Skip to main content

Update OIDC Client

PUT 

/v3/config/extension/oidc/client/:clientId

Updates the configuration of an existing OpenID Connect client. Allows modification of the client's name, presentation definition, transaction data action, redirect URIs, web origins, identity matching attributes, or callback configuration. A presentation definition belongs to at most one client. System-managed clients cannot be updated.

Request​

Path Parameters

    clientId stringrequired

    The ID of the client

Body

required

At least one of the following fields must be provided for updating the client: name, presentationDefinitionId, transactionDataAction, redirectURIs, allowedOrigins, identityMatchingAttributes, callbackURI, or callbackSecret.

    name string

    The name of the client

    presentationDefinitionId string

    The ID of the presentation definition to use for this client. It cannot be empty, and the presentation definition must not belong to another client. If the presentation definition has a transaction data template, the template must be login_risk_transaction_non_ts12 or login_risk_transaction. No credential may come with its own transaction data (TS12: payment wallet attestation, software statement, QESAC, SCA credential types): such a definition has another purpose than login. A new presentation definition is validated against the identity matching attributes and the transaction data action of the client.

    redirectURIs string[]

    The redirect URIs of the client. The redirect_uri of an authorisation request must match one of them exactly.

    allowedOrigins string[]

    The web origins of your application.

    identityMatchingAttributes object

    A map of credential identifiers to claim paths used as linking values for identity matching. Each key identifies a credential: the vct of an SD-JWT credential, the doctype of an mdoc credential, or a type value of a W3C credential. The value is the dot-separated path to the claim within that credential. The value of that claim becomes the sub. Give one entry for each credential in the DCQL query of the presentation definition. The key and the path must exist in that DCQL query. Example: {"urn:eudi:pid:1": "email"} uses the email claim of the PID credential for identity matching. Setting it removes callbackURI and callbackSecret from the client.

    property name* string
    callbackURI string

    The URI at which a sub value will be calculated and returned according to the sent presentation. Use an HTTPS endpoint. The endpoint receives the presentations in a POST request and must answer with status 200 and a JSON object that holds sub. Setting it removes identityMatchingAttributes from the client.

    callbackSecret string

    The secret used to access the callbackURI. Required when callbackURI is set.

    transactionDataAction string

    Possible values: <= 140 characters

    The text that describes the login to the user in the EUDI Wallet, for example Log in to your online bank account. Give it when the presentation definition has a transaction data template. Send an empty string when the presentation definition has no transaction data. The EUDI Wallet accepts at most 140 characters.

Responses​

Client updated

Response Headers
  • Cache-Control string

    Indicates that the response should not be cached.

Schema
    client object
    presentationDefinitionId string

    The ID of the client's configured presentation definition. A presentation definition belongs to at most one client.

    name string

    The name of the client

    clientId string

    The ID of the client

    clientSecret string

    The secret of the client

    redirectURIs string[]

    The valid redirect URIs for the client. The redirect_uri of an authorisation request must match one of them exactly.

    allowedOrigins string[]

    The web origins of your application.

    callbackURI string

    The URI at which a sub value will be calculated and returned according to the sent presentation. Empty when the client uses identityMatchingAttributes.

    callbackSecret string

    The secret used to access the callbackURI. Required when callbackURI is set.

    identityMatchingAttributes object

    A map of credential identifiers to claim paths used as linking values for identity matching. Each key identifies a credential: the vct of an SD-JWT credential, the doctype of an mdoc credential, or a type value of a W3C credential. The value is the dot-separated path to the claim within that credential. The value of that claim becomes the sub. Empty when the client uses callbackURI.

    property name* string
    transactionDataAction string

    Possible values: <= 140 characters

    The text that describes the login to the user in the EUDI Wallet, for example Log in to your online bank account. Empty when the presentation definition has no transaction data.

    kid string

    The ID of the client's key

    systemManaged boolean

    Indicates whether the client is system-managed or not. A system-managed client cannot be updated or deleted.

    updatedAt integer

    The time of the last update of the client, as a Unix timestamp in seconds

    createdAt integer

    The time of the creation of the client, as a Unix timestamp in seconds

Loading...