OidcRelyingParty
Information about a OIDC relying party.
{
"id": "string",
"clientId": "string",
"clientName": "string",
"clientSecret": "string",
"redirectUris": [
"string"
],
"scope": [
"string"
],
"isPublic": false,
"isPkceEnabled": false,
"isGlobal": false,
"orgEntityRef": {
"name": "string",
"id": "string"
}
}
A unique identifier for the relying party.
System generated client id of the relying party as per RFC-7591 Section 3.2.1.
Human readable name of the relying party.
Server generated client secret string. Must be unique for all relying parties. This field is hidden and is only returned in plaintext on a POST (during registration).
Supported redirect URIs for this relying party.
The scope values for this relying party. The following six scope values are always present and are not configurable:
- openid - as required per the OpenID Connect Core spec
- profile - as described in the OpenID Connect Core spec
- email - as described in the OpenID Connect Core spec
- phone - as described in the OpenID Connect Core spec
- groups - grants access to the groups claims.
- vcd_idp - grants access to the roles, org_id, org_display_name, and org_name claims.
- vcfa_api - grants access to VCFA API endpoints. Tokens issued for relying parties without this scope will be rejected with HTTP 403 on all non-OIDC endpoints.
refresh_token grant, the access token issued always carries the six
base scopes above. The optional scope flows as follows:
- vcfa_api - included on the issued token only when both the original authorization
(from which the refresh token was produced) had this scope AND either the request
omitted the
scopeparameter or the request explicitly listedvcfa_api. A request that suppliesscopewithoutvcfa_apiwill drop it, even if the original authorization had it.
Determines whether the relying party is a public client.
Determines whether the relying party is enabled with PKCE support.
For system org - When false, the relying party is system-org-only; when true, it is global. For tenant org - The value must be false. Set only on create; read-only on update.