---
title: Resource Operations
description: Explains the PingOne resources endpoint for creating, reading, updating, and deleting resource entities
component: pingone-api
page_id: pingone-api:platform:resources/resources-1/index
canonical_url: https://developer.pingidentity.com/pingone-api/platform/resources/resources-1/index.html
llms_txt: https://developer.pingidentity.com/pingone-api/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
revdate: 2026-08-11
section_ids:
  migrate-resources: Importing external resources to PingOne
  resources-data-model: Resources data model
  resources-core-attribute-data-model: Resources core attribute data model
  resources-events-generated: Resources events generated
  response-codes: Response codes
---

# Resource Operations

The `/resources` endpoint provides operations to create, read, update, and delete resource entities. The examples that follow show common actions to find and manage resources entities.

You need the Environment Admin or the Client Application Developer roles to perform operations on resources entities.

## Importing external resources to PingOne

Environment Admins can import resources to PingOne, preserving the existing resource client ID and client secret. This enables you to:

* Replicate resource records that have been created in another platform.

* Recover from an accidental deletion of a resource. You can create a new resource record using the client ID and client secret of the deleted resource.

Import of resources is supported only by [Import Resource](import-resource.html), and specifying `clientId` and `clientSecret` in the request body. You're also able to import OIDC applications to PingOne. Refer to [Importing external OIDC applications to PingOne](../../applications/applications-1/index.html#migrate-oidc-apps) for more information.

## Resources data model

| Property                                      | Type    | Required | Mutable   | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| --------------------------------------------- | ------- | -------- | --------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `accessTokenValiditySeconds`                  | Integer | Required | Mutable   | The number of seconds that the access token is valid. If a value is not specified, the default is 3600. The minimum value is 300 seconds (5 minutes); the maximum value is 2592000 seconds (30 days).                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| `applicationPermissionsSettings`              | Object  | Optional | Mutable   | For custom resources, when an application has requested an access token scoped to the Resource service on behalf of a user, and the Resource service has application permissions enabled, this object enables adding the user's application permissions to the access token generated by PingOne.                                                                                                                                                                                                                                                                                                                                                                    |
| `applicationPermissionsSettings.claimEnabled` | Boolean | Optional | Mutable   | For custom resources, when enabled this is `true`, the access token includes a claim with an array of the permissions assigned to the user. If an application requests an access token for the Resource service that does not have the permissions option enabled, the token will not include permissions assigned to the user. See [PingOne Permissions by Resource](../../reference/roles-and-permissions-in-pingone/permissions-by-resource.html) or [PingOne Permissions by Identifier](../../reference/roles-and-permissions-in-pingone/pingone-permissions-by-identifier.html) for more information. If this property is omitted, the value is set to `false`. |
| `audience`                                    | String  | Required | Mutable   | A URL without a fragment or "@ObjectName" and must not contain "pingone" or "pingidentity" (for example, https\://api.myresource.com). If a URL is not specified, the resource name is used. The value that you set here is returned in the audience claim in the token. For more information, refer to [Token Introspection (Resource ID and Secret)](../../../auth/index.html#post-token-introspection-resource-id-and-secret).                                                                                                                                                                                                                                    |
| `clientId`                                    | String  | Optional | Immutable | (Required when `clientSecret` is specified.) Supported only for POST operations. If an identifier exists for an external resource that's being imported to PingOne, this identifier can be set here. This must be a minimum of 8 alpha-numeric characters (maximum 256), and must be globally unique in PingOne. If an identifier for an external resource doesn't exist when it's imported to PingOne, the `id` value automatically generated for the resource is used as the identifier.                                                                                                                                                                           |
| `clientSecret`                                | String  | Optional | Immutable | Supported only for POST operations. This is the client secret associated with `clientId` for an external resource that is being imported to PingOne. This must be a minimum of 8 alpha-numeric characters, and a maximum of 1024 characters. This value is encrypted by PingOne, and returned by the POST, GET, and PUT requests. When a client secret is not provided, PingOne generates a client secret as part of the resource-creation process. In this case, you'll need to update the generated client secret with a new one using [Set Resource Client Secret (Imported Resource)](../resource-secret/set-resource-client-secret.html).                       |
| `createdAt`                                   | Date    | N/A      | Read only | The time the resource was created.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| `description`                                 | String  | Optional | Mutable   | Description of the resource.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| `environment.id`                              | String  | Required | Immutable | The environment resource's unique identifier associated with the resource.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| `id`                                          | String  | Required | Immutable | The resource's unique identifier.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| `name`                                        | String  | Required | Immutable | The resource name, which must be provided and must be unique within an environment.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| `introspectEndpointAuthMethod`                | String  | Required | Mutable   | The authentication methods supported by the token endpoint. Options are `NONE`, `CLIENT_SECRET_BASIC`, `CLIENT_SECRET_POST`, `CLIENT_SECRET_JWT`, and `PRIVATE_KEY_JWT`. Applicable only to custom resources.                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| `type`                                        | String  | Required | Mutable   | The type of resource. Options are `OPENID_CONNECT`, `PING_ONE_API,` and `CUSTOM`. Only the `CUSTOM` resource type can be created. `OPENID_CONNECT` specifies the built-in platform resource for OpenID Connect. `PING_ONE_API` specifies the built-in platform resource for PingOne.                                                                                                                                                                                                                                                                                                                                                                                 |
| `updatedAt`                                   | Date    | N/A      | Read only | The time the resource was last updated.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |

## Resources core attribute data model

| Property | Type   | Required | Mutable | Description                                                             |
| -------- | ------ | -------- | ------- | ----------------------------------------------------------------------- |
| `sub`    | String | Required | Mutable | The core claim for the new resource. The default value is `${user.id}`. |

## Resources events generated

Refer to [Audit Reporting Events](../../audit-activities/index.html#audit-reporting-events) for the events generated.

## Response codes

| Code | Message                                  |
| ---- | ---------------------------------------- |
| 200  | Successful operation.                    |
| 201  | Successfully created.                    |
| 204  | Successfully removed. No content.        |
| 400  | The request could not be completed.      |
| 401  | You do not have access to this resource. |
| 404  | The requested resource was not found.    |
