---
title: "OAuth"
url: "https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8/schemas/OAuth"
---

> Full API specification: https://us-prod.jeffyongtaotang.com/apis/konnect-service-catalog-1/versions/cdbef9b7-686c-4189-bbc8-55c727a972e8.md

# OAuth

Defines the OAuth 2.0 authorization strategy used by an integration. This schema provides all necessary information for the platform to initiate and manage OAuth-based authorization flows on behalf of customers.

## OpenAPI definition

```yaml
openapi: 3.0.3
info:
  title: Konnect Service Catalog
  version: 1.3.0
servers:
  - url: https://us.api.konghq.com/v1
    description: United-States Production region
  - url: https://eu.api.konghq.com/v1
    description: Europe Production region
  - url: https://au.api.konghq.com/v1
    description: Australia Production region
  - url: https://me.api.konghq.com/v1
    description: Middle-East Production region
  - url: https://in.api.konghq.com/v1
    description: India Production region
  - url: https://sg.api.konghq.com/v1
    description: Singapore Production region
components:
  schemas:
    OAuth:
      type: object
      description: >
        Defines the OAuth 2.0 authorization strategy used by an integration.

        This schema provides all necessary information for the platform to
        initiate

        and manage OAuth-based authorization flows on behalf of customers.
      required:
        - type
        - config
      properties:
        type:
          type: string
          enum:
            - oauth
          x-terraform-transform-const: true
        overridable_config:
          description: >
            A list of field names from the `config` object (e.g., `client_id`,
            `authorization_endpoint`, etc)

            that can be overridden on a per-customer basis. When a field is
            listed here, the catalog allows

            customer-defined values to take precedence over the default
            configuration provided by the integration.

            This supports flexible deployment models, including both SaaS-based
            and self-hosted OAuth authorization flows.
          type: array
          items:
            type: string
            enum:
              - client_id
              - client_secret
              - authorization_endpoint
              - token_endpoint
        config:
          type: object
          required:
            - grant_type
            - client_id
            - authorization_endpoint
            - token_endpoint
            - scope
            - rolling_refresh_exp_seconds
          properties:
            grant_type:
              type: string
              enum:
                - authorization_code
              description: >
                The OAuth 2.0 grant type used for authorization (e.g.,
                `authorization_code`).

                Determines the flow the integration uses to request access
                tokens.
            client_id:
              type: string
              example: d745213a-b7e8-4998-abe3-41f164001970
              description: The OAuth client identifier registered with the integration
                provider.
            authorization_endpoint:
              type: object
              required:
                - url
              properties:
                url:
                  type: string
                  format: uri
                  example: https://identity.service.com/oauth/authorize
                  description: The URL where users are redirected to authorize access.
            token_endpoint:
              type: object
              required:
                - url
              properties:
                url:
                  type: string
                  format: uri
                  example: https://identity.service.com/oauth/token
                  description: The URL used to retrieve access tokens.
            scope:
              type: array
              items:
                type: string
              example:
                - read
                - write
              description: |
                A list of permission scopes requested by the integration.
                Defines what level of access the token will grant.
            scope_delimiter:
              type: string
              default: " "
              description: >
                A string used to separate multiple scopes in the `scope`
                parameter.
            rolling_refresh_exp_seconds:
              type: number
              nullable: true
              description: >
                Number of seconds before the refresh token grant can no longer
                be used to mint

                a new access token. Once expired clients must re-authenticate to
                restart the

                window interval.
              example: 15780000
```
