Skip to content
Docs
Application Credentials

Create application credential

Create application credential

POST/zones/{zoneId}/application-credentials

Creates a new application credential

Path ParametersExpand Collapse
zoneId: string
Body ParametersJSONExpand Collapse
body: optional object { application_id, provider_id, type, subject } or object { application_id, type, identifier } or object { application_id, jwks_uri, type, identifier } or 2 more

Schema for creating a new application credential

Accepts one of the following:
IamApplicationCredentialCreateToken = object { application_id, provider_id, type, subject }

Schema for creating a token application credential

application_id: string

ID of the application this credential belongs to

provider_id: string

ID of the provider issuing tokens this credential verifies

type: "token"
subject: optional string

Subject identifier for the token. When omitted, any token from the provider is accepted without checking application-specific claims.

IamApplicationCredentialCreatePassword = object { application_id, type, identifier }

Schema for creating a password application credential

application_id: string

ID of the application this credential belongs to

type: "password"
identifier: optional string

Username for password credential, also used as OAuth 2.0 client ID (auto-generated if not provided)

IamApplicationCredentialCreatePublicKey = object { application_id, jwks_uri, type, identifier }

Schema for creating a public key application credential

application_id: string

ID of the application this credential belongs to

jwks_uri: string

JWKS URI to retrieve public keys from

formaturi
type: "public-key"
identifier: optional string

Client ID for public key credential, also used as OAuth 2.0 client ID (auto-generated if not provided)

IamApplicationCredentialCreateURL = object { application_id, identifier, type }

Schema for creating a URL application credential

application_id: string

ID of the application this credential belongs to

identifier: string

URL of the credential (must be a valid URL)

formaturi
type: "url"
IamApplicationCredentialCreatePublic = object { application_id, type, identifier }

Schema for creating a public application credential

application_id: string

ID of the application this credential belongs to

type: "public"
identifier: optional string

Identifier for public credential, also used as OAuth 2.0 client ID (auto-generated if not provided)

ReturnsExpand Collapse
Token = BaseFields { id, application_id, created_at, 5 more }

Token-based application credential

identifier: string

Identifier for this credential. For token type, this equals the subject value, or '*' when subject is not specified.

provider_id: string

ID of the provider issuing tokens verified by this credential

type: "token"
Deprecatedprovider: optional Provider { id, created_at, identifier, 12 more }

A Provider is a system that supplies access to Resources and allows actors (Users or Applications) to authenticate.

id: string

Unique identifier of the provider

created_at: string

Entity creation timestamp

formatdate-time
identifier: string

User specified identifier, unique within the zone

minLength1
maxLength2048
name: string

Human-readable name

minLength1
maxLength255
organization_id: string

Organization that owns this provider

owner_type: "platform" or "customer"

Who owns this provider. Platform-owned providers cannot be modified via API.

Accepts one of the following:
"platform"
"customer"
slug: string

URL-safe identifier, unique within the zone

minLength1
maxLength63
updated_at: string

Entity update timestamp

formatdate-time
zone_id: string

Zone this provider belongs to

client_id: optional string

OAuth 2.0 client identifier

client_secret_set: optional boolean

Indicates whether a client secret is configured

description: optional string

Human-readable description

maxLength2048
metadata: optional object { icon_url }

Provider metadata

icon_url: optional string

Icon URL

formaturi
maxLength2048
protocols: optional object { oauth2, openid }

Protocol-specific configuration

oauth2: optional object { issuer, authorization_endpoint, authorization_parameters, 10 more }

OAuth 2.0 protocol configuration

issuer: string

OIDC issuer URL used for discovery and token validation.

formaturi
authorization_endpoint: optional string
formaturi
authorization_parameters: optional map[string]

Custom query parameters appended to authorization redirect URLs. Use for non-standard providers (e.g. Google prompt=consent, access_type=offline).

authorization_resource_enabled: optional boolean

Whether to include the resource parameter in authorization requests.

authorization_resource_parameter: optional string

The resource parameter value to include in authorization requests. Defaults to "resource" when authorization_resource_enabled is true.

code_challenge_methods_supported: optional array of string
jwks_uri: optional string
formaturi
registration_endpoint: optional string
formaturi
scope_parameter: optional string

The query parameter name for scopes in authorization requests. Defaults to "scope". Slack v2 uses "user_scope".

scope_separator: optional string

The separator character for scope values. Defaults to " " (space). Slack v2 uses ",".

scopes_supported: optional array of string
token_endpoint: optional string
formaturi
token_response_access_token_pointer: optional string

Dot-separated path to the access token in the token response body. Defaults to "access_token". Slack v2 uses "authed_user.access_token".

openid: optional object { external_id_claim, scopes, single_logout_enabled, 2 more }

OpenID Connect protocol configuration

external_id_claim: optional string

Name of the OIDC claim carrying the stable external id used to correlate logins with externally provisioned (SCIM) users. Defaults to "sub". Set to "oid" for Entra, whose pairwise "sub" differs from the SCIM externalId.

scopes: optional array of string

Additional OIDC scopes to request from this provider during authentication (e.g. "groups"). Merged with the default scopes (openid, profile, email).

single_logout_enabled: optional boolean

When true, logging out of the zone propagates the logout to this provider's end_session_endpoint (RP-initiated logout). Defaults to false.

user_identifier_claim: optional string

Name of a top-level string claim in this provider's ID Token to use as the user identifier on user creation. When not set, the user's Keycard ID is used.

userinfo_endpoint: optional string
formaturi
type: optional "external" or "keycard-vault" or "keycard-sts"
Accepts one of the following:
"external"
"keycard-vault"
"keycard-sts"
subject: optional string

Subject identifier for the token. When null or omitted, any token from the provider is accepted without checking application-specific claims.

Password = BaseFields { id, application_id, created_at, 5 more }

Password-based application credential

identifier: string

Username for password credential, also used as OAuth 2.0 client ID

type: "password"
password: optional string

Password for credential (only returned on creation, store securely), also used as OAuth 2.0 client secret

PublicKey = BaseFields { id, application_id, created_at, 5 more }

Public key-based application credential

identifier: string

Client ID for public key credential, also used as OAuth 2.0 client ID

jwks_uri: string

JWKS URI to retrieve public keys from

formaturi
type: "public-key"
URL = BaseFields { id, application_id, created_at, 5 more }

URL-based application credential

identifier: string

URL of the credential (must be a valid URL)

formaturi
type: "url"
Public = BaseFields { id, application_id, created_at, 5 more }

Public credential (no secret storage)

identifier: string

Identifier for public credential, also used as OAuth 2.0 client ID

type: "public"

Create application credential

curl https://api.keycard.ai/zones/$ZONE_ID/application-credentials \
    -X POST \
    -H "Authorization: Bearer $KEYCARD_API_API_KEY"
{
  "id": "id",
  "application_id": "application_id",
  "created_at": "2019-12-27T18:11:19.117Z",
  "organization_id": "organization_id",
  "slug": "slug",
  "updated_at": "2019-12-27T18:11:19.117Z",
  "zone_id": "zone_id",
  "application": {
    "id": "id",
    "consent": "implicit",
    "created_at": "2019-12-27T18:11:19.117Z",
    "dependencies_count": 0,
    "identifier": "x",
    "name": "x",
    "organization_id": "organization_id",
    "owner_type": "platform",
    "slug": "slug",
    "updated_at": "2019-12-27T18:11:19.117Z",
    "zone_id": "zone_id",
    "description": "description",
    "metadata": {
      "docs_url": "https://example.com",
      "icon_url": "https://example.com"
    },
    "protocols": {
      "oauth2": {
        "post_logout_redirect_uris": [
          "https://example.com"
        ],
        "redirect_uris": [
          "https://example.com"
        ]
      }
    }
  },
  "identifier": "identifier",
  "provider_id": "provider_id",
  "type": "token",
  "provider": {
    "id": "id",
    "created_at": "2019-12-27T18:11:19.117Z",
    "identifier": "x",
    "name": "x",
    "organization_id": "organization_id",
    "owner_type": "platform",
    "slug": "slug",
    "updated_at": "2019-12-27T18:11:19.117Z",
    "zone_id": "zone_id",
    "client_id": "client_id",
    "client_secret_set": true,
    "description": "description",
    "metadata": {
      "icon_url": "https://example.com"
    },
    "protocols": {
      "oauth2": {
        "issuer": "https://example.com",
        "authorization_endpoint": "https://example.com",
        "authorization_parameters": {
          "foo": "string"
        },
        "authorization_resource_enabled": true,
        "authorization_resource_parameter": "authorization_resource_parameter",
        "code_challenge_methods_supported": [
          "string"
        ],
        "jwks_uri": "https://example.com",
        "registration_endpoint": "https://example.com",
        "scope_parameter": "scope_parameter",
        "scope_separator": "scope_separator",
        "scopes_supported": [
          "string"
        ],
        "token_endpoint": "https://example.com",
        "token_response_access_token_pointer": "token_response_access_token_pointer"
      },
      "openid": {
        "external_id_claim": "external_id_claim",
        "scopes": [
          "string"
        ],
        "single_logout_enabled": true,
        "user_identifier_claim": "user_identifier_claim",
        "userinfo_endpoint": "https://example.com"
      }
    },
    "type": "external"
  },
  "subject": "subject"
}
Returns Examples
{
  "id": "id",
  "application_id": "application_id",
  "created_at": "2019-12-27T18:11:19.117Z",
  "organization_id": "organization_id",
  "slug": "slug",
  "updated_at": "2019-12-27T18:11:19.117Z",
  "zone_id": "zone_id",
  "application": {
    "id": "id",
    "consent": "implicit",
    "created_at": "2019-12-27T18:11:19.117Z",
    "dependencies_count": 0,
    "identifier": "x",
    "name": "x",
    "organization_id": "organization_id",
    "owner_type": "platform",
    "slug": "slug",
    "updated_at": "2019-12-27T18:11:19.117Z",
    "zone_id": "zone_id",
    "description": "description",
    "metadata": {
      "docs_url": "https://example.com",
      "icon_url": "https://example.com"
    },
    "protocols": {
      "oauth2": {
        "post_logout_redirect_uris": [
          "https://example.com"
        ],
        "redirect_uris": [
          "https://example.com"
        ]
      }
    }
  },
  "identifier": "identifier",
  "provider_id": "provider_id",
  "type": "token",
  "provider": {
    "id": "id",
    "created_at": "2019-12-27T18:11:19.117Z",
    "identifier": "x",
    "name": "x",
    "organization_id": "organization_id",
    "owner_type": "platform",
    "slug": "slug",
    "updated_at": "2019-12-27T18:11:19.117Z",
    "zone_id": "zone_id",
    "client_id": "client_id",
    "client_secret_set": true,
    "description": "description",
    "metadata": {
      "icon_url": "https://example.com"
    },
    "protocols": {
      "oauth2": {
        "issuer": "https://example.com",
        "authorization_endpoint": "https://example.com",
        "authorization_parameters": {
          "foo": "string"
        },
        "authorization_resource_enabled": true,
        "authorization_resource_parameter": "authorization_resource_parameter",
        "code_challenge_methods_supported": [
          "string"
        ],
        "jwks_uri": "https://example.com",
        "registration_endpoint": "https://example.com",
        "scope_parameter": "scope_parameter",
        "scope_separator": "scope_separator",
        "scopes_supported": [
          "string"
        ],
        "token_endpoint": "https://example.com",
        "token_response_access_token_pointer": "token_response_access_token_pointer"
      },
      "openid": {
        "external_id_claim": "external_id_claim",
        "scopes": [
          "string"
        ],
        "single_logout_enabled": true,
        "user_identifier_claim": "user_identifier_claim",
        "userinfo_endpoint": "https://example.com"
      }
    },
    "type": "external"
  },
  "subject": "subject"
}