{"id":12277,"date":"2026-09-28T08:24:01","date_gmt":"2026-09-28T07:24:01","guid":{"rendered":"https:\/\/help.cirrus-shield.com\/?post_type=docs&#038;p=12277"},"modified":"2026-09-28T08:24:05","modified_gmt":"2026-09-28T07:24:05","slug":"connected-apps","status":"publish","type":"docs","link":"https:\/\/help.cirrus-shield.com\/en\/docs\/developer-guide\/connected-apps\/","title":{"rendered":"Connected Apps"},"content":{"rendered":"\n<h2 class=\"wp-block-heading has-luminous-vivid-amber-color has-text-color has-link-color wp-elements-1\"><strong>Overview<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Connected Apps module lets external applications (portals, ERPs, BI tools, .NET middleware, integration scripts&#8230;) authenticate against the Cirrus Shield REST API without storing a human user\u2019s password. Before writing any code against the REST API (covered in the next section), your integration must be registered as a Connected App.<\/p>\n\n\n\n<h2 class=\"wp-block-heading has-luminous-vivid-amber-color has-text-color has-link-color wp-elements-2\"><strong>Accessing Connected App management<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Navigation: Configuration \u2192 Connected Apps<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This page lists every OAuth application registered for your organization, with its status (active\/inactive) and last-used date. This is where an administrator creates a new app, or edits\/disables\/deletes an existing one.<\/p>\n\n\n\n<h2 class=\"wp-block-heading has-luminous-vivid-amber-color has-text-color has-link-color wp-elements-3\"><strong>Creating a Connected App<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">From the list page, click <strong>New App<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Required fields (common to both client types):<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Field<\/th><th>Description<\/th><\/tr><\/thead><tbody><tr><td><strong>Name<\/strong><\/td><td>Name shown on the consent screen. Max 100 characters.<\/td><\/tr><tr><td><strong>Client Type<\/strong><\/td><td>Confidential or Public \u2014 see \u201cClient Types\u201d below.<\/td><\/tr><tr><td><strong>Allowed Scopes<\/strong><\/td><td>Permissions granted to the application \u2014 see \u201cAvailable Scopes\u201d below.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Additional fields for a Confidential client:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Field<\/th><th>Description<\/th><\/tr><\/thead><tbody><tr><td><strong>Associated User<\/strong><\/td><td>Cirrus Shield account that provides the data context for machine-to-machine (M2M) calls.<\/td><\/tr><tr><td><strong>Allowed IPs<\/strong><\/td><td>Optional \u2014 list of IPs or CIDR ranges allowed to call the token endpoint.<\/td><\/tr><tr><td><strong>Access Token Lifetime<\/strong><\/td><td>Validity in seconds. Default: 3600s. Maximum: 86400s.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Additional fields for a Public client:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Field<\/th><th>Description<\/th><\/tr><\/thead><tbody><tr><td><strong>Redirect URIs<\/strong><\/td><td>One URI per line. Exact match required \u2014 no wildcards.<\/td><\/tr><tr><td><strong>Access Token Lifetime<\/strong><\/td><td>Default: 900s (15 min) for the user flow.<\/td><\/tr><tr><td><strong>Refresh Token Lifetime<\/strong><\/td><td>Default: 604800s (7 days). Maximum: 2592000s.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Client secret:<\/strong> after creating a <strong>Confidential<\/strong> client, the secret is shown <strong>only once<\/strong>. Copy it immediately \u2014 it cannot be retrieved afterwards. Format: <code>cs_<\/code> followed by 40 base64url characters (e.g. <code>cs_rxm2doH1mPQ28NWKbXIlCYImdOrHUXW5HiIGd0Vx<\/code>). A Public client has no secret \u2014 PKCE replaces it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading has-luminous-vivid-amber-color has-text-color has-link-color wp-elements-4\"><strong>Client Types<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Confidential Client (Machine-to-Machine)<\/strong> \u2014 for server-side applications that authenticate without user interaction: scripts, scheduled jobs, backend integrations.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Has a <code>client_secret<\/code> stored server-side.<\/li>\n\n\n\n<li>Uses the <strong>Client Credentials<\/strong> flow.<\/li>\n\n\n\n<li>Acts with the rights of the configured <strong>Associated User<\/strong>.<\/li>\n\n\n\n<li>Cannot use the Authorization Code flow.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Public Client (user delegation)<\/strong> \u2014 for web portals or mobile apps acting on behalf of a real Cirrus Shield user.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>No secret (PKCE stands in for proof of possession).<\/li>\n\n\n\n<li>Uses the <strong>Authorization Code + PKCE<\/strong> flow.<\/li>\n\n\n\n<li>Acts with the rights of the user who consented.<\/li>\n\n\n\n<li>Issues refresh tokens when <code>offline_access<\/code> is among the scopes.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading has-luminous-vivid-amber-color has-text-color has-link-color wp-elements-5\"><strong>Available Scopes<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Scope<\/th><th>What it allows<\/th><\/tr><\/thead><tbody><tr><td><code>api:read<\/code><\/td><td>Read records (Query, Describe)<\/td><\/tr><tr><td><code>api:write<\/code><\/td><td>Create and update records, send emails, generate documents<\/td><\/tr><tr><td><code>api:delete<\/code><\/td><td>Delete records<\/td><\/tr><tr><td><code>api<\/code><\/td><td>Full API access (equivalent to <code>api:read<\/code> + <code>api:write<\/code> + <code>api:delete<\/code>)<\/td><\/tr><tr><td><code>offline_access<\/code><\/td><td>Obtain a refresh token (Authorization Code flow only)<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">\u2139\ufe0f Scopes granted to the application only set the maximum possible permissions \u2014 the associated user (Confidential) or the logged-in user (Public) can still be further restricted by their own profile.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading has-luminous-vivid-amber-color has-text-color has-link-color wp-elements-6\"><strong>Managing an existing Connected App<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">From the client\u2019s detail page:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Enable \/ Disable<\/strong> \u2014 a disabled client returns <code>401 invalid_client<\/code> on every token attempt.<\/li>\n\n\n\n<li><strong>Regenerate Secret<\/strong> \u2014 immediately invalidates all of the client\u2019s active tokens, then generates a new secret shown only once. The old secret stops working right away.<\/li>\n\n\n\n<li><strong>Delete<\/strong> \u2014 revokes all active tokens and permanently removes the client.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading has-luminous-vivid-amber-color has-text-color has-link-color wp-elements-7\"><strong>Activity Log<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Each client\u2019s detail page shows the last 20 OAuth events:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>Event Type<\/th><th>Meaning<\/th><\/tr><\/thead><tbody><tr><td><code>TOKEN_ISSUED<\/code><\/td><td>Token successfully issued<\/td><\/tr><tr><td><code>TOKEN_REFRESHED<\/code><\/td><td>Token renewed via refresh token<\/td><\/tr><tr><td><code>TOKEN_REVOKED<\/code><\/td><td>Token revoked (manually or by rotation)<\/td><\/tr><tr><td><code>AUTH_FAILED<\/code><\/td><td>Authentication failure \u2014 shown in red<\/td><\/tr><tr><td><code>INTROSPECT<\/code><\/td><td>Token verified by a Resource Server<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">No token or credential ever appears in the logs \u2014 only metadata (source IP, duration, HTTP status) is recorded.<\/p>\n\n\n\n<h2 class=\"wp-block-heading has-luminous-vivid-amber-color has-text-color has-link-color wp-elements-8\"><strong>Security Best Practices<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Never share a <code>client_secret<\/code> across multiple applications \u2014 create one client per application.<\/li>\n\n\n\n<li>Restrict allowed IPs for M2M clients that have a fixed IP.<\/li>\n\n\n\n<li>Grant each application the minimum scopes it needs.<\/li>\n\n\n\n<li>Monitor <code>AUTH_FAILED<\/code> events \u2014 a high count can indicate an attack attempt.<\/li>\n\n\n\n<li>Regenerate the secret immediately if compromise is suspected.<\/li>\n\n\n\n<li>Disable rather than delete an application that\u2019s temporarily out of service (logs are preserved).<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Once the Connected App is created, obtaining and using OAuth 2.0 tokens (endpoints, the <em>Client Credentials<\/em> and <em>Authorization Code + PKCE<\/em> flows, introspection, JWT validation, code samples) is covered in the next section: <strong><a href=\"https:\/\/help.cirrus-shield.com\/en\/docs\/developer-guide\/rest-api\/authtoken\/\">1. AuthToken<\/a><\/strong>.<\/p>\n","protected":false},"author":18,"featured_media":0,"parent":943,"menu_order":4,"comment_status":"open","ping_status":"closed","template":"","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","_is_vendor_doc":"0","footnotes":""},"doc_tag":[],"class_list":["post-12277","docs","type-docs","status-publish","hentry"],"comment_count":0,"_links":{"self":[{"href":"https:\/\/help.cirrus-shield.com\/en\/wp-json\/wp\/v2\/docs\/12277","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/help.cirrus-shield.com\/en\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/help.cirrus-shield.com\/en\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/help.cirrus-shield.com\/en\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/help.cirrus-shield.com\/en\/wp-json\/wp\/v2\/comments?post=12277"}],"version-history":[{"count":2,"href":"https:\/\/help.cirrus-shield.com\/en\/wp-json\/wp\/v2\/docs\/12277\/revisions"}],"predecessor-version":[{"id":12287,"href":"https:\/\/help.cirrus-shield.com\/en\/wp-json\/wp\/v2\/docs\/12277\/revisions\/12287"}],"up":[{"embeddable":true,"href":"https:\/\/help.cirrus-shield.com\/en\/wp-json\/wp\/v2\/docs\/943"}],"prev":[{"title":"SSO Single Sign on","link":"https:\/\/help.cirrus-shield.com\/en\/docs\/developer-guide\/sso-single-sign-on\/","href":"https:\/\/help.cirrus-shield.com\/en\/wp-json\/wp\/v2\/docs\/1872"}],"wp:attachment":[{"href":"https:\/\/help.cirrus-shield.com\/en\/wp-json\/wp\/v2\/media?parent=12277"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/help.cirrus-shield.com\/en\/wp-json\/wp\/v2\/doc_tag?post=12277"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}