 property
ClientMetadata
object
Metadata associated with the client, in the form of an object with string values (max 255 chars). Maximum of 10 metadata properties allowed. Field names (max 2…
ConnectionConnectedAccountsPurpose
object
Configure the purpose of a connection to be used for connected accounts and Token Vault.
2 properties
1 required
CreateTokenQuota
object
1 property
1 required
ConnectionAuthenticationPurpose
object
Configure the purpose of a connection to be used for authentication during login.
1 property
1 required
ClientAddonAzureSB
object
Azure Storage Bus addon configuration.
5 properties
CimdMappedPrivateKeyJwtCredential
object
3 properties
3 required
ClientAddonDropbox
object
Dropbox SSO indicator (no configuration settings needed for Dropbox SSO).
PatchClientCredentialRequestContent
object
1 property
ClientDefaultOrganizationFlowsEnum
string
ClientAddonSSOIntegration
object
2 properties
NativeSocialLogin
object
Configure native social settings
3 properties
X509CertificateCredentialTypeEnum
string
ClientAddonNewRelic
object
New Relic SSO configuration.
1 property
ClientCreateAuthenticationMethodPrivateKeyJWTCredentials
array
Fully defined credentials that will be enabled on the client for Private Key JWT authentication.
ClientAddonSAML
object
SAML2 addon indicator (no configuration settings needed for SAML2 addon).
16 properties
ClientOrganizationUsageEnum
string
Defines how to proceed during an authentication transaction with regards an organization. Can be deny (default), allow or require.
ClientSessionTransferAllowedAuthenticationMethodsEnum
string
ClientAddonConcur
object
Concur SSO indicator (no configuration settings needed for Concur SSO).
ClientAddonSentry
object
Sentry SSO configuration.
2 properties
CreateClientRequestContent
object
53 properties
1 required
ClientTokenEndpointAuthMethodEnum
string
Defines the requested authentication method for the token endpoint. Can be none (public client without a client secret), clientsecretpost (client uses HTTP POS…
ClientAddons
object
Addons enabled for this client and their associated configurations.
30 properties
ClientAddonSharePointExternalURL
External SharePoint application URLs if exposed to the Internet.
ClientAppTypeEnum
string
The type of application this client represents
ClientAddonFirebase
object
Google Firebase addon configuration.
5 properties
PublicKeyCredentialTypeEnum
string
Credential type. Supported types: publickey.
ClientAddonWAMS
object
Windows Azure Mobile Services addon configuration.
1 property
ClientAddonSAPAPI
object
SAP API addon configuration.
6 properties
ClientAddonSlack
object
Slack team or workspace name usually first segment in your Slack URL. e.g. https://acme-org.slack.com would be acme-org.
1 property
1 required
ClientAddonSalesforce
object
Salesforce SSO configuration.
1 property
RegisterCimdClientRequestContent
object
1 property
1 required
ClientTokenExchangeTypeEnum
string
Token exchange type. onbehalfoftokenexchange: enables On-Behalf-Of token exchange (Generally Available). customauthentication: enables custom token exchange pr…
ClientCredentialTypeEnum
string
The type of credential.
CimdValidationResult
object
Validation result for the Client ID Metadata Document
3 properties
3 required
ClientAddonAWS
object
AWS addon configuration.
3 properties
ClientOrganizationRequireBehaviorPatchEnum
stringnull
Defines how to proceed during an authentication transaction when client.organizationusage: 'require'. Can be noprompt (default), preloginprompt or postloginpro…
ClientThirdPartySecurityModeEnum
string
Security mode for third-party clients. strict enforces enhanced security controls : OAuth 2.1 alignment, explicit API authorization, and a curated set of suppo…
PatchClientCredentialResponseContent
object
10 properties
ExpressConfigurationOrNull
objectnull
Application specific configuration for use with the OIN Express Configuration feature.
9 properties
7 required
ExpressConfiguration
object
Application specific configuration for use with the OIN Express Configuration feature.
9 properties
7 required
ClientAddonEchoSign
object
Adobe EchoSign SSO configuration.
1 property
ClientAddonBox
object
Box SSO indicator (no configuration settings needed for Box SSO).
GetClientCredentialResponseContent
object
10 properties
ClientCreateAuthenticationMethodTLSClientAuthCredentials
array
Fully defined credentials that will be enabled on the client for CA-based mTLS authentication.
ClientSigningKeys
arraynull
Signing certificates associated with this client.
ClientAddonWSFed
object
WS-Fed (WIF) addon indicator. Actual configuration is stored in callback and clientaliases properties on the client.
ClientMyOrganizationPostConfiguration
object
Configuration related to the My Organization Configuration for the client.
4 properties
2 required
ClientAddonRMS
object
Active Directory Rights Management Service SSO configuration.
1 property
1 required
ClientJwtConfigurationScopes
object
Configuration related to id token claims for the client.
ClientAddonSalesforceSandboxAPI
object
Salesforce Sandbox addon configuration.
4 properties
ClientExternalMetadataCreatedByEnum
string
Indicates who created the external metadata client. The value admin indicates the client was registered via the Management API. The value client indicates the…
Client
object
61 properties
ClientAddonSalesforceAPI
object
Salesforce API addon configuration.
4 properties
The full machine-readable OpenAPI contract behind this narrative.
Other APIs Auth0 publishes across the network.