CLI: Clients
Manage OIDC clients and client secrets via the porta client command.
Mode: HTTP (requires porta login)
OIDC clients belong to one organization and reference one deployment-global application. In porta admin, select the organization first, then open OIDC Clients. Switching organizations closes the prior client workspace so client data is never carried into the new context.
The interactive workspace always uses a DataGrid for the selected organization's clients, including when the list is empty. Registration asks only for client identity, application/type, one redirect URI, and optional initial-secret settings. After creation, Porta opens the authoritative client Overview instead of retaining a local placeholder.
Client details use separate Overview, Authentication, Protocol, Login experience, Credentials, and Lifecycle sections. Each section opens one focused editor instead of a shared tabbed form:
- Authentication stages redirect URIs, post-logout redirect URIs, and allowed origins in one reusable grid. Add, Edit, and Remove remain local until Save submits all three ordered arrays.
- Protocol configures grant types, the fixed
coderesponse type, scope, token authentication, and PKCE while preserving public/confidential compatibility rules. - Login experience either inherits the selected organization's effective methods or enables Password, Magic link, or both explicitly.
- Credentials lists secret metadata and enables Revoke only for the selected active secret.
The client name remains a one-line field in its own small editor. All other multi-field editors use the full Admin surface and reload authoritative server state after saving.
Client CRUD
porta client create
porta client create \
--org <org-id> \
--app <app-id> \
--name "ERP Web App" \
--type public \
--redirect-uris "https://erp.example.com/callback" \
[--application-type web] \
[--login-methods "password,magic_link"] \
[--require-consent]| Flag | Required | Description |
|---|---|---|
--org | ✅ | Organization UUID (owner of the client) |
--app | ✅ | Application UUID or slug |
--name | Client display name | |
--type | ✅ | confidential or public |
--redirect-uris | ✅ | Comma-separated redirect URIs |
--application-type | web, native, or spa (default: web) | |
--login-methods | Override org default login methods | |
--require-consent | Show the OIDC consent page for this client |
porta client list
porta client list --app <app-id> [--status active] [--page 1] [--page-size 20]porta client get
porta client get <client-id>Shows full client details including effectiveLoginMethods and requireConsent.
porta client update
porta client update <client-id> \
[--name "New Name"] \
[--redirect-uris "https://new.example.com/callback"] \
[--login-methods "password,magic_link"] \
[--require-consent | --no-require-consent]Omit --require-consent/--no-require-consent to leave the stored value unchanged.
porta client delete
porta client delete <client-id>Permanently deletes the client, its secrets, and its protocol authority. The CLI always asks whether to keep or delete the named client. There is no record-deletion --force option.
WARNING
Deleting a client removes its credentials and immediately ends its protocol authority.
porta client activate / porta client deactivate
porta client activate <client-id>
porta client deactivate <client-id>Client Secrets
Manage secrets for confidential clients. Supports multiple active secrets for zero-downtime rotation.
At most 10 active, unexpired secrets are allowed for one client. Revoke an old secret before generating another when that limit is reached. An upgrade stops safely if existing data already has more than 10; revoke excess secrets with the previous Porta version, then retry the upgrade.
Clients retained from versions that stored only legacy Argon2 secret hashes must generate one modern secret before legacy overlap authentication can transition. During the overlap, a valid active legacy credential may be canonicalized to the modern value; expired, revoked, or invalid credentials are never canonicalized.
porta client secret generate
porta client secret generate --client-id <id> [--label "production-2024"]In porta admin, secret generation offers 3, 6, 12, and 24 month presets, a custom calendar date, and Never. Six months is selected by default. Custom dates may be later than 24 months, with a rotation warning. Never omits expiry and shows the same non-blocking warning. These warnings do not add a second confirmation.
DANGER
The plaintext secret is displayed only once. Copy and store it securely.
porta client secret list
porta client secret list --client-id <id>Shows secret metadata (ID, label, creation date) without plaintext values.
The Admin UI follows the same rule: generated plaintext appears in one transient dialog and is discarded when that dialog closes. Later views show metadata only.
porta client secret revoke
porta client secret revoke --client-id <id> --secret-id <id>Login Methods
Manage per-client login method overrides.
porta client login-methods get
porta client login-methods get --client-id <id>Shows the effective login methods (client override or inherited from org).
porta client login-methods set
porta client login-methods set --client-id <id> --methods password
porta client login-methods set --client-id <id> --methods password,magic_linkporta client login-methods clear
porta client login-methods clear --client-id <id>Removes the client-specific override, causing the client to inherit login methods from its organization.