Use this API to manage instance-wide OAuth applications that:

You cannot use this API to manage group applications or individual user applications.

Get applications

GET /api/v4/applications

List all registered applications

Responses

CodeDescriptionSchema
200OKAPIEntitiesApplication
401Unauthorized—
403Forbidden—

List all applications

GET /api/v4/user/applications

Lists all applications owned by the authenticated user.

Responses

CodeDescriptionSchema
200OKAPIEntitiesApplication
401Unauthorized—
403Forbidden—

Create an application

POST /api/v4/user/applications

Creates a new OAuth application for the authenticated user. This feature was introduced in GitLab 19.0

Request body (application/json)

PropertyTypeDescription
confidentialBooleanIf true, the application can securely store client credentials, such as the client secret. Non-confidential applications, such as native mobile apps and Single Page Apps might expose client credentials. If unset, defaults to true
Default: true
name
Required
StringName of the application
Example: MyApplication
redirect_uri
Required
StringRedirect URI of the application
Example: https://redirect.uri
scopes
Required
StringScopes available to the application. Separate multiple scopes with a space

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesApplicationWithSecret
400Bad Request—

Retrieve an application

GET /api/v4/user/applications/{id}

Retrieves details of a specific application owned by the authenticated user.

Parameters

NameTypeDescription
id
Path, required
IntegerID of the application. Differs from the application_id

Responses

CodeDescriptionSchema
200OKAPIEntitiesApplication
400Bad Request—
404Not Found—

Update an application

PUT /api/v4/user/applications/{id}

Updates an existing application owned by the authenticated user.

Parameters

NameTypeDescription
id
Path, required
IntegerID of the application. Differs from the application_id

Request body (application/json)

PropertyTypeDescription
nameStringName of the application
scopesStringScopes available to the application. Separate multiple scopes with a space

Responses

CodeDescriptionSchema
200OKAPIEntitiesApplication
400Bad Request—
404Not Found—

Delete an application

DELETE /api/v4/user/applications/{id}

Deletes a specified application owned by the authenticated user.

Parameters

NameTypeDescription
id
Path, required
IntegerID of the application. Differs from the application_id

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
404Not Found—

Schemas

Objects returned by the operations above and objects nested in their request bodies.

APIEntitiesApplication

PropertyTypeDescription
application_idStringExample: 5832fc6e14300a0d962240a8144466eef4ee93ef0d218477e55f11cf12fc3737
application_nameStringExample: MyApplication
callback_urlStringExample: https://redirect.uri
confidentialBooleanExample: true
idInteger (int64)Example: 1
scopesArrayExample: ["api","read_user"]

APIEntitiesApplicationWithSecret

PropertyTypeDescription
application_idStringExample: 5832fc6e14300a0d962240a8144466eef4ee93ef0d218477e55f11cf12fc3737
application_nameStringExample: MyApplication
callback_urlStringExample: https://redirect.uri
confidentialBooleanExample: true
idInteger (int64)Example: 1
scopesArrayExample: ["api","read_user"]
secretStringExample: ee1dd64b6adc89cf7e2c23099301ccc2c61b441064e9324d963c46902a85ec34