PATCH/api/apis/{api_server_id}Authenticated

Update an API server's dynamic-client policy

Updates whether dynamically registered clients may request tokens for this API server as an RFC 8707 resource, and how a resource URL is matched against its registered domains. Nothing else about an API server is updatable here. Hardcoded API servers cannot be changed.

operationId patch_api_apis_api_server_idAPI servers

Authentication & permissionsAuthenticated

Any authenticated user

Accepted credentials
Who may call
Any authenticated user
Notes
Organization owners/admins of the owning organization, the owning user, or platform administrators.

Path parameters

NameTypeDescription
api_server_id*string

API server id

Request body

Required

application/json
ApiServerDynamicClientPolicyUpdate
PropertyTypeDescription
allow_dynamic_clientsboolean

Whether clients registered through RFC 7591 dynamic client registration may obtain access tokens for this API server (as an RFC 8707 resource) without an explicit app-to-API connection

resource_url_match_mode"exact" | "prefix"

Whether an RFC 8707 resource URL must equal a registered domain (exact) or may be any URL under one (prefix)

JSONExample
"allow_dynamic_clients"true
"resource_url_match_mode""exact"

Responses

application/json
ApiServerResponse
PropertyTypeDescription
success*true
api_server*ApiServerDefinition

An API server (resource server) registration: identity, listing visibility, ownership (platform / organization / user) and dynamic-client policy.

api_server_id*string

minLength: 2maxLength: 64pattern: ^[a-z0-9_-]*$

api_server_name*string

maxLength: 64

api_server_description*string

maxLength: 512

created_at*number

minimum: 0

public*boolean
hardcoded*boolean
owner_type"platform" | "organization" | "user" | "dynamic-client-registration"
owner_organization_idstring | null | null
owner_uidstring (uuid) | null (uuid) | null
created_bystring (uuid) | null (uuid) | null
allow_dynamic_clientsboolean
resource_url_match_mode"exact" | "prefix"
JSONExample
"success"true
"api_server"
"api_server_id""string"
"api_server_name""string"
"api_server_description""string"
"created_at"1.5
"public"true
"hardcoded"true
"owner_type""platform"
"owner_organization_id""string"
"owner_uid""123e4567-e89b-12d3-a456-426614174000"
"created_by""123e4567-e89b-12d3-a456-426614174000"
"allow_dynamic_clients"true
"resource_url_match_mode""exact"

Example request

bashcurl
curl -X PATCH 'https://auth.schemavaults.com/api/apis/<api_server_id>' \
  -b 'refresh_token_<auth_server_app_id>=<value>' \
  -H 'Content-Type: application/json' \
  -d '{
  "allow_dynamic_clients": true,
  "resource_url_match_mode": "exact"
}'