Skip to main content

Attributes

Version: 2.22.0

AbsoluteRefreshTokenLifetime​

Maximum lifetime of a refresh token in seconds. Defaults to 2592000 seconds / 30 days

Data Type​

INT

Default Values​
Default Value
2592000

AccessFailedCount​

The number of failed login attempts for the current user.

Data Type​

INT

Default Values​
Default Value
0

AccessTokenLifetime​

Lifetime of access token in seconds (defaults to 3600 seconds / 1 hour)

Data Type​

INT

Default Values​
Default Value
3600

AccessTokenType​

Specifies whether the access token is a reference token or a self contained JWT token (defaults to Jwt).

Data Type​

ENUM: System.Identity-2/TokenType

Default Values​
Default Value
0

AllowAccessTokensViaBrowser​

Controls whether access tokens are transmitted via the browser for this client

Data Type​

BOOLEAN

Default Values​
Default Value
false

AllowOfflineAccess​

Specifies whether this client can request refresh tokens (defaults to false)

Data Type​

BOOLEAN

Default Values​
Default Value
false

AllowPlainTextPkce​

Specifies whether a proof key can be sent using plain method (not recommended and defaults to false).

Data Type​

BOOLEAN

Default Values​
Default Value
false

AllowRememberConsent​

Specifies whether user can choose to store consent decisions (defaults to true)

Data Type​

BOOLEAN

Default Values​
Default Value
true

AllowSelfRegistration​

Controls whether new users can self-register via this identity provider. When false, only existing users can authenticate.

Data Type​

BOOLEAN

Default Values​
Default Value
true

AllowedAccessTokenSigningAlgorithms​

Signing algorithm for access token. If empty, will use the server default signing algorithm.

Data Type​

STRING_ARRAY

Default Values​
Default Value

AllowedCorsOrigins​

Gets or sets the allowed CORS origins for JavaScript clients. Each entry carries a Source marker (see RedirectUris). Runtime-state for the same reason (AB#5210).

Data Type​

Array of RECORD_ARRAY: System.Identity-2/ClientUriEntry

Default Values​
Default Value

AllowedGrantTypes​

Specifies the allowed grant types (legal combinations of AuthorizationCode, Implicit, Hybrid, ResourceOwner, ClientCredentials). Defaults to Implicit.

Data Type​

STRING_ARRAY


AllowedIdentityTokenSigningAlgorithms​

Signing algorithm for identity token. If empty, will use the server default signing algorithm.

Data Type​

STRING_ARRAY

Default Values​
Default Value

AllowedScopes​

Specifies the api scopes that the client is allowed to request. If empty, the client can't access any scope

Data Type​

STRING_ARRAY

Default Values​
Default Value

AlwaysIncludeUserClaimsInIdToken​

When requesting both an id token and access token, should the user claims always be added to the id token instead of requiring the client to use the userinfo endpoint.

Data Type​

BOOLEAN

Default Values​
Default Value
false

AlwaysSendClientClaims​

Gets or sets a value indicating whether client claims should be always included in the access tokens - or only for client credentials flow.

Data Type​

BOOLEAN

Default Values​
Default Value
false

Authority​

Gets or sets the URI of the provider, or discovery endpoint for OpenID Connect discovery.

Data Type​

STRING


AuthorizationCodeLifetime​

Lifetime of authorization code in seconds (defaults to 300 seconds / 5 minutes)

Data Type​

INT

Default Values​
Default Value
300

AuthorizationRtId​

RtId of the OAuthAuthorization this token belongs to.

Data Type​

STRING


AuthorizationType​

OpenIddict authorization type (permanent or ad-hoc).

Data Type​

STRING


AutoProvisionInChildTenants​

When true, the client is auto-provisioned (mirrored) into every new child tenant of the tenant it lives in. Enables a single client identity (e.g. CI/CD service) to reach many tenants without per-tenant manual setup.

Data Type​

BOOLEAN

Default Values​
Default Value
false

BackChannelLogoutSessionRequired​

Specifies if the user's session id should be sent to the BackChannelLogoutUri. Defaults to true.

Data Type​

BOOLEAN

Default Values​
Default Value
true

BackChannelLogoutUri​

Specifies logout URI at client for HTTP back-channel based logout.

Data Type​

STRING


ChildTenantId​

The tenant ID of the child tenant in a parent-child mirror relationship.

Data Type​

STRING


CibaLifetime​

The backchannel authentication request lifetime in seconds.

Data Type​

INT


ClaimType​

The type of the claim.

Data Type​

STRING


ClaimValue​

The value of the claim.

Data Type​

STRING


ClaimValueType​

The value type of the claim.

Data Type​

STRING


ClientClaims​

Gets or sets the client claims to be sent to the user info endpoint.

Data Type​

Array of RECORD_ARRAY: System.Identity-2/ClientClaim

Default Values​
Default Value

ClientClaimsPrefix​

Gets or sets a value to prefix it on client claim types. Defaults to client_.

Data Type​

STRING

Default Values​
Default Value
client_

ClientId​

Data Type​

STRING


ClientSecret​

Gets or sets the client secret of the application.

Data Type​

STRING

Default Values​
Default Value

ClientUri​

URI to further information about client (used on consent screen). Runtime-state for the same reason as RedirectUris (AB#5210).

Data Type​

STRING


ConsentLifetime​

Lifetime of a user consent in seconds. Defaults to null (no expiration)

Data Type​

INT


ConsumedDateTime​

Data Type​

DATE_TIME


CoordinateLifetimeWithUserSession​

When enabled, the client's token lifetimes (e.g. refresh tokens) will be tied to the user's session lifetime.

Data Type​

BOOLEAN


CreationDateTime​

Data Type​

DATE_TIME


DPoPClockSkew​

Clock skew used in validating the client's DPoP proof token 'iat' claim value. Defaults to 5 minutes.

Data Type​

TIME_SPAN

Default Values​
Default Value
00:05:00

DPoPValidationMode​

Enum setting to control validation for the DPoP proof token expiration.

Data Type​

INT

Default Values​
Default Value
1

Data​

Data Type​

STRING


DefaultGroupRtId​

Optional RtId of a group to which new users are automatically added on first login via this provider.

Data Type​

STRING


DeviceCodeLifetime​

Specifies the lifetime (in seconds) of the device code. Defaults to 300 seconds / 5 minutes.

Data Type​

INT

Default Values​
Default Value
300

DisplayName​

Optional display name of the user owning the session.

Data Type​

STRING


DynamicRegistration​

When true, this Client was created at runtime via RFC 7591 Dynamic Client Registration (an interactive MCP client such as Claude Code self-registering), not seeded by a blueprint nor created via the System API. Distinguishes dynamic clients for lifecycle handling (TTL cleanup, per-tenant cap) and cleanup-gate protection. Default false = every pre-existing and operator-created client.

Data Type​

BOOLEAN

Default Values​
Default Value
false

DynamicRegistrationExpiresAt​

UTC expiry of a dynamically-registered Client (RFC 7591). The cleanup sweep erases dynamic clients past this instant. Unset for non-dynamic clients.

Data Type​

DATE_TIME


Email​

The email address of the user.

Data Type​

STRING


EmailConfirmed​

Indicates if the email address of the user has been confirmed.

Data Type​

BOOLEAN

Default Values​
Default Value
false

EmailDomainPattern​

Email domain pattern to match (e.g., "meshmakers.com"). Matched against the domain part of the user's email.

Data Type​

STRING


EnableLocalLogin​

Specifies if this client can use local accounts. Defaults to true.

Data Type​

BOOLEAN

Default Values​
Default Value
true

EnrolledAt​

UTC timestamp when the identifier was first enrolled for the user.

Data Type​

DATE_TIME


EnrollmentTrust​

The stored ENROLLMENT trust dimension (None/Weak/Strong) - does the identifier belong to the user? Raised to Strong by the sibling enrollment WIs on a proven OTP/cert/IdP enrollment. Defaults to None.

Data Type​

ENUM: System.Identity-2/TrustLevel

Default Values​
Default Value
0

ExpirationDateTime​

Data Type​

DATE_TIME


FirstName​

The first name of the user.

Data Type​

STRING


FriendlyName​

Friendly name of an ASP.NET Data Protection key-ring element (format key-{guid}).

Data Type​

STRING


FrontChannelLogoutSessionRequired​

Specifies if the user's session id should be sent to the FrontChannelLogoutUri. Defaults to true.

Data Type​

BOOLEAN

Default Values​
Default Value
true

FrontChannelLogoutUri​

Specifies logout URI at client for HTTP front-channel based logout.

Data Type​

STRING


GrantKey​

Data Type​

STRING


GrantType​

Data Type​

STRING


GroupDescription​

An optional description of the group's purpose.

Data Type​

STRING


GroupName​

The display name of the group.

Data Type​

STRING


Host​

Gets or sets the host address of the identity provider.

Data Type​

STRING


IdentifierKind​

The kind of external identifier (PhoneNumber, EmailAddress, EntraIdObjectId, ClientCertificateFingerprint).

Data Type​

ENUM: System.Identity-2/IdentifierKind

Default Values​
Default Value
0

IdentifierSource​

Provenance of the binding (SelfService, Admin, IdentityProvider). Defaults to SelfService.

Data Type​

ENUM: System.Identity-2/IdentifierSource

Default Values​
Default Value
0

IdentifierValue​

The normalized external identifier value (E.164 phone number, normalized e-mail address, EntraID object id, or certificate fingerprint).

Data Type​

STRING


IdentityProviderRestrictions​

Specifies which external IdPs can be used with this client (if list is empty all IdPs are allowed). Defaults to empty.

Data Type​

STRING_ARRAY

Default Values​
Default Value

IdentityRoleIds​

Data Type​

STRING_ARRAY

Default Values​
Default Value

IdentityTokenLifetime​

Lifetime of identity token in seconds (defaults to 300 seconds / 5 minutes)

Data Type​

INT

Default Values​
Default Value
300

IncludeJwtId​

Value indicating whether JWT access tokens should include an identifier. Defaults to true.

Data Type​

BOOLEAN

Default Values​
Default Value
true

InitiateLoginUri​

Gets of sets a URI that can be used to initiate login from the IdentityServer host or a third party.

Data Type​

STRING


IsEmphasized​

Specifies whether the consent screen will emphasize this scope (if the consent screen wants to implement such a feature). Defaults to false.

Data Type​

BOOLEAN

Default Values​
Default Value
false

IsRequired​

Specifies whether the user can de-select the scope on the consent screen (if the consent screen wants to implement such a feature). Defaults to false.

Data Type​

BOOLEAN

Default Values​
Default Value
false

LastName​

The last name of the user.

Data Type​

STRING


LastVerifiedAt​

UTC timestamp of the most recent successful verification of the identifier.

Data Type​

DATE_TIME


LockoutEnabled​

Flag indicating if the user could be locked out.

Data Type​

BOOLEAN

Default Values​
Default Value
false

LockoutEnd​

The date and time, in UTC, when any user lockout ends.

Data Type​

DATE_TIME_OFFSET


LoginProvider​

Data Type​

STRING


LogoUri​

URI to client logo (used on consent screen)

Data Type​

STRING


MappedRoleIds​

The role IDs assigned to the mapped user in this tenant.

Data Type​

STRING_ARRAY


NormalizedEmail​

The normalized email address of the user.

Data Type​

STRING


NormalizedGroupName​

The normalized (uppercase) group name for case-insensitive lookup.

Data Type​

STRING


NormalizedName​

The normalized name.

Data Type​

STRING


NormalizedUserName​

The normalized user name.

Data Type​

STRING


PairWiseSubjectSalt​

Gets or sets a salt value used in pair-wise subjectId generation for users of this client.

Data Type​

STRING


ParentTenantId​

The tenant ID of the parent tenant that provides user authentication.

Data Type​

STRING


PasswordHash​

The salted and hashed representation of the password for this user.

Data Type​

STRING


Payload​

Protected token payload for reference tokens.

Data Type​

STRING


PermissionId​

Data Type​

STRING


PhoneNumber​

The phone number of the user.

Data Type​

STRING


PhoneNumberConfirmed​

Indicates if the phone number of the user has been confirmed.

Data Type​

BOOLEAN

Default Values​
Default Value
false

PolicyActions​

Granted actions: Read, Write, Delete.

Data Type​

STRING_ARRAY

Default Values​
Default Value

PolicyEnforcementMode​

Enforce applies the policy; AuditOnly only logs violations without filtering or rejecting (migration mode).

Data Type​

ENUM: System.Identity-2/DataPolicyEnforcementMode

Default Values​
Default Value
0

PolicyScope​

All grants access to every entity of the target types; OwnedOnly restricts to entities created by the caller (RtCreatedBy).

Data Type​

ENUM: System.Identity-2/DataPolicyScope

Default Values​
Default Value
0

PollingInterval​

The backchannel authentication request polling interval in seconds.

Data Type​

INT


Port​

Gets or sets the host port of the identity provider.

Data Type​

INT

Default Values​
Default Value
636

PostLogoutRedirectUris​

Specifies allowed URIs to redirect to after logout. Each entry carries a Source marker (see RedirectUris). Runtime-state for the same reason (AB#5210).

Data Type​

Array of RECORD_ARRAY: System.Identity-2/ClientUriEntry

Default Values​
Default Value

PreferredChannelBindingId​

The rtId of the VerifiedExternalIdentifier chosen as preferred outbound channel target for system-initiated messages (null = no preference). The channel kind is derived from the referenced binding. Set via self-service, restricted to the user's own valid bindings.

Data Type​

STRING


Properties​

Additional OpenIddict properties as a JSON object.

Data Type​

STRING


ProtocolType​

Data Type​

STRING

Default Values​
Default Value
oidc

ProviderDisplayName​

Data Type​

STRING


ProviderKey​

Data Type​

STRING


ProvisionedAt​

UTC timestamp when the mirror was provisioned.

Data Type​

DATE_TIME


ProvisionedByParentTenantId​

When set on a Client living in a child tenant, marks this record as a mirror of a parent-tenant client identified by the given tenant id. Sub-tenant admins surface this as a read-only "Provisioned by parent tenant" indicator; the operator cannot edit the client locally — changes must go through the parent.

Data Type​

STRING


RedemptionDateTime​

Point in time a single-use token was redeemed.

Data Type​

DATE_TIME


RedirectUris​

Specifies allowed URIs to return tokens or authorization codes to. Each entry carries a Source marker so local-dev / operator overlay URIs can coexist with base (blueprint) URIs. Runtime-state (AB#5210, same reasoning as Hostname in AB#4706): the productive URI is the public hostname of the deployment, which is tenant-specific and operator-managed and which no seed can derive - ${octo.domain} is the PLATFORM domain while apps are served from their own. A blueprint re-apply therefore preserves what the operator set instead of resetting it to the seeded default and silently breaking sign-in with invalid_redirect_uri. Deliberate trade-off - changing this URI in a seed no longer reaches tenants that already hold the client; use ApplyClientOverlay or set it explicitly.

Data Type​

Array of RECORD_ARRAY: System.Identity-2/ClientUriEntry

Default Values​
Default Value

ReferenceId​

Hashed reference identifier used to look up reference tokens (device/user codes).

Data Type​

STRING


RefreshTokenExpiration​

Gets or sets a value indicating whether the access token (and its claims) should be updated on a refresh token request.

Data Type​

ENUM: System.Identity-2/TokenExpiration

Default Values​
Default Value
1

RefreshTokenUsage​

Gets or sets a value indicating whether the refresh token should be updated on a refresh token request.

Data Type​

ENUM: System.Identity-2/TokenUsage


RenewalDateTime​

UTC timestamp of the last sliding-expiration renewal of the session.

Data Type​

DATE_TIME


RequireClientSecret​

Data Type​

BOOLEAN

Default Values​
Default Value
true

RequireConsent​

Specifies whether a consent screen is required. Defaults to false.

Data Type​

BOOLEAN

Default Values​
Default Value
false

RequireDPoP​

Specifies whether a DPoP (Demonstrating Proof-of-Possession) token is required to be used by this client (defaults to false)

Data Type​

BOOLEAN

Default Values​
Default Value
false

RequirePkce​

Specifies whether a proof key is required for authorization code based token requests (defaults to true).

Data Type​

BOOLEAN

Default Values​
Default Value
true

RequireRequestObject​

Specifies whether the client must use a request object on authorize requests (defaults to false).

Data Type​

BOOLEAN

Default Values​
Default Value
false

RequireResourceIndicator​

Data Type​

BOOLEAN

Default Values​
Default Value
false

RequiredMessageAuthentication​

Channel expectation for the per-message trust dimension - whether the channel behind this binding is expected to authenticate every message (Signal-verified / DKIM-valid). The per-message trust itself is not stored; the resolver combines it per call with EnrollmentTrust.

Data Type​

BOOLEAN

Default Values​
Default Value
false

ResetPasswordOnLogin​

Force the user to change the password after the next login.

Data Type​

BOOLEAN

Default Values​
Default Value
true

ResourceClaims​

Data Type​

STRING_ARRAY

Default Values​
Default Value

RoleClaims​

The claims of a role.

Data Type​

Array of RECORD_ARRAY: System.Identity-2/RoleClaim


RoleId​

Data Type​

STRING


RoleIds​

The id of roles the user is a member of.

Data Type​

STRING_ARRAY


Scheme​

The ASP.NET authentication scheme that produced the session ticket.

Data Type​

STRING


Scopes​

Models the scopes this API resource allows.

Data Type​

STRING_ARRAY


SecretHashVersion​

Monotonic counter incremented on every secret rotation of the parent client. Used to detect mirrors that fell behind on a rotation.

Data Type​

INT

Default Values​
Default Value
0

SecretType​

Data Type​

STRING

Default Values​
Default Value
SharedSecret

Secrets​

Data Type​

Array of RECORD_ARRAY: System.Identity-2/Secret

Default Values​
Default Value

SecurityStamp​

A random value that should change whenever a users credentials have been compromised.

Data Type​

STRING


SessionId​

Data Type​

STRING


SessionKey​

Unique key of a server-side session (the only value stored in the browser cookie).

Data Type​

STRING


ShowInDiscoveryDocument​

Gets or sets a value indicating whether the client will be shown in the discovery document. Defaults to true.

Data Type​

BOOLEAN

Default Values​
Default Value
true

SlidingRefreshTokenLifetime​

Sliding lifetime of a refresh token in seconds. Defaults to 1296000 seconds / 15 days

Data Type​

INT

Default Values​
Default Value
1296000

Source​

Provenance marker on a ClientUriEntry. "base" entries were authored by the blueprint seed (or by the cross-service identity-bootstrap consumer) and get rewritten on every blueprint re-apply. "api" entries were added by an operator through the public REST API and survive re-applies. "overlay:<name>" entries were added by a local-dev or operator overlay cmdlet and also survive re-applies; they are filtered out of DumpTenant --clean exports while base + api survive the export.

Data Type​

STRING

Default Values​
Default Value
base

SourceTenantId​

The tenant ID where the user's account resides.

Data Type​

STRING


SourceUserId​

The RtId of the user in the source tenant.

Data Type​

STRING


SourceUserName​

The username for display purposes.

Data Type​

STRING


Status​

OpenIddict entry status (valid, inactive, redeemed, rejected, revoked).

Data Type​

STRING


SubjectId​

Data Type​

STRING


SubjectIds​

Data Type​

STRING_ARRAY

Default Values​
Default Value

TargetCkTypeIds​

CK type ids or collection roots the policy protects; derived types inherit the policy.

Data Type​

STRING_ARRAY

Default Values​
Default Value

TargetGroupRtId​

RtId of the group to which matching users are added.

Data Type​

STRING


Ticket​

The serialized, data-protected ASP.NET authentication ticket of a server-side session.

Data Type​

STRING


TokenType​

OpenIddict token type (authorization_code, refresh_token, device_code, user_code, ...).

Data Type​

STRING


TwoFactorEnabled​

Indicates if two factor authentication is enabled for the user.

Data Type​

BOOLEAN

Default Values​
Default Value
false

UpdateAccessTokenClaimsOnRefresh​

Indicates whether the access token (and its claims) should be updated on a refresh token request.

Data Type​

BOOLEAN

Default Values​
Default Value
false

Uri​

A single URI value carried by a ClientUriEntry record.

Data Type​

STRING


UseTls​

Gets or sets if the connection to the identity provider should use TLS. Defaults to true.

Data Type​

BOOLEAN

Default Values​
Default Value
true

UserBaseDn​

Gets or sets the base DN of the user.

Data Type​

STRING


UserClaims​

The claims of the user.

Data Type​

Array of RECORD_ARRAY: System.Identity-2/UserClaim


UserCodeType​

Specifies the user code type for the device flow. Defaults to null.

Data Type​

STRING


UserId​

Data Type​

STRING


UserLogins​

The existing logins of the user.

Data Type​

Array of RECORD_ARRAY: System.Identity-2/UserLogin


UserName​

The user name.

Data Type​

STRING


UserNameAttribute​

Gets or sets the name of the user attribute.

Data Type​

STRING


UserSsoLifetime​

Lifetime of user's single sign-on session (in seconds). Defaults to null (no expiration).

Data Type​

INT


UserTokens​

The tokens of the user.

Data Type​

Array of RECORD_ARRAY: System.Identity-2/UserToken


ValidUntil​

UTC not-after of an enrolled client certificate (ClientCertificateFingerprint kind only); a binding whose ValidUntil is in the past is treated as invalid. Null for other kinds.

Data Type​

DATE_TIME


Value​

Data Type​

STRING


XmlData​

The raw XML payload of a Data Protection key-ring element.

Data Type​

STRING