PUT /api/v2/oauth/clients/{clientId} returning 400 Bad Request

Trying to update a client’s redirect URIs via the API. The request is formatted correctly but keeps failing. It’s weird because the same payload worked in the dev org.

The clientId is valid. Permissions are confirmed. The error is CRITICAL and blocking the deployment.

{
 "code": "bad.request",
 "status": 400,
 "detail": "Invalid request body. The provided redirectUris are not allowed for this client type.",
 "message": "Bad Request"
}

Testing with GET /api/v2/oauth/clients/{clientId} first to verify current state. No issues there. The PUT call is where it breaks.

Redirect URIs are standard HTTPS. No wildcards used. The client is a standard confidential client.

PUT /api/v2/oauth/clients/12345-abcde-67890

The request body is just the updated URI list. It’s being sent as application/json.

1 Like

Fun one today. Think of the PUT request as a full replacement of a form- if you leave a field blank, the system thinks you’re trying to delete that data rather than ignore it. You can’t just send the URIs. You’ve got to send the full object.

PUT /api/v2/oauth/clients/{clientId}
{
 "name": "Existing Client Name",
 "redirectUris": ["https://new-url.com/callback"]
}
1 Like