Dieser Inhalt ist in der von Ihnen ausgewählten Sprache nicht verfügbar.
OAuth APIs
Reference guide for Oauth APIs
Abstract
Chapter 1. OAuth APIs
1.1. OAuthAccessToken [oauth.openshift.io/v1]
- Description
- OAuthAccessToken describes an OAuth access token. The name of a token must be prefixed with a - sha256~string, must not contain "/" or "%" characters and must be at least 32 characters long.- The name of the token is constructed from the actual token by sha256-hashing it and using URL-safe unpadded base64-encoding (as described in RFC4648) on the hashed result. - Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer). 
- Type
- 
							object
1.2. OAuthAuthorizeToken [oauth.openshift.io/v1]
- Description
- OAuthAuthorizeToken describes an OAuth authorization token - Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer). 
- Type
- 
							object
1.3. OAuthClientAuthorization [oauth.openshift.io/v1]
- Description
- OAuthClientAuthorization describes an authorization created by an OAuth client - Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer). 
- Type
- 
							object
1.4. OAuthClient [oauth.openshift.io/v1]
- Description
- OAuthClient describes an OAuth client - Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer). 
- Type
- 
							object
1.5. UserOAuthAccessToken [oauth.openshift.io/v1]
- Description
- UserOAuthAccessToken is a virtual resource to mirror OAuthAccessTokens to the user the access token was issued for
- Type
- 
							object
Chapter 2. OAuthAccessToken [oauth.openshift.io/v1]
- Description
- OAuthAccessToken describes an OAuth access token. The name of a token must be prefixed with a - sha256~string, must not contain "/" or "%" characters and must be at least 32 characters long.- The name of the token is constructed from the actual token by sha256-hashing it and using URL-safe unpadded base64-encoding (as described in RFC4648) on the hashed result. - Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer). 
- Type
- 
						object
2.1. Specification
| Property | Type | Description | 
|---|---|---|
| 
								 | 
								 | APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources | 
| 
								 | 
								 | AuthorizeToken contains the token that authorized this token | 
| 
								 | 
								 | ClientName references the client that created this token. | 
| 
								 | 
								 | ExpiresIn is the seconds from CreationTime before this token expires. | 
| 
								 | 
								 | InactivityTimeoutSeconds is the value in seconds, from the CreationTimestamp, after which this token can no longer be used. The value is automatically incremented when the token is used. | 
| 
								 | 
								 | Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds | 
| 
								 | metadata is the standard object’s metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata | |
| 
								 | 
								 | RedirectURI is the redirection associated with the token. | 
| 
								 | 
								 | RefreshToken is the value by which this token can be renewed. Can be blank. | 
| 
								 | 
								 | Scopes is an array of the requested scopes. | 
| 
								 | 
								 | UserName is the user name associated with this token | 
| 
								 | 
								 | UserUID is the unique UID associated with this token | 
2.2. API endpoints
The following API endpoints are available:
- /apis/oauth.openshift.io/v1/oauthaccesstokens- 
								DELETE: delete collection of OAuthAccessToken
- 
								GET: list or watch objects of kind OAuthAccessToken
- 
								POST: create an OAuthAccessToken
 
- 
								
- /apis/oauth.openshift.io/v1/watch/oauthaccesstokens- 
								GET: watch individual changes to a list of OAuthAccessToken. deprecated: use the 'watch' parameter with a list operation instead.
 
- 
								
- /apis/oauth.openshift.io/v1/oauthaccesstokens/{name}- 
								DELETE: delete an OAuthAccessToken
- 
								GET: read the specified OAuthAccessToken
- 
								PATCH: partially update the specified OAuthAccessToken
- 
								PUT: replace the specified OAuthAccessToken
 
- 
								
- /apis/oauth.openshift.io/v1/watch/oauthaccesstokens/{name}- 
								GET: watch changes to an object of kind OAuthAccessToken. deprecated: use the 'watch' parameter with a list operation instead, filtered to a single item with the 'fieldSelector' parameter.
 
- 
								
2.2.1. /apis/oauth.openshift.io/v1/oauthaccesstokens
- HTTP method
- 
								DELETE
- Description
- delete collection of OAuthAccessToken
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								GET
- Description
- list or watch objects of kind OAuthAccessToken
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								POST
- Description
- create an OAuthAccessToken
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| 
									 | 
									 | fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered. | 
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 201 - Created | 
									 | 
| 202 - Accepted | 
									 | 
| 401 - Unauthorized | Empty | 
2.2.2. /apis/oauth.openshift.io/v1/watch/oauthaccesstokens
- HTTP method
- 
								GET
- Description
- watch individual changes to a list of OAuthAccessToken. deprecated: use the 'watch' parameter with a list operation instead.
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
2.2.3. /apis/oauth.openshift.io/v1/oauthaccesstokens/{name}
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | name of the OAuthAccessToken | 
- HTTP method
- 
								DELETE
- Description
- delete an OAuthAccessToken
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 202 - Accepted | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								GET
- Description
- read the specified OAuthAccessToken
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								PATCH
- Description
- partially update the specified OAuthAccessToken
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| 
									 | 
									 | fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered. | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 201 - Created | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								PUT
- Description
- replace the specified OAuthAccessToken
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| 
									 | 
									 | fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered. | 
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 201 - Created | 
									 | 
| 401 - Unauthorized | Empty | 
2.2.4. /apis/oauth.openshift.io/v1/watch/oauthaccesstokens/{name}
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | name of the OAuthAccessToken | 
- HTTP method
- 
								GET
- Description
- watch changes to an object of kind OAuthAccessToken. deprecated: use the 'watch' parameter with a list operation instead, filtered to a single item with the 'fieldSelector' parameter.
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
Chapter 3. OAuthAuthorizeToken [oauth.openshift.io/v1]
- Description
- OAuthAuthorizeToken describes an OAuth authorization token - Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer). 
- Type
- 
						object
3.1. Specification
| Property | Type | Description | 
|---|---|---|
| 
								 | 
								 | APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources | 
| 
								 | 
								 | ClientName references the client that created this token. | 
| 
								 | 
								 | CodeChallenge is the optional code_challenge associated with this authorization code, as described in rfc7636 | 
| 
								 | 
								 | CodeChallengeMethod is the optional code_challenge_method associated with this authorization code, as described in rfc7636 | 
| 
								 | 
								 | ExpiresIn is the seconds from CreationTime before this token expires. | 
| 
								 | 
								 | Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds | 
| 
								 | metadata is the standard object’s metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata | |
| 
								 | 
								 | RedirectURI is the redirection associated with the token. | 
| 
								 | 
								 | Scopes is an array of the requested scopes. | 
| 
								 | 
								 | State data from request | 
| 
								 | 
								 | UserName is the user name associated with this token | 
| 
								 | 
								 | UserUID is the unique UID associated with this token. UserUID and UserName must both match for this token to be valid. | 
3.2. API endpoints
The following API endpoints are available:
- /apis/oauth.openshift.io/v1/oauthauthorizetokens- 
								DELETE: delete collection of OAuthAuthorizeToken
- 
								GET: list or watch objects of kind OAuthAuthorizeToken
- 
								POST: create an OAuthAuthorizeToken
 
- 
								
- /apis/oauth.openshift.io/v1/watch/oauthauthorizetokens- 
								GET: watch individual changes to a list of OAuthAuthorizeToken. deprecated: use the 'watch' parameter with a list operation instead.
 
- 
								
- /apis/oauth.openshift.io/v1/oauthauthorizetokens/{name}- 
								DELETE: delete an OAuthAuthorizeToken
- 
								GET: read the specified OAuthAuthorizeToken
- 
								PATCH: partially update the specified OAuthAuthorizeToken
- 
								PUT: replace the specified OAuthAuthorizeToken
 
- 
								
- /apis/oauth.openshift.io/v1/watch/oauthauthorizetokens/{name}- 
								GET: watch changes to an object of kind OAuthAuthorizeToken. deprecated: use the 'watch' parameter with a list operation instead, filtered to a single item with the 'fieldSelector' parameter.
 
- 
								
3.2.1. /apis/oauth.openshift.io/v1/oauthauthorizetokens
- HTTP method
- 
								DELETE
- Description
- delete collection of OAuthAuthorizeToken
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								GET
- Description
- list or watch objects of kind OAuthAuthorizeToken
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								POST
- Description
- create an OAuthAuthorizeToken
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| 
									 | 
									 | fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered. | 
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 201 - Created | 
									 | 
| 202 - Accepted | 
									 | 
| 401 - Unauthorized | Empty | 
3.2.2. /apis/oauth.openshift.io/v1/watch/oauthauthorizetokens
- HTTP method
- 
								GET
- Description
- watch individual changes to a list of OAuthAuthorizeToken. deprecated: use the 'watch' parameter with a list operation instead.
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
3.2.3. /apis/oauth.openshift.io/v1/oauthauthorizetokens/{name}
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | name of the OAuthAuthorizeToken | 
- HTTP method
- 
								DELETE
- Description
- delete an OAuthAuthorizeToken
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 202 - Accepted | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								GET
- Description
- read the specified OAuthAuthorizeToken
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								PATCH
- Description
- partially update the specified OAuthAuthorizeToken
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| 
									 | 
									 | fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered. | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 201 - Created | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								PUT
- Description
- replace the specified OAuthAuthorizeToken
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| 
									 | 
									 | fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered. | 
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 201 - Created | 
									 | 
| 401 - Unauthorized | Empty | 
3.2.4. /apis/oauth.openshift.io/v1/watch/oauthauthorizetokens/{name}
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | name of the OAuthAuthorizeToken | 
- HTTP method
- 
								GET
- Description
- watch changes to an object of kind OAuthAuthorizeToken. deprecated: use the 'watch' parameter with a list operation instead, filtered to a single item with the 'fieldSelector' parameter.
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
Chapter 4. OAuthClientAuthorization [oauth.openshift.io/v1]
- Description
- OAuthClientAuthorization describes an authorization created by an OAuth client - Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer). 
- Type
- 
						object
4.1. Specification
| Property | Type | Description | 
|---|---|---|
| 
								 | 
								 | APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources | 
| 
								 | 
								 | ClientName references the client that created this authorization | 
| 
								 | 
								 | Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds | 
| 
								 | metadata is the standard object’s metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata | |
| 
								 | 
								 | Scopes is an array of the granted scopes. | 
| 
								 | 
								 | UserName is the user name that authorized this client | 
| 
								 | 
								 | UserUID is the unique UID associated with this authorization. UserUID and UserName must both match for this authorization to be valid. | 
4.2. API endpoints
The following API endpoints are available:
- /apis/oauth.openshift.io/v1/oauthclientauthorizations- 
								DELETE: delete collection of OAuthClientAuthorization
- 
								GET: list or watch objects of kind OAuthClientAuthorization
- 
								POST: create an OAuthClientAuthorization
 
- 
								
- /apis/oauth.openshift.io/v1/watch/oauthclientauthorizations- 
								GET: watch individual changes to a list of OAuthClientAuthorization. deprecated: use the 'watch' parameter with a list operation instead.
 
- 
								
- /apis/oauth.openshift.io/v1/oauthclientauthorizations/{name}- 
								DELETE: delete an OAuthClientAuthorization
- 
								GET: read the specified OAuthClientAuthorization
- 
								PATCH: partially update the specified OAuthClientAuthorization
- 
								PUT: replace the specified OAuthClientAuthorization
 
- 
								
- /apis/oauth.openshift.io/v1/watch/oauthclientauthorizations/{name}- 
								GET: watch changes to an object of kind OAuthClientAuthorization. deprecated: use the 'watch' parameter with a list operation instead, filtered to a single item with the 'fieldSelector' parameter.
 
- 
								
4.2.1. /apis/oauth.openshift.io/v1/oauthclientauthorizations
- HTTP method
- 
								DELETE
- Description
- delete collection of OAuthClientAuthorization
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								GET
- Description
- list or watch objects of kind OAuthClientAuthorization
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								POST
- Description
- create an OAuthClientAuthorization
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| 
									 | 
									 | fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered. | 
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 201 - Created | 
									 | 
| 202 - Accepted | 
									 | 
| 401 - Unauthorized | Empty | 
4.2.2. /apis/oauth.openshift.io/v1/watch/oauthclientauthorizations
- HTTP method
- 
								GET
- Description
- watch individual changes to a list of OAuthClientAuthorization. deprecated: use the 'watch' parameter with a list operation instead.
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
4.2.3. /apis/oauth.openshift.io/v1/oauthclientauthorizations/{name}
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | name of the OAuthClientAuthorization | 
- HTTP method
- 
								DELETE
- Description
- delete an OAuthClientAuthorization
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 202 - Accepted | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								GET
- Description
- read the specified OAuthClientAuthorization
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								PATCH
- Description
- partially update the specified OAuthClientAuthorization
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| 
									 | 
									 | fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered. | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 201 - Created | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								PUT
- Description
- replace the specified OAuthClientAuthorization
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| 
									 | 
									 | fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered. | 
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 201 - Created | 
									 | 
| 401 - Unauthorized | Empty | 
4.2.4. /apis/oauth.openshift.io/v1/watch/oauthclientauthorizations/{name}
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | name of the OAuthClientAuthorization | 
- HTTP method
- 
								GET
- Description
- watch changes to an object of kind OAuthClientAuthorization. deprecated: use the 'watch' parameter with a list operation instead, filtered to a single item with the 'fieldSelector' parameter.
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
Chapter 5. OAuthClient [oauth.openshift.io/v1]
- Description
- OAuthClient describes an OAuth client - Compatibility level 1: Stable within a major release for a minimum of 12 months or 3 minor releases (whichever is longer). 
- Type
- 
						object
5.1. Specification
| Property | Type | Description | 
|---|---|---|
| 
								 | 
								 | AccessTokenInactivityTimeoutSeconds overrides the default token inactivity timeout for tokens granted to this client. The value represents the maximum amount of time that can occur between consecutive uses of the token. Tokens become invalid if they are not used within this temporal window. The user will need to acquire a new token to regain access once a token times out. This value needs to be set only if the default set in configuration is not appropriate for this client. Valid values are: - 0: Tokens for this client never time out - X: Tokens time out if there is no activity for X seconds The current minimum allowed value for X is 300 (5 minutes) WARNING: existing tokens' timeout will not be affected (lowered) by changing this value | 
| 
								 | 
								 | AccessTokenMaxAgeSeconds overrides the default access token max age for tokens granted to this client. 0 means no expiration. | 
| 
								 | 
								 | AdditionalSecrets holds other secrets that may be used to identify the client. This is useful for rotation and for service account token validation | 
| 
								 | 
								 | APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources | 
| 
								 | 
								 | GrantMethod is a required field which determines how to handle grants for this client. Valid grant handling methods are: - auto: always approves grant requests, useful for trusted clients - prompt: prompts the end user for approval of grant requests, useful for third-party clients | 
| 
								 | 
								 | Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds | 
| 
								 | metadata is the standard object’s metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata | |
| 
								 | 
								 | RedirectURIs is the valid redirection URIs associated with a client | 
| 
								 | 
								 | RespondWithChallenges indicates whether the client wants authentication needed responses made in the form of challenges instead of redirects | 
| 
								 | 
								 | ScopeRestrictions describes which scopes this client can request. Each requested scope is checked against each restriction. If any restriction matches, then the scope is allowed. If no restriction matches, then the scope is denied. | 
| 
								 | 
								 | ScopeRestriction describe one restriction on scopes. Exactly one option must be non-nil. | 
| 
								 | 
								 | Secret is the unique secret associated with a client | 
5.1.1. .scopeRestrictions
- Description
- ScopeRestrictions describes which scopes this client can request. Each requested scope is checked against each restriction. If any restriction matches, then the scope is allowed. If no restriction matches, then the scope is denied.
- Type
- 
								array
5.1.2. .scopeRestrictions[]
- Description
- ScopeRestriction describe one restriction on scopes. Exactly one option must be non-nil.
- Type
- 
								object
| Property | Type | Description | 
|---|---|---|
| 
									 | 
									 | ClusterRoleScopeRestriction describes restrictions on cluster role scopes | 
| 
									 | 
									 | ExactValues means the scope has to match a particular set of strings exactly | 
5.1.3. .scopeRestrictions[].clusterRole
- Description
- ClusterRoleScopeRestriction describes restrictions on cluster role scopes
- Type
- 
								object
- Required
- 
										roleNames
- 
										namespaces
- 
										allowEscalation
 
- 
										
| Property | Type | Description | 
|---|---|---|
| 
									 | 
									 | AllowEscalation indicates whether you can request roles and their escalating resources | 
| 
									 | 
									 | Namespaces is the list of namespaces that can be referenced. * means any of them (including *) | 
| 
									 | 
									 | RoleNames is the list of cluster roles that can referenced. * means anything | 
5.2. API endpoints
The following API endpoints are available:
- /apis/oauth.openshift.io/v1/oauthclients- 
								DELETE: delete collection of OAuthClient
- 
								GET: list or watch objects of kind OAuthClient
- 
								POST: create an OAuthClient
 
- 
								
- /apis/oauth.openshift.io/v1/watch/oauthclients- 
								GET: watch individual changes to a list of OAuthClient. deprecated: use the 'watch' parameter with a list operation instead.
 
- 
								
- /apis/oauth.openshift.io/v1/oauthclients/{name}- 
								DELETE: delete an OAuthClient
- 
								GET: read the specified OAuthClient
- 
								PATCH: partially update the specified OAuthClient
- 
								PUT: replace the specified OAuthClient
 
- 
								
- /apis/oauth.openshift.io/v1/watch/oauthclients/{name}- 
								GET: watch changes to an object of kind OAuthClient. deprecated: use the 'watch' parameter with a list operation instead, filtered to a single item with the 'fieldSelector' parameter.
 
- 
								
5.2.1. /apis/oauth.openshift.io/v1/oauthclients
- HTTP method
- 
								DELETE
- Description
- delete collection of OAuthClient
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								GET
- Description
- list or watch objects of kind OAuthClient
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								POST
- Description
- create an OAuthClient
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| 
									 | 
									 | fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered. | 
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 201 - Created | 
									 | 
| 202 - Accepted | 
									 | 
| 401 - Unauthorized | Empty | 
5.2.2. /apis/oauth.openshift.io/v1/watch/oauthclients
- HTTP method
- 
								GET
- Description
- watch individual changes to a list of OAuthClient. deprecated: use the 'watch' parameter with a list operation instead.
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
5.2.3. /apis/oauth.openshift.io/v1/oauthclients/{name}
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | name of the OAuthClient | 
- HTTP method
- 
								DELETE
- Description
- delete an OAuthClient
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 202 - Accepted | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								GET
- Description
- read the specified OAuthClient
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								PATCH
- Description
- partially update the specified OAuthClient
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| 
									 | 
									 | fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered. | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 201 - Created | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								PUT
- Description
- replace the specified OAuthClient
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| 
									 | 
									 | fieldValidation instructs the server on how to handle objects in the request (POST/PUT/PATCH) containing unknown or duplicate fields. Valid values are: - Ignore: This will ignore any unknown fields that are silently dropped from the object, and will ignore all but the last duplicate field that the decoder encounters. This is the default behavior prior to v1.23. - Warn: This will send a warning via the standard warning response header for each unknown field that is dropped from the object, and for each duplicate field that is encountered. The request will still succeed if there are no other errors, and will only persist the last of any duplicate fields. This is the default in v1.23+ - Strict: This will fail the request with a BadRequest error if any unknown fields would be dropped from the object, or if any duplicate fields are present. The error returned from the server will contain all unknown and duplicate fields encountered. | 
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 201 - Created | 
									 | 
| 401 - Unauthorized | Empty | 
5.2.4. /apis/oauth.openshift.io/v1/watch/oauthclients/{name}
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | name of the OAuthClient | 
- HTTP method
- 
								GET
- Description
- watch changes to an object of kind OAuthClient. deprecated: use the 'watch' parameter with a list operation instead, filtered to a single item with the 'fieldSelector' parameter.
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
Chapter 6. UserOAuthAccessToken [oauth.openshift.io/v1]
- Description
- UserOAuthAccessToken is a virtual resource to mirror OAuthAccessTokens to the user the access token was issued for
- Type
- 
						object
6.1. Specification
| Property | Type | Description | 
|---|---|---|
| 
								 | 
								 | APIVersion defines the versioned schema of this representation of an object. Servers should convert recognized schemas to the latest internal value, and may reject unrecognized values. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources | 
| 
								 | 
								 | AuthorizeToken contains the token that authorized this token | 
| 
								 | 
								 | ClientName references the client that created this token. | 
| 
								 | 
								 | ExpiresIn is the seconds from CreationTime before this token expires. | 
| 
								 | 
								 | InactivityTimeoutSeconds is the value in seconds, from the CreationTimestamp, after which this token can no longer be used. The value is automatically incremented when the token is used. | 
| 
								 | 
								 | Kind is a string value representing the REST resource this object represents. Servers may infer this from the endpoint the client submits requests to. Cannot be updated. In CamelCase. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds | 
| 
								 | metadata is the standard object’s metadata. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#metadata | |
| 
								 | 
								 | RedirectURI is the redirection associated with the token. | 
| 
								 | 
								 | RefreshToken is the value by which this token can be renewed. Can be blank. | 
| 
								 | 
								 | Scopes is an array of the requested scopes. | 
| 
								 | 
								 | UserName is the user name associated with this token | 
| 
								 | 
								 | UserUID is the unique UID associated with this token | 
6.2. API endpoints
The following API endpoints are available:
- /apis/oauth.openshift.io/v1/useroauthaccesstokens- 
								GET: list or watch objects of kind UserOAuthAccessToken
 
- 
								
- /apis/oauth.openshift.io/v1/watch/useroauthaccesstokens- 
								GET: watch individual changes to a list of UserOAuthAccessToken. deprecated: use the 'watch' parameter with a list operation instead.
 
- 
								
- /apis/oauth.openshift.io/v1/useroauthaccesstokens/{name}- 
								DELETE: delete an UserOAuthAccessToken
- 
								GET: read the specified UserOAuthAccessToken
 
- 
								
- /apis/oauth.openshift.io/v1/watch/useroauthaccesstokens/{name}- 
								GET: watch changes to an object of kind UserOAuthAccessToken. deprecated: use the 'watch' parameter with a list operation instead, filtered to a single item with the 'fieldSelector' parameter.
 
- 
								
6.2.1. /apis/oauth.openshift.io/v1/useroauthaccesstokens
- HTTP method
- 
								GET
- Description
- list or watch objects of kind UserOAuthAccessToken
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
6.2.2. /apis/oauth.openshift.io/v1/watch/useroauthaccesstokens
- HTTP method
- 
								GET
- Description
- watch individual changes to a list of UserOAuthAccessToken. deprecated: use the 'watch' parameter with a list operation instead.
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
6.2.3. /apis/oauth.openshift.io/v1/useroauthaccesstokens/{name}
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | name of the UserOAuthAccessToken | 
- HTTP method
- 
								DELETE
- Description
- delete an UserOAuthAccessToken
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | When present, indicates that modifications should not be persisted. An invalid or unrecognized dryRun directive will result in an error response and no further processing of the request. Valid values are: - All: all dry run stages will be processed | 
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 202 - Accepted | 
									 | 
| 401 - Unauthorized | Empty | 
- HTTP method
- 
								GET
- Description
- read the specified UserOAuthAccessToken
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
6.2.4. /apis/oauth.openshift.io/v1/watch/useroauthaccesstokens/{name}
| Parameter | Type | Description | 
|---|---|---|
| 
									 | 
									 | name of the UserOAuthAccessToken | 
- HTTP method
- 
								GET
- Description
- watch changes to an object of kind UserOAuthAccessToken. deprecated: use the 'watch' parameter with a list operation instead, filtered to a single item with the 'fieldSelector' parameter.
| HTTP code | Reponse body | 
|---|---|
| 200 - OK | 
									 | 
| 401 - Unauthorized | Empty | 
        Legal Notice
        
          
            
          
        
      
 
Copyright © 2025 Red Hat
OpenShift documentation is licensed under the Apache License 2.0 (https://www.apache.org/licenses/LICENSE-2.0).
Modified versions must remove all Red Hat trademarks.
Portions adapted from https://github.com/kubernetes-incubator/service-catalog/ with modifications by Red Hat.
Red Hat, Red Hat Enterprise Linux, the Red Hat logo, the Shadowman logo, JBoss, OpenShift, Fedora, the Infinity logo, and RHCE are trademarks of Red Hat, Inc., registered in the United States and other countries.
Linux® is the registered trademark of Linus Torvalds in the United States and other countries.
Java® is a registered trademark of Oracle and/or its affiliates.
XFS® is a trademark of Silicon Graphics International Corp. or its subsidiaries in the United States and/or other countries.
MySQL® is a registered trademark of MySQL AB in the United States, the European Union and other countries.
Node.js® is an official trademark of Joyent. Red Hat Software Collections is not formally related to or endorsed by the official Joyent Node.js open source or commercial project.
The OpenStack® Word Mark and OpenStack logo are either registered trademarks/service marks or trademarks/service marks of the OpenStack Foundation, in the United States and other countries and are used with the OpenStack Foundation’s permission. We are not affiliated with, endorsed or sponsored by the OpenStack Foundation, or the OpenStack community.
All other trademarks are the property of their respective owners.