Create a service account
POST
/v1/oauth/clients
const url = 'https://api.adversarial.com/api/v1/oauth/clients';const options = { method: 'POST', headers: {cookie: 'arm-session=<arm-session>', 'Content-Type': 'application/json'}, body: '{"allowed_ips":["example"],"client_name":"example","expires_at":"2026-04-15T12:00:00Z","roles":["example"]}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.adversarial.com/api/v1/oauth/clients \ --header 'Content-Type: application/json' \ --cookie arm-session=<arm-session> \ --data '{ "allowed_ips": [ "example" ], "client_name": "example", "expires_at": "2026-04-15T12:00:00Z", "roles": [ "example" ] }'Creates a service account and issues its client_id and client_secret
for the client credentials grant. The secret is returned in this response
only and cannot be retrieved afterwards — store it before discarding the
response.
Authorizations
Section titled “Authorizations”Request Bodyrequired
Section titled “Request Bodyrequired”Media typeapplication/json
object
allowed_ips
IP/CIDR allowlist; null or empty = unrestricted
Array<string> | null
client_name
required
User-friendly name for the service account
string
expires_at
Optional expiration
string | null format: date-time
roles
required
Role names to assign to the service-account user. Case-insensitive; must be non-empty.
Array<string>
Examplegenerated
{ "allowed_ips": [ "example" ], "client_name": "example", "expires_at": "2026-04-15T12:00:00Z", "roles": [ "example" ]}Responses
Section titled “Responses”OAuth client created successfully
Media typeapplication/json
object
allowed_ips
Array<string> | null
client_id
required
string
client_name
required
string
client_secret
string | null
created_by
string | null format: uuid
created_date
required
string format: date-time
expires_at
string | null format: date-time
id
required
string format: uuid
last_used
string | null format: date-time
org_id
required
string format: uuid
revoked_at
string | null format: date-time
roles
required
Array<string>
user
required
The service-account user this key authenticates as — one user per key.
object
email
required
string
first_name
required
string
icon
Relative path to the user’s avatar endpoint, e.g.
"users/{id}/avatar?v={hash}". None when the user has no avatar.
string | null
id
required
string format: uuid
last_name
required
string
user_id
required
string format: uuid
Examplegenerated
{ "allowed_ips": [ "example" ], "client_id": "example", "client_name": "example", "client_secret": "example", "created_by": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "created_date": "2026-04-15T12:00:00Z", "expires_at": "2026-04-15T12:00:00Z", "id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "last_used": "2026-04-15T12:00:00Z", "org_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "revoked_at": "2026-04-15T12:00:00Z", "roles": [ "example" ], "user": { "email": "example", "first_name": "example", "icon": "example", "id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "last_name": "example" }, "user_id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0"}Invalid request
Unauthorized
Forbidden