---
title: "Service: /oauth/members/{member}/clients/{client} [PATCH]"
source: https://dev.pageseeder.com/api/services/oauth-client-PATCH.html
description: "Updates an OAuth client with configurable parameters including tokens, URIs, scopes, and credentials. Members can modify their own clients; administrators can update any client. Returns updated client details in XML format."
last_updated: 2026-09-02T11:36:20+10:00
document_type: api_endpoint
operation_id: oauth-PATCH
resource_id: oauth
path_template: /oauth/members/{member}/clients/{client}
http_method: PATCH
api_category: oauth
implementation_version: 6.3000
api_since: 5.8900
deprecated_since: null
obsolete_since: null
api_support: experimental
cache_control: N/A
generated_at: 2026-09-02
tokens: ~810
---

# /oauth/members/\{member\}/clients/\{client\} \[PATCH\]

## Description

Updates an OAuth [client](../elements/element_client.md).

If the client URI changes, this service updates the CORS origin accordingly.

## Parameters

| Name | Description | Required | Type | Default value |
| --- | --- | --- | --- | --- |
| access-token-max-age | The max age of the access tokens in seconds | no | long |  |
| app | The name of the app (informational) | no | string |  |
| client-secret | The client secret | no | string |  |
| client-uri | The URL for the client app (informational) | no | url |  |
| confidential | Whether the client is capable of maintaining confidentiality of credentials | no | boolean |  |
| description | The description of this client (informational) | no | string |  |
| grant-type | The grant type allowed for this client | no | enum |  |
| identifier | The OAuth 2.0 client ID - 16 digit hexadecimal number (admin only) | no | string |  |
| member | The member ID or username for this client (admin only) | no | string |  |
| name | The name of the client (informational) | no | string |  |
| redirect-uri | The redirection URI specific to this client | no | url |  |
| refresh-token-max-age | The max age of the refresh tokens in seconds | no | long |  |
| scope | A space separated list of [scopes](../../reference/glossary/oauth_scopes.md) allowed for this client e.g. openid profile email | no | string |  |
| webhook-secret | The secret used for signing webhook requests (between 24 and 64 characters long) | no | string |  |

The valid grant types are: `authorization_code|password|client_credentials`

> **Obsolete:** Support for the `implicit` grant type has been removed in version 6.

## Permission

Members can update their own OAuth client but cannot change its member or client ID (`member` and `identifier` parameters).

An administrators can update any client.

## Response

This service returns a [\<client\> element](../elements/element_client.md) wrapped in a `<client-modification>`.

```xml
<client-modification>
  <client id="1"
          identifier="2aa92c5a79baf3fe"
          requires-consent="false"
          confidential="false"
          name="My app"
          grant-type="authorization_code"
          [created="2020-03-08T12:34:00+10:00"]
          [modified="2020-03-10T11:24:00+10:00"]
          [last-token="2020-05-10T10:28:00+10:00"]
          [app="Timesheet"]
          [webhook-secret="S0meP@ssw0d"]
          [redirect-uri="http://example.org/login"]
          [description="My example timesheet"]
          [client-uri="http://example.org"]
          [scope="openid profile email"]
          access-token-max-age="7200"
          refresh-token-max-age="0">
    <member id="45" ...>
      <fullname>John Smith</fullname>
    </member>
  </client>
</client-modification>
```

## Error Handling

| HTTP code | Condition |
| --- | --- |
| 400 | The name is already in use |
| 400 | Maximum number of clients for this member has been reached |
| 400 | Invalid grant-type, member or client-uri or redirect-uri parameter |
| 403 | The client is not owned by the member |
| 400 | No matching client for ID |

The maximum number of clients a non-administrator member can have is **10**.

