---
title: Create OAuth Client
---

[Skip to content](#%5Ftop) 

[API Reference](https://developers.cloudflare.com/api/python)

[IAM](https://developers.cloudflare.com/api/python/resources/iam)

[OAuth Clients](https://developers.cloudflare.com/api/python/resources/iam/subresources/oauth%5Fclients)

Copy Markdown

Open in **Claude**

Open in **ChatGPT**

Open in **Cursor**

---

**Copy Markdown**

**View as Markdown**

# Create OAuth Client

iam.oauth\_clients.create(OAuthClientCreateParams\*\*kwargs)  \-> [OAuthClientCreateResponse](https://developers.cloudflare.com/api/python/resources/iam#%28resource%29%20iam.oauth%5Fclients%20%3E%20%28model%29%20oauth%5Fclient%5Fcreate%5Fresponse%20%3E%20%28schema%29)

POST/accounts/{account\_id}/oauth\_clients

Create a new OAuth client for an account.

##### Security

API Token

The preferred authorization scheme for interacting with the Cloudflare API. [Create a token](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/).

**Example:**`Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY`

API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**`X-Auth-Email: user@example.com`

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**`X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194`

##### Accepted Permissions (at least one required)

`OAuth Client Write`

##### ParametersExpand Collapse 

account\_id: str

Account identifier tag.

maxLength32

minLength32

client\_name: str

Human-readable name of the OAuth client.

grant\_types: List\[Literal\["authorization\_code", "refresh\_token"\]\]

Array of OAuth grant types the client is allowed to use. `authorization_code` is required; `refresh_token` may be included optionally.

One of the following:

"authorization\_code"

"refresh\_token"

redirect\_uris: Sequence\[str\]

Array of allowed redirect URIs for the client.

response\_types: List\[Literal\["token", "id\_token", "code"\]\]

Array of OAuth response types the client is allowed to use.

One of the following:

"token"

"id\_token"

"code"

scopes: Sequence\[str\]

Array of OAuth scopes the client is allowed to request. Colon-delimited scopes are not accepted. Dot-delimited scopes are validated against available OAuth API scopes; simple identity scopes are allowed. Protocol scopes `offline_access` and `openid` are added or removed automatically based on `grant_types` and `response_types`.

token\_endpoint\_auth\_method: Literal\["none", "client\_secret\_basic", "client\_secret\_post"\]

The authentication method the client uses at the token endpoint.

One of the following:

"none"

"client\_secret\_basic"

"client\_secret\_post"

allowed\_cors\_origins: Optional\[Sequence\[str\]\]

Array of allowed CORS origins.

client\_uri: Optional\[str\]

URL of the home page of the client.

logo\_uri: Optional\[str\]

URL of the client’s logo.

optional\_scopes: Optional\[Sequence\[str\]\]

Scopes that the authorizing user may decline during consent. Each value must also appear in `scopes`. The scopes `openid`, `offline`, and `offline_access` cannot be optional.

policy\_uri: Optional\[str\]

URL that points to a privacy policy document.

post\_logout\_redirect\_uris: Optional\[Sequence\[str\]\]

Array of allowed post-logout redirect URIs.

tos\_uri: Optional\[str\]

URL that points to a terms of service document.

##### ReturnsExpand Collapse 

class OAuthClientCreateResponse: …

Fields shared by OAuth client responses and create/update requests.

client\_id: str

The unique identifier for an OAuth client.

visibility: Literal\["public", "private"\]

Visibility of the OAuth client.

One of the following:

"public"

"private"

allowed\_cors\_origins: Optional\[List\[str\]\]

Array of allowed CORS origins.

client\_name: Optional\[str\]

Human-readable name of the OAuth client.

client\_secret: Optional\[str\]

The client secret. This is the only time the secret is returned in a response.

client\_uri: Optional\[str\]

URL of the home page of the client.

client\_uri\_verification: Optional\[ClientURIVerification\]

Client URI domain control verification state.

status: Optional\[Literal\["pending", "in\_progress", "verified", "failed"\]\]

Current verification status for the client URI host.

One of the following:

"pending"

"in\_progress"

"verified"

"failed"

text: Optional\[str\]

Exact TXT record value that must be added to DNS to prove ownership of the client URI host.

created\_at: Optional\[datetime\]

Timestamp when the OAuth client was created.

formatdate-time

grant\_types: Optional\[List\[Literal\["authorization\_code", "refresh\_token"\]\]\]

Array of OAuth grant types the client is allowed to use. `authorization_code` is required; `refresh_token` may be included optionally.

One of the following:

"authorization\_code"

"refresh\_token"

has\_rotated\_secret: Optional\[bool\]

Indicates whether the client has a rotated secret that has not yet been deleted.

logo\_uri: Optional\[str\]

URL of the client’s logo.

optional\_scopes: Optional\[List\[str\]\]

Scopes that the authorizing user may decline during consent. Each value must also appear in `scopes`. The scopes `openid`, `offline`, and `offline_access` cannot be optional.

policy\_uri: Optional\[str\]

URL that points to a privacy policy document.

post\_logout\_redirect\_uris: Optional\[List\[str\]\]

Array of allowed post-logout redirect URIs.

promoted\_at: Optional\[datetime\]

Timestamp when the OAuth client was promoted to public visibility.

formatdate-time

redirect\_uris: Optional\[List\[str\]\]

Array of allowed redirect URIs for the client.

response\_types: Optional\[List\[Literal\["token", "id\_token", "code"\]\]\]

Array of OAuth response types the client is allowed to use.

One of the following:

"token"

"id\_token"

"code"

scopes: Optional\[List\[str\]\]

Array of OAuth scopes the client is allowed to request. Colon-delimited scopes are not accepted. Dot-delimited scopes are validated against available OAuth API scopes; simple identity scopes are allowed. Protocol scopes `offline_access` and `openid` are added or removed automatically based on `grant_types` and `response_types`.

token\_endpoint\_auth\_method: Optional\[Literal\["none", "client\_secret\_basic", "client\_secret\_post"\]\]

The authentication method the client uses at the token endpoint.

One of the following:

"none"

"client\_secret\_basic"

"client\_secret\_post"

tos\_uri: Optional\[str\]

URL that points to a terms of service document.

updated\_at: Optional\[datetime\]

Timestamp when the OAuth client was last updated.

formatdate-time

### Create OAuth Client

Python

HTTPHTTP

TypeScriptTypeScript

PythonPython

GoGo

TerraformTerraform

```
import os
from cloudflare import Cloudflare

client = Cloudflare(
    api_token=os.environ.get("CLOUDFLARE_API_TOKEN"),  # This is the default and can be omitted
)
oauth_client = client.iam.oauth_clients.create(
    account_id="023e105f4ecef8ad9ca31a8372d0c353",
    client_name="My OAuth App",
    grant_types=["authorization_code", "refresh_token"],
    redirect_uris=["https://example.com/callback"],
    response_types=["code"],
    scopes=["account.read"],
    token_endpoint_auth_method="client_secret_post",
)
print(oauth_client.client_id)
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "client_id": "a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4",
    "visibility": "private",
    "allowed_cors_origins": [
      "https://example.com"
    ],
    "client_name": "My OAuth App",
    "client_secret": "cf-oauth-secret-example",
    "client_uri": "https://example.com",
    "client_uri_verification": {
      "status": "in_progress",
      "text": "cloudflare_oauth_client_publisher=example"
    },
    "created_at": "2025-01-01T00:00:00Z",
    "grant_types": [
      "authorization_code",
      "refresh_token"
    ],
    "has_rotated_secret": false,
    "logo_uri": "https://example.com/logo.png",
    "optional_scopes": [
      "account.write"
    ],
    "policy_uri": "https://example.com/privacy",
    "post_logout_redirect_uris": [
      "https://example.com/logout"
    ],
    "promoted_at": "2026-05-13T12:00:00Z",
    "redirect_uris": [
      "https://example.com/callback"
    ],
    "response_types": [
      "code"
    ],
    "scopes": [
      "account.read"
    ],
    "token_endpoint_auth_method": "client_secret_post",
    "tos_uri": "https://example.com/tos",
    "updated_at": "2025-01-01T00:00:00Z"
  }
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "client_id": "a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4",
    "visibility": "private",
    "allowed_cors_origins": [
      "https://example.com"
    ],
    "client_name": "My OAuth App",
    "client_secret": "cf-oauth-secret-example",
    "client_uri": "https://example.com",
    "client_uri_verification": {
      "status": "in_progress",
      "text": "cloudflare_oauth_client_publisher=example"
    },
    "created_at": "2025-01-01T00:00:00Z",
    "grant_types": [
      "authorization_code",
      "refresh_token"
    ],
    "has_rotated_secret": false,
    "logo_uri": "https://example.com/logo.png",
    "optional_scopes": [
      "account.write"
    ],
    "policy_uri": "https://example.com/privacy",
    "post_logout_redirect_uris": [
      "https://example.com/logout"
    ],
    "promoted_at": "2026-05-13T12:00:00Z",
    "redirect_uris": [
      "https://example.com/callback"
    ],
    "response_types": [
      "code"
    ],
    "scopes": [
      "account.read"
    ],
    "token_endpoint_auth_method": "client_secret_post",
    "tos_uri": "https://example.com/tos",
    "updated_at": "2025-01-01T00:00:00Z"
  }
}
```