Create an Okta OAuth/OIDC Application with a Custom client_id and client_secret in Okta
Last Updated:
Overview
Create an OAuth 2.0 or OpenID Connect (OIDC) application with a custom client ID and client secret by using the Okta Management API. Retrieve an existing application definition and create a new application with the custom credentials to achieve this goal.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- OAuth 2.0 / OpenID Connect (OIDC) Applications
- Okta Management API
Solution
How to create an OIDC application with a custom Client ID and/or Client Secret?
Prerequisites
- Okta Domain
- API Token or Access Token (used to authorize the API call)
How to use the Apps endpoint
The Okta Management API Applications documentation details available options when creating a new OAuth 2.0 application. Depending on the application type, administrators often find it easier to build the application in the User Interface (UI) and configure it as needed, then use the management API to retrieve the definition. The sample below uses a Web App type since it defines both a client_id and client_secret.
To confirm the format of the application model, check the definition of an existing application created in the UI or our API documentation on how to create an OpenID Connect application. Next, create a new application definition and include the custom credentials by following these steps.
- Send a
POSTrequest to the/api/v1/appsendpoint using an OAuth 2.0 Access Token:
Response:curl --location --request POST 'https://{yourOktaDomain}.okta.com/api/v1/apps' \ --header 'Accept: application/json' \ --header 'Content-Type: application/json' \ --header 'Authorization: Bearer <ACCESS_TOKEN>' \ --data-raw '{ "name": "oidc_client", "label": "My Custom OAuth Web App", "signOnMode": "OPENID_CONNECT", "credentials": { "oauthClient": { "client_id": "CUSTOM_CLIENT_ID_HERE", "client_secret": "CUSTOM_CLIENT_SECRET_HERE", "token_endpoint_auth_method": "client_secret_basic" } }, "settings": { "oauthClient": { "client_uri": "https://example.com", "logo_uri": "https://example.com/logo.png", "redirect_uris": [ "https://example.com/authorization-code/callback" ], "post_logout_redirect_uris": [ "https://example.com" ], "response_types": [ "code" ], "grant_types": [ "authorization_code", "refresh_token" ], "application_type": "web" } } }'{ "id": "0oa9ht5knq78zN8Ni1d7", "name": "oidc_client", "label": "My Custom OIDC App", "status": "ACTIVE", "signOnMode": "OPENID_CONNECT", "credentials": { "oauthClient": { "client_id": "my_custom_client_id", "client_secret": "my_custom_client_secret_value", "token_endpoint_auth_method": "client_secret_basic" } }, "settings": { "oauthClient": { "redirect_uris": [ "http://localhost:8080/authorization-code/callback" ], "post_logout_redirect_uris": [ "http://localhost:8080" ], "response_types": [ "code" ], "grant_types": [ "authorization_code", "refresh_token" ], "application_type": "web", "consent_method": "REQUIRED", "issuer_mode": "DYNAMIC", "wildcard_redirect": "DISABLED", "dpop_bound_access_tokens": false } }, "_links": { "appLinks": [ { "name": "oidc_client_link", "href": "https://${yourOktaDomain}/home/oidc_client/0oa9ht5knq78zN8Ni1d7/aln177a159h7Zf52X0g8", "type": "text/html" } ], "users": { "href": "https://${yourOktaDomain}/api/v1/apps/0oa9ht5knq78zN8Ni1d7/users" }, "deactivate": { "href": "https://${yourOktaDomain}/api/v1/apps/0oa9ht5knq78zN8Ni1d7/lifecycle/deactivate" } } } - Verify that the response returns an HTTP
200 OKstatus containing the customclient_idandclient_secret.
NOTE: Ensure the custom credentials adhere to Okta’s character length requirements:
client_id: Between 6 and 100 characters.client_secret: Between 14 and 100 characters.
