Update OAuth application
Rate limit: 60 requests per 60 seconds. This is the default shared quota — it is shared with every other endpoint that has no dedicated limit, so requests across those endpoints all draw from the same budget.
Updates one or more modifiable fields of an existing OAuth application. Only the application’s admin (the caller’s GCID must be in adminGcids) can perform updates. Non-admins receive 404 Not Found (opaque authorization - the gateway does not disclose whether the application exists). At least one field must be provided in the body; omitted fields are left unchanged. Uniqueness and length constraints match the create endpoint.
Authorizations
API key of the application. Only valid together with the x-user-key header — the pair is an alternative to OAuth bearer authentication, never sent alongside it. The pair is granted the same permissions the operation's OAuth scopes describe.
Demo credential for trying the API from these docs: lhgfaslk21490FAScVPkdsb53F9dNkfHG4faZSG5vfjndfcfgdssdgsdHF4663
User-specific authentication key. Only valid together with the x-api-key header — the pair is an alternative to OAuth bearer authentication, never sent alongside it.
Demo credential for trying the API from these docs: eyJlYW4iOiJVbnJlZ2lzdGVyZWRBcHBsaWNhdGlvbiIsImVrIjoiOE5sZ2cwcW5EUVdROUFNWGpXT2lmOWktZnpidG5KcUlqWGJ3WHJZZkpZcldrbG90ZEhvLVBjSWhQaU8xU1ZtMW84aU1WZGZqN2xWNzFjLXFxLmcybXE1dnh4Q1hUT25xaWRUaTFlcEhmVk1fIn0_
Headers
A unique request identifier.
"946f2ce8-4236-498f-b001-1d4dd9b2383f"
Path Parameters
The OAuth clientId of the application to update.
Body
At least one field must be provided. Omitted fields are left unchanged.
Updated display name.
100Updated icon URL.
500Replacement set of scopes. Each scopeId must be positive and present in the cached catalog; no duplicates.
Replacement set of redirect URIs.
500GCIDs permitted to use this application. Pass an empty array to clear.
Response
Application updated successfully.
Full application record. The clientSecret is intentionally excluded.