Update the tenant-level OAuth Client ID Metadata Document (CIMD) configuration. Enabling requires the OIDC provider SSRF protection to be active.
Body
Required
-
Whether CIMD is enabled for the tenant.
-
Experimental. When enabled, Logto adds
consentto thepromptparameter of CIMD authorization requests that include theoffline_accessscope without it, so the client can receive a refresh token. Requests withprompt=noneare not changed. Defaults tofalse.
PATCH
/api/configs/cimd
curl \
--request PATCH 'https://[tenant_id].logto.app/api/configs/cimd' \
--header "Authorization: Bearer $ACCESS_TOKEN" \
--header "Content-Type: application/json" \
--data '{
"enabled": true,
"addConsentPromptForOfflineAccess": true
}'
Request examples
{
"enabled": true,
"addConsentPromptForOfflineAccess": true
}
Response examples (200)
{
"enabled": true,
"addConsentPromptForOfflineAccess": true
}