<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Create an Okta OAuth/OIDC Application with a Custom client_id and client_secret in Okta

API Access Management

Overview

Create an OAuth 2.0 or OpenID Connect (OIDC) application with a custom client ID and client secret by using the Okta Management API. Retrieve an existing application definition and create a new application with the custom credentials to achieve this goal.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • OAuth 2.0 / OpenID Connect (OIDC) Applications
  • Okta Management API

Solution

How to create an OIDC application with a custom Client ID and/or Client Secret?

Prerequisites

How to use the Apps endpoint

The Okta Management API Applications documentation details available options when creating a new OAuth 2.0 application. Depending on the application type, administrators often find it easier to build the application in the User Interface (UI) and configure it as needed, then use the management API to retrieve the definition. The sample below uses a Web App type since it defines both a client_id and client_secret.

To confirm the format of the application model, check the definition of an existing application created in the UI or our API documentation on how to create an OpenID Connect application. Next, create a new application definition and include the custom credentials by following these steps.

 

  1. Send a POST request to the /api/v1/apps endpoint using an OAuth 2.0 Access Token:
    curl --location --request POST 'https://{yourOktaDomain}.okta.com/api/v1/apps' \
    --header 'Accept: application/json' \
    --header 'Content-Type: application/json' \
    --header 'Authorization: Bearer <ACCESS_TOKEN>' \
    --data-raw '{
      "name": "oidc_client",
      "label": "My Custom OAuth Web App",
      "signOnMode": "OPENID_CONNECT",
      "credentials": {
        "oauthClient": {
          "client_id": "CUSTOM_CLIENT_ID_HERE",
          "client_secret": "CUSTOM_CLIENT_SECRET_HERE",
          "token_endpoint_auth_method": "client_secret_basic"
        }
      },
      "settings": {
        "oauthClient": {
          "client_uri": "https://example.com",
          "logo_uri": "https://example.com/logo.png",
          "redirect_uris": [
            "https://example.com/authorization-code/callback"
          ],
          "post_logout_redirect_uris": [
            "https://example.com"
          ],
          "response_types": [
            "code"
          ],
          "grant_types": [
            "authorization_code",
            "refresh_token"
          ],
          "application_type": "web"
        }
      }
    }'
    Response:
      {
        "id": "0oa9ht5knq78zN8Ni1d7",
        "name": "oidc_client",
        "label": "My Custom OIDC App",
        "status": "ACTIVE",
        "signOnMode": "OPENID_CONNECT",
        "credentials": {
          "oauthClient": {
            "client_id": "my_custom_client_id",
            "client_secret": "my_custom_client_secret_value",
            "token_endpoint_auth_method": "client_secret_basic"
          }
        },
        "settings": {
          "oauthClient": {
            "redirect_uris": [
              "http://localhost:8080/authorization-code/callback"
            ],
            "post_logout_redirect_uris": [
              "http://localhost:8080"
            ],
            "response_types": [
              "code"
            ],
            "grant_types": [
              "authorization_code",
              "refresh_token"
            ],
            "application_type": "web",
            "consent_method": "REQUIRED",
            "issuer_mode": "DYNAMIC",
            "wildcard_redirect": "DISABLED",
            "dpop_bound_access_tokens": false
          }
        },
        "_links": {
          "appLinks": [
            {
              "name": "oidc_client_link",
              "href": "https://${yourOktaDomain}/home/oidc_client/0oa9ht5knq78zN8Ni1d7/aln177a159h7Zf52X0g8",
              "type": "text/html"
            }
          ],
          "users": {
            "href": "https://${yourOktaDomain}/api/v1/apps/0oa9ht5knq78zN8Ni1d7/users"
          },
          "deactivate": {
            "href": "https://${yourOktaDomain}/api/v1/apps/0oa9ht5knq78zN8Ni1d7/lifecycle/deactivate"
          }
        }
      }
  2. Verify that the response returns an HTTP 200 OK status containing the custom client_id and client_secret.

NOTE: Ensure the custom credentials adhere to Okta’s character length requirements:

  • client_id: Between 6 and 100 characters.
  • client_secret: Between 14 and 100 characters.

 

Related References

Loading
Create an Okta OAuth/OIDC Application with a Custom client_id and client_secret in Okta | Okta Support