OidcRelyingParty

OidcRelyingParty
OidcRelyingParty

Information about a OIDC relying party.

JSON Example
{
    "id": "string",
    "clientId": "string",
    "clientName": "string",
    "clientSecret": "string",
    "redirectUris": [
        "string"
    ],
    "scope": [
        "string"
    ],
    "isPublic": false,
    "isPkceEnabled": false,
    "isGlobal": false,
    "orgEntityRef": {
        "name": "string",
        "id": "string"
    }
}
string
id
Optional

A unique identifier for the relying party.

string
clientId
Optional

System generated client id of the relying party as per RFC-7591 Section 3.2.1.

string
clientName
Required

Human readable name of the relying party.

string
clientSecret
Optional

Server generated client secret string. Must be unique for all relying parties. This field is hidden and is only returned in plaintext on a POST (during registration).

array of string
redirectUris
Required

Supported redirect URIs for this relying party.

array of string
scope
Optional

The scope values for this relying party. The following six scope values are always present and are not configurable:

The following scope value is optional and may be specified on create only (immutable after creation):
  • vcfa_api - grants access to VCFA API endpoints. Tokens issued for relying parties without this scope will be rejected with HTTP 403 on all non-OIDC endpoints.
On the refresh_token grant, the access token issued always carries the six base scopes above. The optional scope flows as follows:
  • vcfa_api - included on the issued token only when both the original authorization (from which the refresh token was produced) had this scope AND either the request omitted the scope parameter or the request explicitly listed vcfa_api. A request that supplies scope without vcfa_api will drop it, even if the original authorization had it.
boolean
isPublic
Optional

Determines whether the relying party is a public client.

boolean
isPkceEnabled
Optional

Determines whether the relying party is enabled with PKCE support.

boolean
isGlobal
Optional

For system org - When false, the relying party is system-org-only; when true, it is global. For tenant org - The value must be false. Set only on create; read-only on update.

orgEntityRef
Optional

Entity reference used to describe VCD entities