Skip to main content
OAuth clients are applications owned by an organization. They use the selected organization. Applications you have authorized are account connections, listed under photon account oauth. Browse the automatic command reference.

Clients

--redirect-uri and --scope are repeatable; without --scope the client has no delegated scopes. The default redirect must exactly match one of the supplied redirect URIs. Redirect URIs must use HTTPS, except for HTTP loopback URLs during development. User info, fragments, duplicates, and more than ten redirect URIs are rejected before the request is sent. Creation sends an idempotency key, generated unless you pass --idempotency-key. If the outcome is uncertain — the connection dropped or Photon answered with a server error — the error names the key: retry the same command with it rather than a new one, and Photon returns the client the first request created. update replaces redirect URIs or scopes when you supply them. Use --clear-description or --clear-scopes to remove those values:
delete reports status. When Photon has accepted the deletion but provider cleanup is still pending, the CLI warns that existing tokens may keep working until it completes.

Test an authorization

authorize builds an authorization-code request and opens it, which is the fastest way to check a client’s redirect URIs and scopes:
It reads the scope catalogue, discovers the authorization server through Photon’s protected-resource metadata, reads the client, and validates the redirect URI and scopes before opening anything. With the options omitted, it uses the client’s default redirect URI and configured scopes.
This helper only generates the authorization URL, state, and nonce. Your registered application handles the callback and exchanges the code with its own client secret — the CLI never accepts or stores that secret.

Secrets

secret list returns metadata only, including revokesAt for a secret whose revocation is scheduled.
secret create prints the plaintext secret once. Save it immediately. Photon never stores it locally, and --debug output redacts the response.Secret creation is not journaled, and the plaintext is never stored. After an uncertain failure, retry with the --idempotency-key the error names: Photon then reports the earlier attempt’s status instead of creating a second secret, and the CLI reports OAUTH_SECRET_NOT_DELIVERED. Plaintext is only returned to the request that created the secret, so if it was lost, revoke that secret from secret list and create a replacement.
These commands replaced photon account oauth client and photon account oauth secret, which now only point here.