Skip to main content
DELETE
TypeScript

Path Parameters

webhookOauthId
string<uuid>
required

The unique identifier of the OAuth credentials

Example:

"44fcead0-7053-4831-a53a-df7fb90d440f"

Query Parameters

forceDelete
boolean
default:false

Delete the credentials even while webhooks still reference them, detaching those webhooks instead of refusing. Leave it unset, or false, to get a 409 Conflict whenever anything still references the credentials.

Response

The deleted OAuth credentials, plus the ids of any webhooks that were detached from them

The deleted OAuth credential set, plus the ids of any webhooks the delete detached from it. Webhooks are only detached by forceDelete=true; without it a delete is refused with 409 while anything still references the credentials.

id
string<uuid>
required

The id of the OAuth credentials. Pass this as a webhook's webhookOauthId to attach them.

Example:

"123e4567-e89b-12d3-a456-426614174000"

name
string
required

The label given to this credential set.

Example:

"Production treasury gateway"

clientId
string
required

OAuth client ID used to authenticate with the token endpoint.

Example:

"my-client-id"

url
string
required

Token endpoint URL.

Example:

"https://auth.example.com/oauth/token"

authMethod
string
default:client_secret_basic
required

How the client credentials are presented to the token endpoint: client_secret_basic, client_secret_post or client_secret_jwt. Credentials created without this field report client_secret_basic, which is what they use.

Example:

"client_secret_basic"

createdAt
integer<int64>
required

The date and time the OAuth credentials were created, in milliseconds.

Example:

1625097600000

updatedAt
integer<int64>
required

The date and time the OAuth credentials were last updated, in milliseconds.

Example:

1625097600000

detachedWebhookIds
string<uuid>[]
required

Webhooks whose webhookOauthId was cleared. The webhooks themselves are not deleted and keep delivering, just without an Authorization header. Empty unless forceDelete=true detached something.

Example:
customJwtClaims
string[]

Names of the additional claims placed in the JWT assertion. Claim values are write-only and are never returned. Absent when no custom claims are configured.

Example:
customBodyParams
string[]

Names of the additional parameters added to the token request body. Parameter values are write-only and are never returned. Absent when no custom parameters are configured.

Example:
customHeaders
string[]

Names of the additional HTTP headers added to the token request sent to the authorization server — not to the webhook delivery, which has its own separate customHeaders. Header values are write-only and are never returned. Absent when no custom headers are configured.

Example:
mtlsClientSignedCert
string

PEM-encoded client certificate used for mTLS when fetching OAuth tokens.

Example:

"-----BEGIN CERTIFICATE-----\n...\n-----END CERTIFICATE-----"