1. Home
  2. /
  3. Developer Guide
  4. /
  5. Connected Apps

Connected Apps

The Connected Apps module lets external applications (portals, ERPs, BI tools, .NET middleware, integration scripts…) authenticate against the Cirrus Shield REST API without storing a human user’s password. Before writing any code against the REST API (covered in the next section), your integration must be registered as a Connected App.

Navigation: Configuration → Connected Apps

This page lists every OAuth application registered for your organization, with its status (active/inactive) and last-used date. This is where an administrator creates a new app, or edits/disables/deletes an existing one.

From the list page, click New App.

Required fields (common to both client types):

FieldDescription
NameName shown on the consent screen. Max 100 characters.
Client TypeConfidential or Public — see “Client Types” below.
Allowed ScopesPermissions granted to the application — see “Available Scopes” below.

Additional fields for a Confidential client:

FieldDescription
Associated UserCirrus Shield account that provides the data context for machine-to-machine (M2M) calls.
Allowed IPsOptional — list of IPs or CIDR ranges allowed to call the token endpoint.
Access Token LifetimeValidity in seconds. Default: 3600s. Maximum: 86400s.

Additional fields for a Public client:

FieldDescription
Redirect URIsOne URI per line. Exact match required — no wildcards.
Access Token LifetimeDefault: 900s (15 min) for the user flow.
Refresh Token LifetimeDefault: 604800s (7 days). Maximum: 2592000s.

Client secret: after creating a Confidential client, the secret is shown only once. Copy it immediately — it cannot be retrieved afterwards. Format: cs_ followed by 40 base64url characters (e.g. cs_rxm2doH1mPQ28NWKbXIlCYImdOrHUXW5HiIGd0Vx). A Public client has no secret — PKCE replaces it.

Confidential Client (Machine-to-Machine) — for server-side applications that authenticate without user interaction: scripts, scheduled jobs, backend integrations.

  • Has a client_secret stored server-side.
  • Uses the Client Credentials flow.
  • Acts with the rights of the configured Associated User.
  • Cannot use the Authorization Code flow.

Public Client (user delegation) — for web portals or mobile apps acting on behalf of a real Cirrus Shield user.

  • No secret (PKCE stands in for proof of possession).
  • Uses the Authorization Code + PKCE flow.
  • Acts with the rights of the user who consented.
  • Issues refresh tokens when offline_access is among the scopes.
ScopeWhat it allows
api:readRead records (Query, Describe)
api:writeCreate and update records, send emails, generate documents
api:deleteDelete records
apiFull API access (equivalent to api:read + api:write + api:delete)
offline_accessObtain a refresh token (Authorization Code flow only)

ℹ️ Scopes granted to the application only set the maximum possible permissions — the associated user (Confidential) or the logged-in user (Public) can still be further restricted by their own profile.

From the client’s detail page:

  • Enable / Disable — a disabled client returns 401 invalid_client on every token attempt.
  • Regenerate Secret — immediately invalidates all of the client’s active tokens, then generates a new secret shown only once. The old secret stops working right away.
  • Delete — revokes all active tokens and permanently removes the client.

Each client’s detail page shows the last 20 OAuth events:

Event TypeMeaning
TOKEN_ISSUEDToken successfully issued
TOKEN_REFRESHEDToken renewed via refresh token
TOKEN_REVOKEDToken revoked (manually or by rotation)
AUTH_FAILEDAuthentication failure — shown in red
INTROSPECTToken verified by a Resource Server

No token or credential ever appears in the logs — only metadata (source IP, duration, HTTP status) is recorded.

  • Never share a client_secret across multiple applications — create one client per application.
  • Restrict allowed IPs for M2M clients that have a fixed IP.
  • Grant each application the minimum scopes it needs.
  • Monitor AUTH_FAILED events — a high count can indicate an attack attempt.
  • Regenerate the secret immediately if compromise is suspected.
  • Disable rather than delete an application that’s temporarily out of service (logs are preserved).

Once the Connected App is created, obtaining and using OAuth 2.0 tokens (endpoints, the Client Credentials and Authorization Code + PKCE flows, introspection, JWT validation, code samples) is covered in the next section: 1. AuthToken.

Was this article helpful to you? No Yes

How can we help?