Update OIDC Client
PUT/v3/config/extension/oidc/client/:clientId
Updates the configuration of an existing OpenID Connect client. Allows modification of the client's name, presentation definition, transaction data action, redirect URIs, web origins, identity matching attributes, or callback configuration. A presentation definition belongs to at most one client. System-managed clients cannot be updated.
Request
Path Parameters
The ID of the client
- application/json
Body
required
At least one of the following fields must be provided for updating the client: name, presentationDefinitionId, transactionDataAction, redirectURIs, allowedOrigins, identityMatchingAttributes, callbackURI, or callbackSecret.
The name of the client
The ID of the presentation definition to use for this client. It cannot be empty, and the presentation definition must not belong to another client. If the presentation definition has a transaction data template, the template must be login_risk_transaction_non_ts12 or login_risk_transaction. No credential may come with its own transaction data (TS12: payment wallet attestation, software statement, QESAC, SCA credential types): such a definition has another purpose than login. A new presentation definition is validated against the identity matching attributes and the transaction data action of the client.
The redirect URIs of the client. The redirect_uri of an authorisation request must match one of them exactly.
The web origins of your application.
identityMatchingAttributes object
A map of credential identifiers to claim paths used as linking values for identity matching. Each key identifies a credential: the vct of an SD-JWT credential, the doctype of an mdoc credential, or a type value of a W3C credential. The value is the dot-separated path to the claim within that credential. The value of that claim becomes the sub. Give one entry for each credential in the DCQL query of the presentation definition. The key and the path must exist in that DCQL query. Example: {"urn:eudi:pid:1": "email"} uses the email claim of the PID credential for identity matching. Setting it removes callbackURI and callbackSecret from the client.
The URI at which a sub value will be calculated and returned according to the sent presentation. Use an HTTPS endpoint. The endpoint receives the presentations in a POST request and must answer with status 200 and a JSON object that holds sub. Setting it removes identityMatchingAttributes from the client.
The secret used to access the callbackURI. Required when callbackURI is set.
Possible values: <= 140 characters
The text that describes the login to the user in the EUDI Wallet, for example Log in to your online bank account. Give it when the presentation definition has a transaction data template. Send an empty string when the presentation definition has no transaction data. The EUDI Wallet accepts at most 140 characters.
Responses
- 200
- 400
- 401
- 404
- 500
Client updated
Response Headers
Cache-Control string
Indicates that the response should not be cached.
- application/json
- Schema
- Example (from schema)
Schema
client object
The ID of the client's configured presentation definition. A presentation definition belongs to at most one client.
The name of the client
The ID of the client
The secret of the client
The valid redirect URIs for the client. The redirect_uri of an authorisation request must match one of them exactly.
The web origins of your application.
The URI at which a sub value will be calculated and returned according to the sent presentation. Empty when the client uses identityMatchingAttributes.
The secret used to access the callbackURI. Required when callbackURI is set.
identityMatchingAttributes object
A map of credential identifiers to claim paths used as linking values for identity matching. Each key identifies a credential: the vct of an SD-JWT credential, the doctype of an mdoc credential, or a type value of a W3C credential. The value is the dot-separated path to the claim within that credential. The value of that claim becomes the sub. Empty when the client uses callbackURI.
Possible values: <= 140 characters
The text that describes the login to the user in the EUDI Wallet, for example Log in to your online bank account. Empty when the presentation definition has no transaction data.
The ID of the client's key
Indicates whether the client is system-managed or not. A system-managed client cannot be updated or deleted.
The time of the last update of the client, as a Unix timestamp in seconds
The time of the creation of the client, as a Unix timestamp in seconds
{
"client": {
"presentationDefinitionId": "string",
"name": "string",
"clientId": "string",
"clientSecret": "string",
"redirectURIs": [
"string"
],
"allowedOrigins": [
"string"
],
"callbackURI": "string",
"callbackSecret": "string",
"identityMatchingAttributes": {
"urn:eudi:pid:1": "email"
},
"transactionDataAction": "Log in to your online bank account",
"kid": "string",
"systemManaged": true,
"updatedAt": 1747015200,
"createdAt": 1747011600
}
}
Bad request. The provider answers with error and error_description when the body is not valid JSON or holds no field, when the client is system-managed, when presentationDefinitionId is empty or already belongs to another client, when callbackSecret is empty, or when the client would have both or none of identityMatchingAttributes and callbackURI. The answer has errorCode and errorDescription when the Passwordless Login extension is not enabled.
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
- Provider error
- API error
The error code, for example invalid_request, not_found or server_error
The reason for the error
{
"error": "invalid_request",
"error_description": "System managed clients cannot be updated"
}
Unauthorized
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
{
"errorCode": 400,
"errorDescription": "Bad input parameter"
}
Client not found
Response Headers
- application/json
- Schema
- Example (from schema)
- Example
Schema
The error code, for example invalid_request, not_found or server_error
The reason for the error
{
"error": "string",
"error_description": "string"
}
{
"error": "not_found",
"error_description": "Client not found"
}
The validation of the presentation definition, of identityMatchingAttributes or of transactionDataAction refused the request, or an internal error occurred. A refusal holds the reason in error_description. The API answers with errorCode and errorDescription when it cannot reach the provider.
Response Headers
- application/json
- Schema
- Example (from schema)
Schema
- Provider error
- API error
The error code, for example invalid_request, not_found or server_error
The reason for the error
{
"error": "invalid_request",
"error_description": "Transaction data action is required when presentation definition has transaction data"
}