Read OIDC Client
GET/v3/config/extension/oidc/client/:clientId
Retrieves details of an OpenID Connect client. The client enables passwordless login with EUDI Wallet by requesting verifications from individuals. The client configuration includes presentation definition that specifies which credentials to request - appearing as a QR code or deep link on the authentication page. The answer holds clientSecret and callbackSecret in clear text.
Request
Path Parameters
The ID of the client
Responses
- 200
- 400
- 401
- 404
- 500
Client details
Response Headers
Cache-Control string
Indicates that the response should not be cached.
- application/json
- Schema
- Example (from schema)
Schema
client object
The ID of the client's configured presentation definition. A presentation definition belongs to at most one client.
The name of the client
The ID of the client
The secret of the client
The valid redirect URIs for the client. The redirect_uri of an authorisation request must match one of them exactly.
The web origins of your application.
The URI at which a sub value will be calculated and returned according to the sent presentation. Empty when the client uses identityMatchingAttributes.
The secret used to access the callbackURI. Required when callbackURI is set.
identityMatchingAttributes object
A map of credential identifiers to claim paths used as linking values for identity matching. Each key identifies a credential: the vct of an SD-JWT credential, the doctype of an mdoc credential, or a type value of a W3C credential. The value is the dot-separated path to the claim within that credential. The value of that claim becomes the sub. Empty when the client uses callbackURI.
Possible values: <= 140 characters
The text that describes the login to the user in the EUDI Wallet, for example Log in to your online bank account. Empty when the presentation definition has no transaction data.
The ID of the client's key
Indicates whether the client is system-managed or not. A system-managed client cannot be updated or deleted.
The time of the last update of the client, as a Unix timestamp in seconds
The time of the creation of the client, as a Unix timestamp in seconds
{
"client": {
"presentationDefinitionId": "string",
"name": "string",
"clientId": "string",
"clientSecret": "string",
"redirectURIs": [
"string"
],
"allowedOrigins": [
"string"
],
"callbackURI": "string",
"callbackSecret": "string",
"identityMatchingAttributes": {
"urn:eudi:pid:1": "email"
},
"transactionDataAction": "Log in to your online bank account",
"kid": "string",
"systemManaged": true,
"updatedAt": 1747015200,
"createdAt": 1747011600
}
}
Bad request. The Passwordless Login extension is not enabled.
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
{
"errorCode": 400,
"errorDescription": "Bad input parameter"
}
Unauthorized
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
{
"errorCode": 400,
"errorDescription": "Bad input parameter"
}
Client not found
Response Headers
- application/json
- Schema
- Example (from schema)
- Example
Schema
The error code, for example invalid_request, not_found or server_error
The reason for the error
{
"error": "string",
"error_description": "string"
}
{
"error": "not_found",
"error_description": "Client not found"
}
Internal server error. The answer has errorCode and errorDescription when it cannot reach the provider.
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
- Provider error
- API error
The error code, for example invalid_request, not_found or server_error
The reason for the error
{
"error": "server_error",
"error_description": "Internal server error"
}