Import Application (OIDC Protocol)
POST {{apiPath}}/v1/environments/{{envID}}/applications
Use this POST {{apiPath}}/v1/environments/{{envID}}/applications operation to import an application to the specified environment. You can specify the client ID by including the clientId property in the request body. You can optionally import the client secret as well by including the clientSecret property in the request body.
If you don’t specify a value for enabled in the request body, it defaults to false.
Prerequisites
-
Refer to Application Operations for important overview information.
Query parameters
| Parameter | Description |
|---|---|
|
Shows additional information in the |
Request Model
Base application data model (web application)
Refer to Applications base data model for complete descriptions.
| Property | Required? | Type |
|---|---|---|
|
Optional |
Boolean |
|
Optional |
String |
|
Optional |
String |
|
Optional |
Array |
|
Optional |
UUID |
|
Optional |
String |
|
Required |
Boolean |
|
Optional |
URL |
|
Optional |
URL |
|
Optional |
UUID |
|
Optional |
URL |
|
Required |
String |
|
Required |
String |
|
Optional |
Boolean |
|
Optional |
Array |
|
Required |
String |
Additional OIDC settings
Refer to Applications OIDC settings data model for complete descriptions.
If you set the protocol attribute to OPENID_CONNECT, you must provide values for the required OIDC settings. Optional settings can be omitted.
| Property | Required? | Type |
|---|---|---|
|
Optional |
Boolean |
|
Optional |
String |
|
Optional |
String |
|
Optional |
String |
|
String |
Optional |
|
String |
Optional |
|
Optional |
String |
|
Optional |
String |
|
Required |
URL |
|
Required |
URL |
|
Optional |
Integer |
|
Optional |
Integer |
|
Optional |
Boolean |
|
Required |
String |
|
Optional |
Object |
|
Required |
Object |
|
Required |
String |
|
Optional |
Boolean |
|
Required |
String |
Body
raw ( application/json )
{
"enabled": false,
"name": "Import-OIDC-App-test",
"description": "Test Description - OIDC App import",
"clientId": "{{$timestamp}}_myClientId",
"clientSecret": "myClientSecret",
"type": "WEB_APP",
"protocol": "OPENID_CONNECT",
"homePageUrl": "https://example.com/homePage",
"loginPageUrl": "https://example.com/loginPage",
"icon": {
"id": "{{iconID}}",
"href": "https://upload.image/image.jpg"
},
"grantTypes": [
"AUTHORIZATION_CODE"
],
"postLogoutRedirectUris": [
"https://example.com/logout"
],
"redirectUris": [
"https://example.com"
],
"responseTypes": [
"CODE"
],
"signing": {
"keyRotationPolicy": {
"id": "{{krpID}}"
}
},
"tokenEndpointAuthMethod": "CLIENT_SECRET_BASIC",
"pkceEnforcement": "REQUIRED",
"refreshTokenDuration": 86400,
"refreshTokenRollingDuration": 86400
}
Example Request
-
cURL
-
C#
-
Go
-
HTTP
-
Java
-
jQuery
-
NodeJS
-
Python
-
PHP
-
Ruby
-
Swift
curl --location --globoff '{{apiPath}}/v1/environments/{{envID}}/applications' \
--header 'Content-Type: application/json' \
--header 'Authorization: Bearer {{accessToken}}' \
--data '{
"enabled": false,
"name": "Import-OIDC-App-test",
"description": "Test Description - OIDC App import",
"clientId": "{{$timestamp}}_myClientId",
"clientSecret": "myClientSecret",
"type": "WEB_APP",
"protocol": "OPENID_CONNECT",
"homePageUrl": "https://example.com/homePage",
"loginPageUrl": "https://example.com/loginPage",
"icon": {
"id": "{{iconID}}",
"href": "https://upload.image/image.jpg"
},
"grantTypes": [
"AUTHORIZATION_CODE"
],
"postLogoutRedirectUris": [
"https://example.com/logout"
],
"redirectUris": [
"https://example.com"
],
"responseTypes": [
"CODE"
],
"signing": {
"keyRotationPolicy": {
"id": "{{krpID}}"
}
},
"tokenEndpointAuthMethod": "CLIENT_SECRET_BASIC",
"pkceEnforcement": "REQUIRED",
"refreshTokenDuration": 86400,
"refreshTokenRollingDuration": 86400
}'
var options = new RestClientOptions("{{apiPath}}/v1/environments/{{envID}}/applications")
{
MaxTimeout = -1,
};
var client = new RestClient(options);
var request = new RestRequest("", Method.Post);
request.AddHeader("Content-Type", "application/json");
request.AddHeader("Authorization", "Bearer {{accessToken}}");
var body = @"{" + "\n" +
@" ""enabled"": false," + "\n" +
@" ""name"": ""Import-OIDC-App-test""," + "\n" +
@" ""description"": ""Test Description - OIDC App import""," + "\n" +
@" ""clientId"": ""{{$timestamp}}_myClientId""," + "\n" +
@" ""clientSecret"": ""myClientSecret""," + "\n" +
@" ""type"": ""WEB_APP""," + "\n" +
@" ""protocol"": ""OPENID_CONNECT""," + "\n" +
@" ""homePageUrl"": ""https://example.com/homePage""," + "\n" +
@" ""loginPageUrl"": ""https://example.com/loginPage""," + "\n" +
@" ""icon"": {" + "\n" +
@" ""id"": ""{{iconID}}""," + "\n" +
@" ""href"": ""https://upload.image/image.jpg""" + "\n" +
@" }," + "\n" +
@" ""grantTypes"": [" + "\n" +
@" ""AUTHORIZATION_CODE""" + "\n" +
@" ]," + "\n" +
@" ""postLogoutRedirectUris"": [" + "\n" +
@" ""https://example.com/logout""" + "\n" +
@" ]," + "\n" +
@" ""redirectUris"": [" + "\n" +
@" ""https://example.com""" + "\n" +
@" ]," + "\n" +
@" ""responseTypes"": [" + "\n" +
@" ""CODE""" + "\n" +
@" ]," + "\n" +
@" ""signing"": {" + "\n" +
@" ""keyRotationPolicy"": {" + "\n" +
@" ""id"": ""{{krpID}}""" + "\n" +
@" }" + "\n" +
@" }," + "\n" +
@" ""tokenEndpointAuthMethod"": ""CLIENT_SECRET_BASIC""," + "\n" +
@" ""pkceEnforcement"": ""REQUIRED""," + "\n" +
@" ""refreshTokenDuration"": 86400," + "\n" +
@" ""refreshTokenRollingDuration"": 86400" + "\n" +
@"}";
request.AddStringBody(body, DataFormat.Json);
RestResponse response = await client.ExecuteAsync(request);
Console.WriteLine(response.Content);
package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "{{apiPath}}/v1/environments/{{envID}}/applications"
method := "POST"
payload := strings.NewReader(`{
"enabled": false,
"name": "Import-OIDC-App-test",
"description": "Test Description - OIDC App import",
"clientId": "{{$timestamp}}_myClientId",
"clientSecret": "myClientSecret",
"type": "WEB_APP",
"protocol": "OPENID_CONNECT",
"homePageUrl": "https://example.com/homePage",
"loginPageUrl": "https://example.com/loginPage",
"icon": {
"id": "{{iconID}}",
"href": "https://upload.image/image.jpg"
},
"grantTypes": [
"AUTHORIZATION_CODE"
],
"postLogoutRedirectUris": [
"https://example.com/logout"
],
"redirectUris": [
"https://example.com"
],
"responseTypes": [
"CODE"
],
"signing": {
"keyRotationPolicy": {
"id": "{{krpID}}"
}
},
"tokenEndpointAuthMethod": "CLIENT_SECRET_BASIC",
"pkceEnforcement": "REQUIRED",
"refreshTokenDuration": 86400,
"refreshTokenRollingDuration": 86400
}`)
client := &http.Client {
}
req, err := http.NewRequest(method, url, payload)
if err != nil {
fmt.Println(err)
return
}
req.Header.Add("Content-Type", "application/json")
req.Header.Add("Authorization", "Bearer {{accessToken}}")
res, err := client.Do(req)
if err != nil {
fmt.Println(err)
return
}
defer res.Body.Close()
body, err := io.ReadAll(res.Body)
if err != nil {
fmt.Println(err)
return
}
fmt.Println(string(body))
}
POST /v1/environments/{{envID}}/applications HTTP/1.1
Host: {{apiPath}}
Content-Type: application/json
Authorization: Bearer {{accessToken}}
{
"enabled": false,
"name": "Import-OIDC-App-test",
"description": "Test Description - OIDC App import",
"clientId": "{{$timestamp}}_myClientId",
"clientSecret": "myClientSecret",
"type": "WEB_APP",
"protocol": "OPENID_CONNECT",
"homePageUrl": "https://example.com/homePage",
"loginPageUrl": "https://example.com/loginPage",
"icon": {
"id": "{{iconID}}",
"href": "https://upload.image/image.jpg"
},
"grantTypes": [
"AUTHORIZATION_CODE"
],
"postLogoutRedirectUris": [
"https://example.com/logout"
],
"redirectUris": [
"https://example.com"
],
"responseTypes": [
"CODE"
],
"signing": {
"keyRotationPolicy": {
"id": "{{krpID}}"
}
},
"tokenEndpointAuthMethod": "CLIENT_SECRET_BASIC",
"pkceEnforcement": "REQUIRED",
"refreshTokenDuration": 86400,
"refreshTokenRollingDuration": 86400
}
OkHttpClient client = new OkHttpClient().newBuilder()
.build();
MediaType mediaType = MediaType.parse("application/json");
RequestBody body = RequestBody.create(mediaType, "{\n \"enabled\": false,\n \"name\": \"Import-OIDC-App-test\",\n \"description\": \"Test Description - OIDC App import\",\n \"clientId\": \"{{$timestamp}}_myClientId\",\n \"clientSecret\": \"myClientSecret\",\n \"type\": \"WEB_APP\",\n \"protocol\": \"OPENID_CONNECT\",\n \"homePageUrl\": \"https://example.com/homePage\",\n \"loginPageUrl\": \"https://example.com/loginPage\",\n \"icon\": {\n \"id\": \"{{iconID}}\",\n \"href\": \"https://upload.image/image.jpg\"\n },\n \"grantTypes\": [\n \"AUTHORIZATION_CODE\"\n ],\n \"postLogoutRedirectUris\": [\n \"https://example.com/logout\"\n ],\n \"redirectUris\": [\n \"https://example.com\"\n ],\n \"responseTypes\": [\n \"CODE\"\n ],\n \"signing\": {\n \"keyRotationPolicy\": {\n \"id\": \"{{krpID}}\"\n }\n },\n \"tokenEndpointAuthMethod\": \"CLIENT_SECRET_BASIC\",\n \"pkceEnforcement\": \"REQUIRED\",\n \"refreshTokenDuration\": 86400,\n \"refreshTokenRollingDuration\": 86400\n}");
Request request = new Request.Builder()
.url("{{apiPath}}/v1/environments/{{envID}}/applications")
.method("POST", body)
.addHeader("Content-Type", "application/json")
.addHeader("Authorization", "Bearer {{accessToken}}")
.build();
Response response = client.newCall(request).execute();
var settings = {
"url": "{{apiPath}}/v1/environments/{{envID}}/applications",
"method": "POST",
"timeout": 0,
"headers": {
"Content-Type": "application/json",
"Authorization": "Bearer {{accessToken}}"
},
"data": JSON.stringify({
"enabled": false,
"name": "Import-OIDC-App-test",
"description": "Test Description - OIDC App import",
"clientId": "{{$timestamp}}_myClientId",
"clientSecret": "myClientSecret",
"type": "WEB_APP",
"protocol": "OPENID_CONNECT",
"homePageUrl": "https://example.com/homePage",
"loginPageUrl": "https://example.com/loginPage",
"icon": {
"id": "{{iconID}}",
"href": "https://upload.image/image.jpg"
},
"grantTypes": [
"AUTHORIZATION_CODE"
],
"postLogoutRedirectUris": [
"https://example.com/logout"
],
"redirectUris": [
"https://example.com"
],
"responseTypes": [
"CODE"
],
"signing": {
"keyRotationPolicy": {
"id": "{{krpID}}"
}
},
"tokenEndpointAuthMethod": "CLIENT_SECRET_BASIC",
"pkceEnforcement": "REQUIRED",
"refreshTokenDuration": 86400,
"refreshTokenRollingDuration": 86400
}),
};
$.ajax(settings).done(function (response) {
console.log(response);
});
var request = require('request');
var options = {
'method': 'POST',
'url': '{{apiPath}}/v1/environments/{{envID}}/applications',
'headers': {
'Content-Type': 'application/json',
'Authorization': 'Bearer {{accessToken}}'
},
body: JSON.stringify({
"enabled": false,
"name": "Import-OIDC-App-test",
"description": "Test Description - OIDC App import",
"clientId": "{{$timestamp}}_myClientId",
"clientSecret": "myClientSecret",
"type": "WEB_APP",
"protocol": "OPENID_CONNECT",
"homePageUrl": "https://example.com/homePage",
"loginPageUrl": "https://example.com/loginPage",
"icon": {
"id": "{{iconID}}",
"href": "https://upload.image/image.jpg"
},
"grantTypes": [
"AUTHORIZATION_CODE"
],
"postLogoutRedirectUris": [
"https://example.com/logout"
],
"redirectUris": [
"https://example.com"
],
"responseTypes": [
"CODE"
],
"signing": {
"keyRotationPolicy": {
"id": "{{krpID}}"
}
},
"tokenEndpointAuthMethod": "CLIENT_SECRET_BASIC",
"pkceEnforcement": "REQUIRED",
"refreshTokenDuration": 86400,
"refreshTokenRollingDuration": 86400
})
};
request(options, function (error, response) {
if (error) throw new Error(error);
console.log(response.body);
});
import requests
import json
url = "{{apiPath}}/v1/environments/{{envID}}/applications"
payload = json.dumps({
"enabled": False,
"name": "Import-OIDC-App-test",
"description": "Test Description - OIDC App import",
"clientId": "{{$timestamp}}_myClientId",
"clientSecret": "myClientSecret",
"type": "WEB_APP",
"protocol": "OPENID_CONNECT",
"homePageUrl": "https://example.com/homePage",
"loginPageUrl": "https://example.com/loginPage",
"icon": {
"id": "{{iconID}}",
"href": "https://upload.image/image.jpg"
},
"grantTypes": [
"AUTHORIZATION_CODE"
],
"postLogoutRedirectUris": [
"https://example.com/logout"
],
"redirectUris": [
"https://example.com"
],
"responseTypes": [
"CODE"
],
"signing": {
"keyRotationPolicy": {
"id": "{{krpID}}"
}
},
"tokenEndpointAuthMethod": "CLIENT_SECRET_BASIC",
"pkceEnforcement": "REQUIRED",
"refreshTokenDuration": 86400,
"refreshTokenRollingDuration": 86400
})
headers = {
'Content-Type': 'application/json',
'Authorization': 'Bearer {{accessToken}}'
}
response = requests.request("POST", url, headers=headers, data=payload)
print(response.text)
<?php
require_once 'HTTP/Request2.php';
$request = new HTTP_Request2();
$request->setUrl('{{apiPath}}/v1/environments/{{envID}}/applications');
$request->setMethod(HTTP_Request2::METHOD_POST);
$request->setConfig(array(
'follow_redirects' => TRUE
));
$request->setHeader(array(
'Content-Type' => 'application/json',
'Authorization' => 'Bearer {{accessToken}}'
));
$request->setBody('{\n "enabled": false,\n "name": "Import-OIDC-App-test",\n "description": "Test Description - OIDC App import",\n "clientId": "{{$timestamp}}_myClientId",\n "clientSecret": "myClientSecret",\n "type": "WEB_APP",\n "protocol": "OPENID_CONNECT",\n "homePageUrl": "https://example.com/homePage",\n "loginPageUrl": "https://example.com/loginPage",\n "icon": {\n "id": "{{iconID}}",\n "href": "https://upload.image/image.jpg"\n },\n "grantTypes": [\n "AUTHORIZATION_CODE"\n ],\n "postLogoutRedirectUris": [\n "https://example.com/logout"\n ],\n "redirectUris": [\n "https://example.com"\n ],\n "responseTypes": [\n "CODE"\n ],\n "signing": {\n "keyRotationPolicy": {\n "id": "{{krpID}}"\n }\n },\n "tokenEndpointAuthMethod": "CLIENT_SECRET_BASIC",\n "pkceEnforcement": "REQUIRED",\n "refreshTokenDuration": 86400,\n "refreshTokenRollingDuration": 86400\n}');
try {
$response = $request->send();
if ($response->getStatus() == 200) {
echo $response->getBody();
}
else {
echo 'Unexpected HTTP status: ' . $response->getStatus() . ' ' .
$response->getReasonPhrase();
}
}
catch(HTTP_Request2_Exception $e) {
echo 'Error: ' . $e->getMessage();
}
require "uri"
require "json"
require "net/http"
url = URI("{{apiPath}}/v1/environments/{{envID}}/applications")
http = Net::HTTP.new(url.host, url.port);
request = Net::HTTP::Post.new(url)
request["Content-Type"] = "application/json"
request["Authorization"] = "Bearer {{accessToken}}"
request.body = JSON.dump({
"enabled": false,
"name": "Import-OIDC-App-test",
"description": "Test Description - OIDC App import",
"clientId": "{{\$timestamp}}_myClientId",
"clientSecret": "myClientSecret",
"type": "WEB_APP",
"protocol": "OPENID_CONNECT",
"homePageUrl": "https://example.com/homePage",
"loginPageUrl": "https://example.com/loginPage",
"icon": {
"id": "{{iconID}}",
"href": "https://upload.image/image.jpg"
},
"grantTypes": [
"AUTHORIZATION_CODE"
],
"postLogoutRedirectUris": [
"https://example.com/logout"
],
"redirectUris": [
"https://example.com"
],
"responseTypes": [
"CODE"
],
"signing": {
"keyRotationPolicy": {
"id": "{{krpID}}"
}
},
"tokenEndpointAuthMethod": "CLIENT_SECRET_BASIC",
"pkceEnforcement": "REQUIRED",
"refreshTokenDuration": 86400,
"refreshTokenRollingDuration": 86400
})
response = http.request(request)
puts response.read_body
let parameters = "{\n \"enabled\": false,\n \"name\": \"Import-OIDC-App-test\",\n \"description\": \"Test Description - OIDC App import\",\n \"clientId\": \"{{$timestamp}}_myClientId\",\n \"clientSecret\": \"myClientSecret\",\n \"type\": \"WEB_APP\",\n \"protocol\": \"OPENID_CONNECT\",\n \"homePageUrl\": \"https://example.com/homePage\",\n \"loginPageUrl\": \"https://example.com/loginPage\",\n \"icon\": {\n \"id\": \"{{iconID}}\",\n \"href\": \"https://upload.image/image.jpg\"\n },\n \"grantTypes\": [\n \"AUTHORIZATION_CODE\"\n ],\n \"postLogoutRedirectUris\": [\n \"https://example.com/logout\"\n ],\n \"redirectUris\": [\n \"https://example.com\"\n ],\n \"responseTypes\": [\n \"CODE\"\n ],\n \"signing\": {\n \"keyRotationPolicy\": {\n \"id\": \"{{krpID}}\"\n }\n },\n \"tokenEndpointAuthMethod\": \"CLIENT_SECRET_BASIC\",\n \"pkceEnforcement\": \"REQUIRED\",\n \"refreshTokenDuration\": 86400,\n \"refreshTokenRollingDuration\": 86400\n}"
let postData = parameters.data(using: .utf8)
var request = URLRequest(url: URL(string: "{{apiPath}}/v1/environments/{{envID}}/applications")!,timeoutInterval: Double.infinity)
request.addValue("application/json", forHTTPHeaderField: "Content-Type")
request.addValue("Bearer {{accessToken}}", forHTTPHeaderField: "Authorization")
request.httpMethod = "POST"
request.httpBody = postData
let task = URLSession.shared.dataTask(with: request) { data, response, error in
guard let data = data else {
print(String(describing: error))
return
}
print(String(data: data, encoding: .utf8)!)
}
task.resume()
Example Response
201 Created
{
"_links": {
"self": {
"href": "https://api.pingone.com/v1/environments/abfba8f6-49eb-49f5-a5d9-80ad5c98f9f6/applications/82dbca26-ac1f-4422-a7e8-a933f3276830"
},
"environment": {
"href": "https://api.pingone.com/v1/environments/abfba8f6-49eb-49f5-a5d9-80ad5c98f9f6"
},
"attributes": {
"href": "https://api.pingone.com/v1/environments/abfba8f6-49eb-49f5-a5d9-80ad5c98f9f6/applications/82dbca26-ac1f-4422-a7e8-a933f3276830/attributes"
},
"secret": {
"href": "https://api.pingone.com/v1/environments/abfba8f6-49eb-49f5-a5d9-80ad5c98f9f6/applications/82dbca26-ac1f-4422-a7e8-a933f3276830/secret"
},
"grants": {
"href": "https://api.pingone.com/v1/environments/abfba8f6-49eb-49f5-a5d9-80ad5c98f9f6/applications/82dbca26-ac1f-4422-a7e8-a933f3276830/grants"
},
"keyRotationPolicy": {
"href": "https://api.pingone.com/v1/environments/abfba8f6-49eb-49f5-a5d9-80ad5c98f9f6/keyRotationPolicies/a36791ae-91c9-486e-b607-da515b03c70c"
}
},
"environment": {
"id": "abfba8f6-49eb-49f5-a5d9-80ad5c98f9f6"
},
"id": "82dbca26-ac1f-4422-a7e8-a933f3276830",
"name": "Import-OIDC-App-test2",
"description": "Test Description - OIDC App import",
"enabled": false,
"hiddenFromAppPortal": false,
"type": "WEB_APP",
"loginPageUrl": "https://example.com/loginPage",
"homePageUrl": "https://example.com/homePage",
"icon": {
"id": "58a03414-4a8c-4adf-8040-36f91a96723e",
"href": "https://upload.image/image.jpg"
},
"protocol": "OPENID_CONNECT",
"createdAt": "2026-02-18T15:44:49.454Z",
"updatedAt": "2026-02-18T15:44:49.454Z",
"clientId": "1771429489_myClientId",
"assignActorRoles": false,
"responseTypes": [
"CODE"
],
"pkceEnforcement": "REQUIRED",
"requestScopesForMultipleResourcesEnabled": false,
"redirectUris": [
"https://example.com"
],
"deviceTimeout": 600,
"grantTypes": [
"AUTHORIZATION_CODE"
],
"idpSignoff": false,
"refreshTokenDuration": 86400,
"additionalRefreshTokenReplayProtectionEnabled": true,
"tokenEndpointAuthMethod": "CLIENT_SECRET_BASIC",
"postLogoutRedirectUris": [
"https://example.com/logout"
],
"refreshTokenRollingDuration": 86400,
"parRequirement": "OPTIONAL",
"devicePollingInterval": 5,
"signing": {
"keyRotationPolicy": {
"id": "a36791ae-91c9-486e-b607-da515b03c70c"
}
},
"parTimeout": 60
}