> For the complete documentation index, see [llms.txt](https://docs.veza.com/4yItIzMvkpAvMVFAamTf/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.veza.com/4yItIzMvkpAvMVFAamTf/developers/api/authentication/oauth2-clients.md).

# OAuth2 Clients

Create OAuth2 Clients for machine-to-machine API access scoped to a Veza team

OAuth2 Clients provide machine-to-machine authentication for backend services and automated pipelines. No user interaction or redirect is required, and access is scoped to a specific Veza team. Choose one of two grant types when you create the client:

* **Client credentials**: the client authenticates with a client ID and client secret.
* **JWT bearer**: the client authenticates by presenting a JWT assertion signed with its own private key. You generate the key pair and upload only the public key to Veza.

Use OAuth2 Clients when:

* A backend service or pipeline needs to call Veza APIs without user involvement
* You want credentials tied to a team rather than a personal user account
* You are automating integrations or data collection

OAuth2 Clients are managed from **Administration** > *API Keys* > *OAuth2 Clients*.

## Prerequisites

* Admin role in Veza.
* The team the client will be scoped to must already exist.

## Create an OAuth2 Client

1. Open **Administration** > *API Keys* > *OAuth2 Clients*.
2. Click **Add New OAuth2 Client**.
3. Enter a **Client Name** to identify the client.
4. Select the **Grant Type**: **Client Credentials** or **JWT Bearer**.
5. For a JWT Bearer client, provide the **Public Key**. Paste a PEM-encoded RSA or ECDSA public key, or upload a `.pem` file. Keep the matching private key in your own secret store: Veza never receives it.
6. Select the **Team** the client will be scoped to. The client's access is limited to the resources and permissions of that team.
7. Select the **Allowed scopes** the client is permitted to use. See [Scopes](#scopes) for the available scopes and the grant types each one supports.
8. Click **Create**.

For a Client Credentials client, Veza displays the **Client ID** and an initial **Client Secret** after creation. Copy both values. The secret will not be shown again. For a JWT Bearer client, Veza displays the **Client ID**; the uploaded public key is stored as a client secret and can be viewed later with the **View Client Secrets** action.

## Get an access token

For a Client Credentials client, request an access token with the client ID and secret:

```bash
curl -X POST https://<tenant>/oauth/token \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=client_credentials" \
  -d "client_id=<client-id>" \
  -d "client_secret=<client-secret>" \
  -d "scope=<scope>"
```

A successful response:

```json
{
  "access_token": "<token>",
  "token_type": "Bearer",
  "expires_in": 43200,
  "scope": "<scope>"
}
```

Client credentials access tokens expire after 12 hours.

For a JWT Bearer client, sign a JWT assertion with the private key that matches the public key you uploaded, then present it at the same token endpoint with `grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer`. JWT bearer access tokens expire after 1 hour.

Neither grant type issues a refresh token. Request a new access token when the current one expires.

### Use the access token

Include the token as a Bearer token in the `Authorization` header:

```bash
curl -H "Authorization: Bearer <access-token>" \
  https://<tenant>/api/v1/providers
```

## Manage client secrets

Each OAuth2 Client supports a maximum of 2 client secrets.

1. From the **OAuth2 Clients** list, locate the client and select **View Client Secrets**.
2. Click **Create New Client Secret**.
3. Copy and save the secret value. It will not be shown again. Only the first four characters are displayed for identification after creation.

| Column             | Description                                         |
| ------------------ | --------------------------------------------------- |
| First 4 characters | A partial identifier to distinguish between secrets |
| Created at         | When the secret was generated                       |
| Last used at       | Most recent authentication using this secret        |

Revoked tokens take effect immediately. Veza validates every token against the database on each request, so a deleted or revoked token is rejected on the next use.

To rotate a secret: create a new one, update your service, then delete the old one.

A JWT Bearer client stores each uploaded public key as a client secret, so the same limit and rotation process apply. Register the new public key, switch your service to the new private key, then delete the old key.

## Team scoping

Each OAuth2 Client is associated with one team and inherits that team's permissions. If a service needs access to resources across multiple teams, create a separate client for each team.

{% hint style="info" %}
Changing a team's permissions affects all OAuth2 Clients scoped to that team.
{% endhint %}

## Scopes

OAuth2 Client scopes determine which operations the issued tokens can perform. Select only the scopes your service requires. See [OAuth Scopes](/4yItIzMvkpAvMVFAamTf/developers/api/authentication/oauth-scopes.md) for the full list of Veza scopes, their descriptions, and the grant types each one supports. You can assign any scope marked for the client credentials or JWT bearer grant to an OAuth2 Client.

The scopes you select define the client's effective permissions within its team. You do not assign Veza roles to a client separately.

Veza continues to add scopes. If a capability your service needs has no scope listed, contact your Veza account team.

## Manage OAuth2 Clients

From the **OAuth2 Clients** list, open the actions menu for a client:

* **Edit Client**: Update the client name, team assignment, or allowed scopes.
* **View Client Secrets**: View, create, and delete client secrets, including registered public keys.
* **Revoke Client**: Temporarily disable the client. All active tokens are invalidated immediately.
* **Reinstate Client**: Re-enable a revoked client so it can authenticate again. This action replaces **Revoke Client** once a client is revoked.
* **Delete Client**: Permanently remove the client and all associated secrets and tokens.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.veza.com/4yItIzMvkpAvMVFAamTf/developers/api/authentication/oauth2-clients.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
