> For the complete documentation index, see [llms.txt](https://fusionauth.io/docs/llms.txt)

# Update an Application

API documentation for the FusionAuth Update an Application API.

# Update an Application

This API is used to update an existing Application.

You must specify all of the properties of the Application when calling this API with the `PUT` HTTP method. When used with `PUT`, this API doesn't merge the existing Application and your new data. It replaces the existing Application with your new data.

Utilize the `PATCH` HTTP method to send specific changes to merge into an existing Application.

note

You can't update an Application's roles or OAuth scopes via this API. This prevents you from accidentally removing all the roles or scopes of an Application.

To create, update or remove a role from the Application, you need to call one of these APIs:

*   [Create an Application Role](https://fusionauth.io/docs/apis/applications/create-an-application-role.md)
*   [Update an Application Role](https://fusionauth.io/docs/apis/applications/update-an-application-role.md)
*   [Delete an Application Role](https://fusionauth.io/docs/apis/applications/delete-an-application-role.md)

To create, update or remove an OAuth scope from the Application, you need to call one of these APIs:

*   [Create an OAuth Scope](https://fusionauth.io/docs/apis/scopes.md#create-an-oauth-scope)
*   [Update an OAuth Scope](https://fusionauth.io/docs/apis/scopes.md#update-an-oauth-scope)
*   [Delete an OAuth Scope](https://fusionauth.io/docs/apis/scopes.md#delete-an-oauth-scope)

note

When updating a universal application, a global API key is required. A tenant-scoped API key is not sufficient for this operation.

## Request

[!API Key Authentication](https://fusionauth.io/docs/apis/authentication.md#api-key-authentication)

Update an Application by Id

PUT/api/application/{applicationId}

OpenAPI Spec

PATCH/api/application/{applicationId}

OpenAPI Spec

note

For backward compatibility, the `PATCH` method accepts the same media type (specified by a `Content-Type` of `application/json`) and body as the `PUT` request. You can also use the following media types for different behavior:

*   [JSON Patch/RFC 6902](https://www.rfc-editor.org/rfc/rfc6902): `application/json-patch+json`
*   [JSON Merge Patch/RFC 7396](https://www.rfc-editor.org/rfc/rfc7396): `merge-patch+json`

For details, see the [PATCH documentation](https://fusionauth.io/docs/apis.md#the-patch-http-method).

Using a media type of `application/json` merges the provided request parameters into the existing object. As a result, all parameters are optional with `PATCH`: only provide the values you want to change. To remove a value, provide a `null` value. Patching an `Array` appends all values in the new list to the old list.

#### Request Headers

`X-FusionAuth-TenantId`Stringoptional

The unique Id of the tenant used to scope this API request.

The tenant Id is not required on this request even when more than one tenant has been configured because the tenant can be identified based upon the request parameters or it is otherwise not required.

Specify a tenant Id on this request when you want to ensure the request is scoped to a specific tenant. The tenant Id may be provided through this header or by using a tenant locked API key to achieve the same result.

See [Making an API request using a Tenant Id](https://fusionauth.io/docs/apis/authentication.md#making-an-api-request-using-a-tenant-id) for additional information.

#### Request Body

`application.accessControlConfiguration.uiIPAccessControlListId`UUIDoptionalAvailable since 1.30.0

The Id of the [IP Access Control List](https://fusionauth.io/docs/apis/ip-acl.md) limiting access to this application.

**Note:** To use IP ACLs, you'll need an Enterprise plan.

`application.authenticationTokenConfiguration.enabled`Booleanoptional

Determines if Users can have Authentication Tokens associated with this Application. This feature may not be enabled for the FusionAuth application.

`application.baseURL`StringoptionalAvailable since 1.68.0

The base URL used when rendering links in templates for this Application. When defined, this value overrides `tenant.baseURL`.

`application.cleanSpeakConfiguration.applicationIds`Array<UUID>optional

An array of UUIDs that map to the CleanSpeak applications for this Application. It is possible that a single Application in FusionAuth might have multiple Applications in CleanSpeak. For example, a FusionAuth Application for a game might have one CleanSpeak Application for usernames and another Application for chat.

This property is used when CleanSpeak sends user action notifications to FusionAuth (when users are disciplined for example). FusionAuth will translate the CleanSpeak ids to FusionAuth ids and then apply the user action.

`application.cleanSpeakConfiguration.usernameModeration.applicationId`UUIDoptional

The Id of the CleanSpeak application that usernames are sent to for moderation.

`application.cleanSpeakConfiguration.usernameModeration.enabled`Booleanoptional

True if CleanSpeak username moderation is enabled.

`application.data`Objectoptional

An object that can hold any information about the Application that should be persisted.

`application.emailConfiguration.emailVerificationEmailTemplateId`UUIDoptionalAvailable since 1.19.0

The Id of the Email Template used to send emails to users to verify that their email address is valid.

`application.emailConfiguration.emailUpdateEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when their email address is updated.

**Note:** To use advanced threat detection emails, you'll need an Enterprise plan.

`application.emailConfiguration.emailVerifiedEmailTemplateId`UUIDoptionalAvailable since 1.19.0

The Id of the Email Template used to notify a user that their email address has been verified.

`application.emailConfiguration.forgotPasswordEmailTemplateId`UUIDoptionalAvailable since 1.19.0

The Id of the Email Template that is used when a user is sent a forgot password email.

`application.emailConfiguration.loginIdInUseOnCreateEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when another user attempts to create an account with their login Id.

**Note:** To use advanced threat detection emails, you'll need an Enterprise plan.

`application.emailConfiguration.loginIdInUseOnUpdateEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when another user attempts to update an existing account to use their login Id.

`application.emailConfiguration.loginNewDeviceEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when they log in on a new device.

**Note:** To use advanced threat detection emails, you'll need an Enterprise plan.

`application.emailConfiguration.loginSuspiciousEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when a suspicious login occurs.

**Note:** To use advanced threat detection emails, you'll need an Enterprise plan.

`application.emailConfiguration.passwordlessEmailTemplateId`UUIDoptionalAvailable since 1.19.0

The Id of the Passwordless Email Template, sent to users when they start a passwordless login.

`application.emailConfiguration.passwordResetSuccessEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when they have completed a 'forgot password' workflow and their password has been reset.

**Note:** To use advanced threat detection emails, you'll need an Enterprise plan.

`application.emailConfiguration.passwordUpdateEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when their password has been updated.

**Note:** To use advanced threat detection emails, you'll need an Enterprise plan.

`application.emailConfiguration.setPasswordEmailTemplateId`UUIDoptionalAvailable since 1.19.0

The Id of the Email Template that is used when a user had their account created for them and they must set their password manually and they are sent an email to set their password.

`application.emailConfiguration.twoFactorMethodAddEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when a MFA method has been added to their account.

**Note:** To use advanced threat detection emails, you'll need an Enterprise plan.

`application.emailConfiguration.twoFactorMethodRemoveEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when a MFA method has been removed from their account.

**Note:** To use advanced threat detection emails, you'll need an Enterprise plan.

`application.externalIdentifierConfiguration.twoFactorTrustIdTimeToLiveInSeconds`IntegeroptionalAvailable since 1.37.0

The time in seconds until an issued Two-Factor trust Id is no longer valid and the User will be required to complete Two-Factor authentication during the next authentication attempt. Value must be greater than 0.

When this value is not defined, the value defined by **tenant.externalIdentifierConfiguration.twoFactorTrustIdTimeToLiveInSeconds** is utilized. When this value is defined it will override the tenant configured value.

This configuration is only utilized when **application.multiFactorConfiguration.loginPolicy** is `Enabled` or `Required`.

`application.formConfiguration.selfServiceFormConfiguration.requireCurrentPasswordOnPasswordChange`BooleanoptionalAvailable since 1.45.0

When enabled a user will be required to provide their current password when changing their password on a self-service account form.

**Note:** To use custom forms, you'll need a paid plan.

`application.formConfiguration.selfServiceFormId`UUIDoptionalAvailable since 1.26.0

The unique Id of the form to enable authenticated users to manage their profile on the account page.

**Note:** To use custom forms, you'll need a paid plan.

`application.jwtConfiguration.accessTokenKeyId`UUIDoptionalAvailable since 1.6.0

The Id of the signing key used to sign the access token.

`application.jwtConfiguration.enabled`Booleanoptional

Indicates if this application is using the JWT configuration defined here or the global JWT configuration defined by the Tenant. If this is `false` the signing algorithm configured in the Tenant will be used. If `true` the signing algorithm defined in this application will be used.

`application.jwtConfiguration.idTokenKeyId`UUIDoptionalAvailable since 1.6.0

The Id of the signing key used to sign the Id token.

`application.jwtConfiguration.refreshTokenExpirationPolicy`StringoptionalDefaults to FixedAvailable since 1.17.0

The Refresh Token expiration policy.

The possible values are:

*   `Fixed` - the expiration is calculated from the time the token is issued.
*   `SlidingWindow` - the expiration is calculated from the last time the token was used.
*   `SlidingWindowWithMaximumLifetime` - the expiration is calculated from the last time the token was used, or until the **maximumTimeToLiveInMinutes** is reached. Available since 1.46.0

`application.jwtConfiguration.refreshTokenOneTimeUseConfiguration.gracePeriodInSeconds`IntegeroptionalDefaults to 0Available since 1.55.1

The length of time specified in seconds that a one-time use token can be re-used.

This value must be greater than `0` and less than `86,400` which is equal to 24 hours. Setting this value to `0` effectively disables the grace period which means a one-time token may not be reused. For security reasons, you should keep this value as small as possible, and only increase past `0` to improve reliability for an asynchronous or clustered integration that may require a brief grace period.

Note that one-time use tokens refreshed within a grace period are not considered for revocation when **tenant.jwtConfiguration.refreshTokenRevocationPolicy.onOneTimeTokenReuse** is `true`. When a token is reused within the grace period the current token will be returned on the API response and the token will not be rotated.

`application.jwtConfiguration.refreshTokenSlidingWindowConfiguration.maximumTimeToLiveInMinutes`IntegeroptionalDefaults to 43,200Available since 1.46.0

The maximum lifetime of a refresh token when using a **refreshTokenExpirationPolicy** of `SlidingWindowWithMaximumLifetime`. Value must be greater than 0.

When **refreshTokenExpirationPolicy** is set to `SlidingWindowWithMaximumLifetime`, this value must be greater than or equal to **refreshTokenTimeToLiveInMinutes**.

`application.jwtConfiguration.refreshTokenTimeToLiveInMinutes`IntegeroptionalAvailable since 1.2.0

The length of time in minutes the JWT refresh token will live before it is expired and is not able to be exchanged for a JWT.

Required when **enabled** is set to `true`.

`application.jwtConfiguration.refreshTokenUsagePolicy`StringoptionalDefaults to ReusableAvailable since 1.17.0

The refresh token usage policy. The following are valid values:

*   `Reusable` - the token does not change after it was issued.
*   `OneTimeUse` - the token value will be changed each time the token is used to refresh a JWT. The client must store the new value after each usage.

`application.jwtConfiguration.timeToLiveInSeconds`Integeroptional

The length of time in seconds the JWT will live before it is expired and no longer valid.

Required when **enabled** is set to `true`.

`application.lambdaConfiguration.accessTokenPopulateId`UUIDoptionalAvailable since 1.6.0

The Id of the lambda that will be invoked when an access token is generated for this application. This will be utilized during OAuth2 and OpenID Connect authentication requests as well as when an access token is generated for the Login API.

`application.lambdaConfiguration.idTokenPopulateId`UUIDoptionalAvailable since 1.6.0

The Id of the lambda that will be invoked when an Id token is generated for this application during an OpenID Connect authentication request.

`application.lambdaConfiguration.multiFactorRequirementId`UUIDoptionalAvailable since 1.62.0

The Id of the lambda that will be invoked during logins, password changes, and MFA Status API calls to perform various validations to decide whether to challenge the user on one of their MFA methods.

**Note:** To use Multi-Factor Requirement Lambdas, you'll need an Enterprise plan.

`application.lambdaConfiguration.samlv2PopulateId`UUIDoptionalAvailable since 1.6.0

The Id of the lambda that will be invoked when a SAML response is generated during a SAML authentication request.

`application.lambdaConfiguration.selfServiceRegistrationValidationId`UUIDoptionalAvailable since 1.43.0

The Id of the lambda that will be used to perform additional validation on registration form steps.

**Note:** To use custom forms, you'll need a paid plan.

`application.lambdaConfiguration.userinfoPopulateId`UUIDoptionalAvailable since 1.50.0

The Id of the lambda that will be invoked when a UserInfo response is generated for this application.

`application.loginConfiguration.allowTokenRefresh`BooleanoptionalAvailable since 1.5.0

Indicates if a JWT may be refreshed using a Refresh Token for this application. This configuration is separate from issuing new Refresh Tokens which is controlled by the `generateRefreshTokens` parameter. This configuration indicates specifically if an existing Refresh Token may be used to request a new JWT using the [Refresh API](https://fusionauth.io/docs/apis/jwt/refresh-a-jwt.md).

If you do not intend to use the Login API, and instead will only be using the OAuth endpoints, you may leave this set to `false` to ensure Refresh Tokens cannot be used outside of the Refresh Token Grant.

`application.loginConfiguration.generateRefreshTokens`BooleanoptionalAvailable since 1.5.0

Indicates if a Refresh Token should be issued from the Login API.

If you do not intend to use the Login API, and instead will only be using the OAuth endpoints, you may leave this set to `false` to ensure Refresh Tokens will not be issued outside of the OAuth grants.

`application.loginConfiguration.requireAuthentication`BooleanoptionalAvailable since 1.5.0

Indicates if the Login API should require an API key. If you set this value to `false` and your FusionAuth API is on a public network, anyone may attempt to use the Login API.

If you do not intend to use the Login API, or will only be calling this API from a secure backend server, setting this value to `true` in order to require an API key is preferred.

`application.multiFactorConfiguration.email.templateId`UUIDoptionalAvailable since 1.26.0

The Id of the email template that is used when notifying a user to complete a multi-factor authentication request.

`application.multiFactorConfiguration.loginPolicy`StringoptionalAvailable since 1.37.0

When enabled and a user has one or more two-factor methods configured, the user will be required to complete a two-factor challenge during login. When disabled, even when a user has configured one or more two-factor methods, the user will not be required to complete a two-factor challenge during login. When required, the user will be required to complete a two-factor challenge during login.

Risk-based policies use FusionAuth's **Intelligent MFA**, which combines multiple signals to decide when to issue an MFA challenge.

When configured, this value overrides the value configured by the **tenant.multiFactorConfiguration.loginPolicy**.

Supported values include:

*   `Enabled` - Require a two-factor challenge during login when an eligible method is available.
*   `ChallengeOnMediumRisk` - Only challenge on medium or high login risk Available since 1.68.0
*   `ChallengeOnHighRisk` - Only challenge on high login risk Available since 1.68.0
*   `Disabled` - Do not require a two-factor challenge during login.
*   `Required` - Require a two-factor challenge during login. A user will be required to configure 2FA if no eligible methods are available. Available since 1.42.0

**Note:** To use an Intelligent MFA Policy, you'll need a paid plan.

Available since 1.49.0

This value may be set for the FusionAuth admin UI application whether or not an instance is licensed. For other applications, a license is required.

`application.multiFactorConfiguration.sms.templateId`UUIDoptionalAvailable since 1.26.0

The Id of the SMS template that is used when notifying a user to complete a multi-factor authentication request.

`application.multiFactorConfiguration.voice.templateId`UUIDoptionalAvailable since 1.65.0

The Id of the voice template that is used when notifying a user to complete a multi-factor authentication request.

`application.multiFactorConfiguration.trustPolicy`StringoptionalAvailable since 1.37.0

When **application.multiFactorConfiguration.loginPolicy** is set to `Enabled` or `Required`, this trust policy is utilized when determining if a user must complete a two-factor challenge during login.

For example, a normal two-factor login flow will result in a trust Id being returned if you set **trustComputer** equal to `true` when completing a Two-Factor Login. The returned Trust identifier can be used on subsequent Login requests to keep from being required to complete a Two-Factor login. This configuration determines if that trust value can be utilized for another application.

Supported values include:

*   `Any` - Trust obtained from any application is sufficient to bypass the two-factor challenge.
*   `This` - Only trust obtained for this application is sufficient to bypass the two-factor challenge.
*   `None` - Never trusted. The user will be required to complete a two-factor challenge during each login attempt.

`application.name`Stringrequired

The name of the Application.

`application.oauthConfiguration.authorizedOriginURLs`Array<String>optional

An array of URLs that are the authorized origins for FusionAuth OAuth.

For improved security, all FusionAuth hosted login pages add an HTTP response header of `X-Frame-Options: DENY`. This response header disallows loading the FusionAuth pages from an iframe. To utilize an iframe and load one or more of the FusionAuth hosted login pages, add the iframe page URLs to this property. For that host, FusionAuth will remove the `X-Frame-Options` header allowing the page to load in the iframe.

Examples of valid authorized origin URIs:

*   [https://example.com](https://example.com)
*   com.myApp://example
*   com.myApp:/example

Available since 1.32.0

You may now use URLs that do not begin with `http` to support native application origins. Prior to this version the value will be validated to begin with `http`. This also includes authorized origins that use a single slash to denote there is no naming authority for the scheme. Prior to this version a URL such as `com.myApp:/example` would fail validation as an invalid URL.

Available since 1.43.0

Configured URLs containing wildcards are considered during validation when **application.oauthConfiguration.authorizedURLValidationPolicy** is set to `AllowWildcards`. Wildcards are allowed in the following positions:

*   The left-most subdomain - A full or partial wildcard is allowed in the left-most subdomain. The replacement value cannot contain a `.`.
*   The port number - A wildcard is allowed in place of the port number. Partial wildcards are not allowed in this position.
*   A path segment - A full or partial wildcard is allowed in any path segment. The replacement value cannot contain a `/`.
*   A query string value - A wildcard is allowed in place of a query string value. Partial wildcards are not allowed in this position. Wildcards are not allowed in query string names.

See the OAuth 2.0 [URL Validation](https://fusionauth.io/docs/lifecycle/authenticate-users/oauth/url-validation.md) page for more detail.

`application.oauthConfiguration.authorizedRedirectURLs`Array<String>optional

An array of URLs that are the authorized redirect URLs for FusionAuth OAuth.

Examples of valid redirect URIs:

*   [https://example.com/redirect](https://example.com/redirect)
*   com.myApp://redirect
*   com.myApp:/redirect

Available since 1.7.0

You may now use URLs that do not begin with `http` to support native application redirect. Prior to this version the value will be validated to begin with `http`.

Available since 1.12.0

You may now use URLs for application redirects that use a single slash to denote there is no naming authority for the scheme. Prior to this version a URL such as `com.myApp:/redirect` would fail validation as in invalid URL.

Available since 1.43.0

Configured URLs containing wildcards are considered during validation when **application.oauthConfiguration.authorizedURLValidationPolicy** is set to `AllowWildcards`. Wildcards are allowed in the following positions:

*   The left-most subdomain - A full or partial wildcard is allowed in the left-most subdomain. The replacement value cannot contain a `.`.
*   The port number - A wildcard is allowed in place of the port number. Partial wildcards are not allowed in this position.
*   A path segment - A full or partial wildcard is allowed in any path segment. The replacement value cannot contain a `/`.
*   A query string value - A wildcard is allowed in place of a query string value. Partial wildcards are not allowed in this position. Wildcards are not allowed in query string names.

See the OAuth 2.0 [URL Validation](https://fusionauth.io/docs/lifecycle/authenticate-users/oauth/url-validation.md) page for more detail.

`application.oauthConfiguration.authorizedResourceUris`Array<String>optionalAvailable since 1.67.0

An array of allowed resource server URIs for this application, per [RFC 8707 (Resource Indicators for OAuth 2.0)](https://www.rfc-editor.org/rfc/rfc8707.html). Defaults to an empty list.

Each URI must be an absolute URI and may not contain a fragment (`#`). Blank entries are ignored. When this list is non-empty, clients may pass a `resource` parameter during the OAuth authorize and token flows to request access tokens scoped to a specific resource server. Only URIs present in this list are accepted; any other value returns an `invalid_target` error.

When this list is empty (the default), any `resource` parameter sent by the client is silently ignored and existing application behavior is unchanged. This feature is entirely opt-in.

Examples of valid resource URIs:

*   `https://api.example.com`
*   `https://mcp.example.com/v2/api`

`application.oauthConfiguration.authorizedURLValidationPolicy`optionalAvailable since 1.43.0

Controls the validation policy for **application.oauthConfiguration.authorizedOriginURLs** and **application.oauthConfiguration.authorizedRedirectURLs**.

The possible values are:

*   `ExactMatch` - Only the configured values that do not contain wildcards are considered for validation. Values during OAuth 2.0 workflows must match a configured value exactly.
*   `AllowWildcards` - Configured values with and without wildcards are considered for validation. Values during OAuth 2.0 workflows can be matched against wildcard patterns or exactly match a configured value.

`application.oauthConfiguration.clientAuthenticationPolicy`StringoptionalAvailable since 1.28.0

Determines the client authentication requirements for the OAuth 2.0 Token endpoint.

The possible values are:

*   `Required` - The client must provide client credentials when using the Token endpoint. The `client_id` and `client_secret` may be provided using a Basic Authorization HTTP header, or by sending these parameters in the request body using POST data.
*   `NotRequired` - Providing client credentials is optional when using the Token endpoint.
*   `NotRequiredWhenUsingPKCE` - The client must provide client credentials when using the Token endpoint unless a valid PCKE `code_verifier` has been provided in the request body using POST data.

`application.oauthConfiguration.clientSecret`Stringoptional

The OAuth 2.0 client secret. If you leave this blank during a POST, a secure secret will be generated for you. If you leave this blank during PUT, the previous value will be maintained. For both POST and PUT you can provide a value and it will be stored.

`application.oauthConfiguration.consentMode`StringoptionalDefaults to AlwaysPromptAvailable since 1.50.0

Controls the policy for prompting a user to consent to requested OAuth scopes. This configuration only takes effect when **application.oauthConfiguration.relationship** is `ThirdParty`.

The possible values are:

*   `AlwaysPrompt` - Always prompt the user for consent.
*   `RememberDecision` - Remember previous consents; only prompt if the choice expires or if the requested or required scopes have changed. The duration of this persisted choice is controlled by the Tenant's **externalIdentifierConfiguration.rememberOAuthScopeConsentChoiceTimeToLiveInSeconds** value.
*   `NeverPrompt` - The user will be never be prompted to consent to requested OAuth scopes. Permission will be granted implicitly as if this were a `FirstParty` application. This configuration is meant for testing purposes only and should not be used in production.

`application.oauthConfiguration.debug`BooleanoptionalAvailable since 1.25.0

Whether or not FusionAuth will log a debug Event Log. This is particular useful for debugging the authorization code exchange with the Token endpoint during an Authorization Code grant.

`application.oauthConfiguration.deviceVerificationURL`StringoptionalAvailable since 1.11.0

The device verification URL to be used with the Device Code grant type, this field is required when `device_code` is enabled.

`application.oauthConfiguration.enabledGrants`Array<String>optionalAvailable since 1.5.0

The enabled grants for this application. In order to utilize a particular grant with the OAuth 2.0 endpoints you must have enabled the grant.

Supported values include:

*   `authorization_code`
*   `implicit`
*   `password`
*   `refresh_token`
*   `urn:ietf:params:oauth:grant-type:device_code` Available since 1.11.0

`application.oauthConfiguration.generateRefreshTokens`BooleanoptionalAvailable since 1.3.0

Determines if the OAuth 2.0 Token endpoint will generate a refresh token when the `offline_access` scope is requested.

`application.oauthConfiguration.logoutBehavior`StringoptionalAvailable since 1.11.0

Behavior when `/oauth2/logout` is called.

Valid values:

*   `RedirectOnly`: end the SSO session and redirect to the configured Logout URL or the passed in **post\_logout\_redirect\_uri** value.
*   `AllApplications`: end the SSO session and make a `GET` request to all configured Logout URLs for every application in the tenant.

`application.oauthConfiguration.logoutURL`Stringoptional

The logout URL for the Application. The exact use of this URL is determined by the **application.oauthConfiguration.logoutBehavior** setting.

When a `GET` request is made of this URL, it should end the application session.

You can learn more about this behavior in the [Logout And Session Management guide](https://fusionauth.io/docs/lifecycle/authenticate-users/logout-session-management.md).

`application.oauthConfiguration.proofKeyForCodeExchangePolicy`StringoptionalAvailable since 1.28.0

Determines the PKCE requirements when using the authorization code grant.

The possible values are:

*   `Required` - The client must provide a valid `code_verifier` on the request body when completing the authorization code grant.
*   `NotRequired` - Providing a `code_verifier` is optional when completing the authorization code grant.
*   `NotRequiredWhenUsingClientAuthentication` - The client must provide a valid `code_verifier` on the request body when completing the authorization code grant unless valid client credentials have been provided using a Basic Authorization HTTP header, or by sending these parameters in the request body using POST data.

`application.oauthConfiguration.providedScopePolicy.address.enabled`BooleanoptionalDefaults to trueAvailable since 1.50.0

Whether the `address` OAuth scope provided by FusionAuth is enabled for this application.

`application.oauthConfiguration.providedScopePolicy.address.required`BooleanoptionalAvailable since 1.50.0

Whether consent to the `address` OAuth scope provided by FusionAuth is required for this application when present on the OAuth request.

`application.oauthConfiguration.providedScopePolicy.email.enabled`BooleanoptionalDefaults to trueAvailable since 1.50.0

Whether the `email` OAuth scope provided by FusionAuth is enabled for this application.

`application.oauthConfiguration.providedScopePolicy.email.required`BooleanoptionalAvailable since 1.50.0

Whether consent to the `email` OAuth scope provided by FusionAuth is required for this application when present on the OAuth request.

`application.oauthConfiguration.providedScopePolicy.phone.enabled`BooleanoptionalDefaults to trueAvailable since 1.50.0

Whether the `phone` OAuth scope provided by FusionAuth is enabled for this application.

`application.oauthConfiguration.providedScopePolicy.phone.required`BooleanoptionalAvailable since 1.50.0

Whether consent to the `phone` OAuth scope provided by FusionAuth is required for this application when present on the OAuth request.

`application.oauthConfiguration.providedScopePolicy.profile.enabled`BooleanoptionalDefaults to trueAvailable since 1.50.0

Whether the `profile` OAuth scope provided by FusionAuth is enabled for this application.

`application.oauthConfiguration.providedScopePolicy.profile.required`BooleanoptionalAvailable since 1.50.0

Whether consent to the `profile` OAuth scope provided by FusionAuth is required for this application when present on the OAuth request.

`application.oauthConfiguration.relationship`StringoptionalDefaults to FirstPartyAvailable since 1.50.0

The application's relationship to the OAuth server.

The possible values are:

*   `FirstParty` - The application has the same owner as the authorization server. Consent to requested OAuth scopes is granted implicitly.
*   `ThirdParty` - The application is external to the authorization server. Users will be prompted to consent to requested OAuth scopes based on the application object's **oauthConfiguration.consentMode** value.

**Note:** To use third-party applications, you'll need an Essentials or Enterprise plan.

`application.oauthConfiguration.requireClientAuthentication`BooleanoptionalDEPRECATED

Determines if the OAuth 2.0 Token endpoint requires client authentication. If this is enabled, the client must provide client credentials when using the Token endpoint. The `client_id` and `client_secret` may be provided using a Basic Authorization HTTP header, or by sending these parameters in the request body using POST data.

Deprecated since 1.28.0

In version 1.28.0 and beyond, client authentication can be managed via **application.oauthConfiguration.clientAuthenticationPolicy**.

`application.oauthConfiguration.requireRegistration`BooleanoptionalAvailable since 1.28.0

When enabled the user will be required to be registered, or complete registration before redirecting to the configured callback in the authorization code grant or the implicit grant. This configuration does not affect any other grant, and does not affect the API usage.

`application.oauthConfiguration.scopeHandlingPolicy`StringoptionalDefaults to StrictAvailable since 1.50.0

Controls the policy for handling of OAuth scopes when populating JWTs and the UserInfo response.

The possible values are:

*   `Compatibility` - OAuth workflows will populate JWT and UserInfo claims in a manner compatible with versions of FusionAuth before version 1.50.0.
*   `Strict` - OAuth workflows will populate token and UserInfo claims according to the OpenID Connect 1.0 specification based on requested and consented scopes.

`application.oauthConfiguration.unknownScopePolicy`StringoptionalDefaults to RejectAvailable since 1.50.0

Controls the policy for handling unknown scopes on an OAuth request.

The possible values are:

*   `Allow` - Unknown scopes will be allowed on the request, passed through the OAuth workflow, and written to the resulting tokens without consent.
*   `Remove` - Unknown scopes will be removed from the OAuth workflow, but the workflow will proceed without them.
*   `Reject` - Unknown scopes will be rejected and cause the OAuth workflow to fail with an error.

`application.passwordlessConfiguration.enabled`BooleanoptionalAvailable since 1.5.0

Determines if passwordless login is enabled for this application.

`application.passwordlessConfiguration.emailLoginStrategy`StringoptionalAvailable since 1.64.0

The default login strategy by which the user will complete the passwordless login via email. The possible values are:

*   `ClickableLink` - send the user a clickable link that they can open in a web browser to authenticate
*   `FormField` - send the user a short code that they can enter into a form field to authenticate

`application.passwordlessConfiguration.phoneLoginStrategy`StringoptionalAvailable since 1.64.0

The default login strategy by which the user will complete the passwordless login via phone. The possible values are:

*   `ClickableLink` - send the user a clickable link that they can open in a web browser to authenticate
*   `FormField` - send the user a short code that they can enter into a form field to authenticate

`application.phoneConfiguration.forgotPasswordTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template that is used when sending a user a forgot password message.

`application.phoneConfiguration.identityUpdateTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when their phone number has been updated. The message will be sent to both their new and old phone numbers.

`application.phoneConfiguration.loginIdInUseOnCreateTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when another user attempts to create an account with their login Id.

**Note:** To use advanced threat detection messages, you'll need an Enterprise plan.

`application.phoneConfiguration.loginIdInUseOnUpdateTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when another user attempts to update an existing account to use their login Id.

**Note:** To use advanced threat detection messages, you'll need an Enterprise plan.

`application.phoneConfiguration.loginNewDeviceTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when they log in on a new device.

**Note:** To use advanced threat detection messages, you'll need an Enterprise plan.

`application.phoneConfiguration.loginSuspiciousTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when a suspicious login using their login Id occurs.

**Note:** To use advanced threat detection messages, you'll need an Enterprise plan.

`application.phoneConfiguration.passwordlessTemplateId`UUIDAvailable since 1.59.0

The Id of the Passwordless Message Template, sent to users when they start a passwordless login.

`application.phoneConfiguration.passwordResetSuccessTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when they have completed a 'forgot password' workflow and their password has been reset.

**Note:** To use advanced threat detection messages, you'll need an Enterprise plan.

`application.phoneConfiguration.passwordUpdateTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when their password has been updated.

**Note:** To use advanced threat detection messages, you'll need an Enterprise plan.

`application.phoneConfiguration.setPasswordTemplateId`UUIDoptionalAvailable since 1.59.0

The Id of the SMS Message Template used when a user must set their password manually after their account was created for them (by an admin, for example).

`application.phoneConfiguration.twoFactorMethodRemoveTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when a MFA method has been removed from their account.

**Note:** To use advanced threat detection messages, you'll need an Enterprise plan.

`application.phoneConfiguration.twoFactorMethodAddTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when a MFA method has been added to their account.

**Note:** To use advanced threat detection messages, you'll need an Enterprise plan.

`application.phoneConfiguration.verificationCompleteTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to notify a user that their phone number has been verified.

`application.phoneConfiguration.verificationTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send SMS messages to users to verify that their phone number is valid.

`application.registrationConfiguration.birthDate.enabled`BooleanoptionalAvailable since 1.4.0

Determines if the **birthDate** field will be included on the registration form.

`application.registrationConfiguration.birthDate.required`BooleanoptionalAvailable since 1.4.0

Determines if the **birthDate** field is required when displayed on the registration form.

`application.registrationConfiguration.confirmPassword`BooleanoptionalAvailable since 1.4.0

Determines if the password should be confirmed during self service registration, this means that the user will be required to type the password twice.

`application.registrationConfiguration.completeRegistration`BooleanoptionalDefaults to falseAvailable since 1.65.0

Users cannot self-register, but can complete missing information from an existing registration. Defaults to `false`.

When `true`, any registered user logging in to this application using hosted login pages is prompted to complete missing registration information based on the application's configured registration form.

If `application.registrationConfiguration.enabled` is `true`, `completeRegistration` is ignored. In that case, users can create a registration or complete profile information.

`application.registrationConfiguration.enabled`BooleanoptionalAvailable since 1.4.0

Determines if self service registration is enabled for this application. When this value is false, you may still use the Registration API, this only affects if the self service option is available during the OAuth 2.0 login.

Self service registration cannot be enabled on the FusionAuth application.

If `true`, any user logging in to this application using hosted login pages will automatically have a registration created, if they are not already registered.

`application.registrationConfiguration.firstName.enabled`BooleanoptionalAvailable since 1.4.0

Determines if the **firstName** field will be included on the registration form.

`application.registrationConfiguration.firstName.required`BooleanoptionalAvailable since 1.4.0

Determines if the **firstName** field is required when displayed on the registration form.

`application.registrationConfiguration.formId`UUIDoptionalAvailable since 1.18.0

The Id of an associated [Form](https://fusionauth.io/docs/apis/custom-forms/forms.md) when using `advanced` registration configuration type. This field is required when **application.registrationConfiguration.type** is set to `advanced`.

`application.registrationConfiguration.fullName.enabled`BooleanoptionalAvailable since 1.4.0

Determines if the **fullName** field will be included on the registration form.

`application.registrationConfiguration.fullName.required`BooleanoptionalAvailable since 1.4.0

Determines if the **fullName** field is required when displayed on the registration form.

`application.registrationConfiguration.lastName.enabled`BooleanoptionalAvailable since 1.4.0

Determines if the **lastName** field will be included on the registration form.

`application.registrationConfiguration.lastName.required`BooleanoptionalAvailable since 1.4.0

Determines if the **lastName** field is required when displayed on the registration form.

`application.registrationConfiguration.loginIdType`StringoptionalAvailable since 1.4.0

The unique login Id collected during registration. A value of `email` or `phoneNumber` is preferred because an email or phone number is unique. The possible values are:

*   `email`
*   `phoneNumber` Available since 1.59.0
*   `username`

`application.registrationConfiguration.middleName.enabled`BooleanoptionalAvailable since 1.4.0

Determines if the **middleName** field will be included on the registration form.

`application.registrationConfiguration.middleName.required`BooleanoptionalAvailable since 1.4.0

Determines if the **middleName** field is required when displayed on the registration form.

`application.registrationConfiguration.mobilePhone.enabled`BooleanoptionalAvailable since 1.4.0

Determines if the **mobilePhone** field will be included on the registration form.

`application.registrationConfiguration.mobilePhone.required`BooleanoptionalAvailable since 1.4.0

Determines if the **mobilePhone** field is required when displayed on the registration form.

`application.registrationConfiguration.preferredLanguages.enabled`BooleanoptionalAvailable since 1.47.0

Determines if the **preferredLanguages** field will be included on the registration form. The default form control will display all available [locales](https://fusionauth.io/docs/reference/data-types.md#locales).

`application.registrationConfiguration.preferredLanguages.required`BooleanoptionalAvailable since 1.47.0

Determines if the **preferredLanguages** field is required when displayed on the registration form.

`application.registrationConfiguration.type`StringoptionalAvailable since 1.18.0

The type of registration flow.

Supported values include:

*   `basic` - basic self registration options.
*   `advanced` - advanced usage of custom forms and requires a paid plan. Available since 1.18.0

`application.registrationDeletePolicy.unverified.enabled`BooleanoptionalAvailable since 1.13.0

Indicates that users without a verified registration for this application will have their registration permanently deleted after **application.registrationDeletePolicy.unverified.numberOfDaysToRetain** days.

`application.registrationDeletePolicy.unverified.numberOfDaysToRetain`IntegeroptionalAvailable since 1.13.0

The number of days from registration a user's registration will be retained before being deleted for not completing registration verification. This field is required when **application.registrationDeletePolicy.enabled** is set to `true`. Value must be greater than 0.

`application.samlv2Configuration.assertionEncryptionConfiguration.digestAlgorithm`StringoptionalAvailable since 1.47.0

The message digest algorithm to use when encrypting the symmetric key for transport. The possible values are:

*   `SHA1` - SHA-1 hashing algorithm
*   `SHA256` - SHA-256 hashing algorithm
*   `SHA384` - SHA-384 hashing algorithm
*   `SHA512` - SHA-512 hashing algorithm

Using `SHA256` or higher is recommended.

`application.samlv2Configuration.assertionEncryptionConfiguration.enabled`BooleanoptionalAvailable since 1.47.0

Determines if SAML assertion encryption is enabled for this Application.

`application.samlv2Configuration.assertionEncryptionConfiguration.encryptionAlgorithm`StringoptionalAvailable since 1.47.0

The symmetric key encryption algorithm that will be used to encrypt SAML assertions. A new symmetric key will be generated every time an assertion is encrypted. AES ciphers can operate in Cipher Block Chaining (CBC) or Galois/Counter Mode (GCM). The possible values are:

*   `AES128` - AES in CBC mode with a 128-bit key
*   `AES192` - AES in CBC mode with a 192-bit key
*   `AES256` - AES in CBC mode with a 256-bit key
*   `AES128GCM` - AES using GCM with a 128-bit key
*   `AES192GCM` - AES using GCM with a 192-bit key
*   `AES256GCM` - AES using GCM with a 256-bit key
*   `TripleDES` - Triple DES with a 192-bit key

Cryptography experts *strongly* recommend the use of AES using GCM if supported. Availability will depend on whether the SAML Service Provider (SP) supports those algorithms.

`application.samlv2Configuration.assertionEncryptionConfiguration.keyLocation`StringoptionalAvailable since 1.47.0

The location that the encrypted symmetric key information will be placed in the SAML response in relation to the `EncryptedData` element containing the encrypted assertion value. The possible values are:

*   `Child` - The `EncryptedKey` element will be wrapped in a `KeyInfo` element and added inside the `EncryptedData`
*   `Sibling` - The `EncryptedKey` element will be added to the document as a sibling of `EncryptedData`

This value will be dictated by the SAML Service Provider (SP) and which options it supports.

`application.samlv2Configuration.assertionEncryptionConfiguration.keyTransportAlgorithm`StringoptionalAvailable since 1.47.0

The encryption algorithm used to encrypt the symmetric key for transport in the SAML response. The possible values are:

*   `RSAv15` - RSA version 1.5
*   `RSA_OAEP` - RSA encryption with Optimal Asymmetric Encryption Padding using the mask generation function and hash specified by **application.samlv2Configuration.assertionEncryptionConfiguration.maskGenerationFunction**
*   `RSA_OAEP_MGF1P` - RSA encryption with Optimal Asymmetric Encryption Padding using the MGF1 mask generation function and SHA-1 hash

Use of `RSAv15` is not recommended but is available for backwards compatibility.

`application.samlv2Configuration.assertionEncryptionConfiguration.keyTransportEncryptionKeyId`UUIDoptionalAvailable since 1.47.0

The unique Id of the Key used to encrypt the symmetric key for transport in the SAML response. The selected Key must contain an RSA certificate.

This parameter is required when **application.samlv2Configuration.assertionEncryptionConfiguration.enabled** is set to `true`.

`application.samlv2Configuration.assertionEncryptionConfiguration.maskGenerationFunction`StringoptionalAvailable since 1.47.0

The mask generation function and hash function to use for the Optimal Asymmetric Encryption Padding when encrypting a symmetric key for transport. The possible values are:

*   `MGF1_SHA1` - MGF1 mask generation function with SHA-1 hash
*   `MGF1_SHA224` - MGF1 mask generation function with SHA-224 hash
*   `MGF1_SHA256` - MGF1 mask generation function with SHA-256 hash
*   `MGF1_SHA384` - MGF1 mask generation function with SHA-384 hash
*   `MGF1_SHA512` - MGF1 mask generation function with SHA-512 hash

This value is only used when the **application.samlv2Configuration.assertionEncryptionConfiguration.keyTransportAlgorithm** is set to **RSA\_OAEP**. **RSAv15** does not require a message digest function, and `RSA_OAEP_MGF1P` will always use `MGF1_SHA1` regardless of this value.

`application.samlv2Configuration.audience`StringoptionalAvailable since 1.6.0

The audience for the SAML response sent to back to the service provider from FusionAuth. Some service providers require different audience values than the `issuer` and this configuration option lets you change the `audience` in the response.

`application.samlv2Configuration.authorizedRedirectURLs`Array<String>requiredAvailable since 1.20.0

One or more authorized URLS that may be specified by the SAML v2 Service Provider in the Authentication request `[AssertionConsumerServiceURL]` element. If a requested URL is not in this list the request will be rejected by FusionAuth.

This is the URL that FusionAuth will send the SAML response during a SAML login request, this URL is also referred to as the Assertion Consumer Service or ACS). If the Authentication request does not contain the `[AssertionConsumerServiceURL]` element, the first URL found in this list will be used to send the SAML response back to the Service Provider.

If the **application.samlv2Configuration.initiatedLogin.enabled** is `true`, the particular URL where the user will end up after successful login can be configured by appending a parameter to the `Initiate login URL`. The parameter must be either **redirect\_uri** or **RelayState**. The value should be a URL encoded URL present in this field. If both **RelayState** and **redirect\_uri** are present **redirect\_uri** will be ignored in favor of **RelayState**.

`application.samlv2Configuration.callbackURL`StringoptionalAvailable since 1.6.0DEPRECATED

The URL of the callback (sometimes called the Assertion Consumer Service or ACS). This is where FusionAuth sends the browser after the user logs in via SAML.

Deprecated since 1.20.0

In version 1.20.0 and beyond, Callback URLs can be managed via **application.samlv2Configuration.authorizedRedirectURLs**.

`application.samlv2Configuration.debug`BooleanoptionalAvailable since 1.6.0

Whether or not FusionAuth will log SAML debug messages to the event log. This is useful for debugging purposes.

`application.samlv2Configuration.defaultVerificationKeyId`UUIDoptionalAvailable since 1.20.0

The verification key used to verify a signature when the SAML v2 Service Provider is using HTTP Redirect Bindings.

When HTTP POST Bindings are used, this is the default verification key used if a `[KeyInfo]` element is not found in the SAML AuthNRequest. If a `[KeyInfo]` element is found, Key Master will be used to resolve the key and this configuration will not be used to verify the request signature.

This parameter is required when **application.samlv2Configuration.requireSignedRequests** is set to `true`.

`application.samlv2Configuration.enabled`BooleanoptionalAvailable since 1.6.0

Determines if the SAML IdP is enabled for this Application.

`application.samlv2Configuration.issuer`StringrequiredAvailable since 1.6.0

An `issuer` identifies the service provider and allows FusionAuth to load the correct Application and SAML configuration. If you don't know the `issuer`, you can put anything in this field and FusionAuth will display an error message with the `issuer` from the service provider when you test the SAML login.

`application.samlv2Configuration.initiatedLogin.enabled`BooleanoptionalAvailable since 1.41.0

Determines if SAML v2 IdP initiated login is enabled for this application. See **application.samlv2Configuration.authorizedRedirectURLs** for information on which destination URLs are allowed.

`application.samlv2Configuration.initiatedLogin.nameIdFormat`StringoptionalAvailable since 1.41.0

The value sent in the AuthN response to the SAML v2 Service Provider in the NameID assertion.

`application.samlv2Configuration.keyId`UUIDoptionalAvailable since 1.6.0

The unique Id of the Key used to sign the SAML response. If you do not specify this property, FusionAuth will create a new key and associate it with this Application.

`application.samlv2Configuration.loginHintConfiguration.enabled`BooleanAvailable since 1.47.0

When enabled, FusionAuth will accept a username or email address as a login hint on a custom HTTP request parameter.

`application.samlv2Configuration.loginHintConfiguration.parameterName`StringoptionalAvailable since 1.47.0

The name of the login hint parameter provided by the service provider on an AuthnRequest. If this parameter is present, its value will be used to pre-populate the username field on the FusionAuth login form.

`application.samlv2Configuration.logout.behavior`StringoptionalAvailable since 1.25.0

The possible values are:

*   `AllParticipants` - each session participant that has enabled single logout will be sent a Logout Request
*   `OnlyOriginator` - no other session participants will be notified when a logout request is sent for this application

This configuration is functionally equivalent to the Logout Behavior found in the OAuth2 configuration.

`application.samlv2Configuration.logout.defaultVerificationKeyId`UUIDoptionalAvailable since 1.25.0

The unique Id of the Key used to verify the signature if the public key cannot be determined by the `KeyInfo` element when using POST bindings, or the key used to verify the signature when using HTTP Redirect bindings.

This parameter is required when **application.samlv2Configuration.logout.requireSignedRequests** is set to `true`.

`application.samlv2Configuration.logout.keyId`UUIDoptionalAvailable since 1.25.0

The unique Id of the Key used to sign the SAML Logout response.

When this parameter is omitted, the key defined by `application.samlv2Configuration.keyId` will be used.

`application.samlv2Configuration.logout.requireSignedRequests`BooleanrequiredAvailable since 1.25.0

Set this parameter equal to `true` to require the SAML v2 Service Provider to sign the Logout request. When this value is `true` all Logout requests missing a signature will be rejected.

When set to `true`, the parameter **application.samlv2Configuration.logout.defaultVerificationKeyId** is required.

`application.samlv2Configuration.logout.singleLogout.enabled`BooleanoptionalAvailable since 1.25.0

Whether or not SAML Single Logout for this SAML IdP is enabled.

`application.samlv2Configuration.logout.singleLogout.keyId`UUIDoptionalAvailable since 1.25.0

The unique Id of the Key used to sign the SAML Single Logout response.

When this parameter is omitted, the key defined by `application.samlv2Configuration.keyId` will be used.

`application.samlv2Configuration.logout.singleLogout.url`StringoptionalAvailable since 1.25.0

The URL at which you want to receive the `LogoutRequest` from FusionAuth.

Required if **application.samlv2Configuration.logout.singleLogout.enabled** is `true`.

`application.samlv2Configuration.logout.singleLogout.xmlSignatureC14nMethod`StringoptionalAvailable since 1.25.0

The XML signature canonicalization method used when digesting and signing the SAML Single Logout response. Unfortunately, many service providers do not correctly implement the XML signature specifications and force a specific canonicalization method. This setting allows you to change the canonicalization method to match the service provider. Often, service providers don't even document their required method. You might need to contact enterprise support at the service provider to figure out what method they use.

The possible values are:

*   `exclusive`: The URI for this method is `http://www.w3.org/2001/10/xml-exc-c14n#`
*   `exclusive_with_comments`: The URI for this method is `http://www.w3.org/2001/10/xml-exc-c14n#WithComments`
*   `inclusive`: The URI for this method is `http://www.w3.org/TR/2001/REC-xml-c14n-20010315`
*   `inclusive_with_comments`: The URI for this method is `http://www.w3.org/TR/2001/REC-xml-c14n-20010315#WithComments`

`application.samlv2Configuration.logout.xmlSignatureC14nMethod`StringoptionalAvailable since 1.25.0

The XML signature canonicalization method used when digesting and signing the SAML Single Logout response. Unfortunately, many service providers do not correctly implement the XML signature specifications and force a specific canonicalization method. This setting allows you to change the canonicalization method to match the service provider. Often, service providers don't even document their required method. You might need to contact enterprise support at the service provider to figure out what method they use.

The possible values are:

*   `exclusive`: The URI for this method is `http://www.w3.org/2001/10/xml-exc-c14n#`
*   `exclusive_with_comments`: The URI for this method is `http://www.w3.org/2001/10/xml-exc-c14n#WithComments`
*   `inclusive`: The URI for this method is `http://www.w3.org/TR/2001/REC-xml-c14n-20010315`
*   `inclusive_with_comments`: The URI for this method is `http://www.w3.org/TR/2001/REC-xml-c14n-20010315#WithComments`

`application.samlv2Configuration.logoutURL`StringoptionalAvailable since 1.6.0

The URL that the browser is taken to after the user logs out of the SAML service provider. Often service providers need this URL in order to correctly hook up single-logout.

This is also the URL that will be sent the SAML v2 LogoutResponse using the same bindings that were used to initiate the logout request with the IdP. For example, if POST bindings were used to initiate the logout request, POST bindings will be used for this LogoutResponse request.

`application.samlv2Configuration.requireSignedRequests`BooleanoptionalAvailable since 1.20.0

Set this parameter equal to `true` to require the SAML v2 Service Provider to sign the request. When this value is `true` all requests missing a signature will be rejected.

When set to `true`, the parameter **application.samlv2Configuration.defaultVerificationKeyId** is required.

`application.samlv2Configuration.xmlSignatureC14nMethod`StringoptionalAvailable since 1.6.0

The XML signature canonicalization method used when digesting and signing the SAML response. Unfortunately, many service providers do not correctly implement the XML signature specifications and force a specific canonicalization method. This setting allows you to change the canonicalization method to match the service provider. Often, service providers don't even document their required method. You might need to contact enterprise support at the service provider to figure out what method they use.

The possible values are:

*   `exclusive`: The URI for this method is `http://www.w3.org/2001/10/xml-exc-c14n#`
*   `exclusive_with_comments`: The URI for this method is `http://www.w3.org/2001/10/xml-exc-c14n#WithComments`
*   `inclusive`: The URI for this method is `http://www.w3.org/TR/2001/REC-xml-c14n-20010315`
*   `inclusive_with_comments`: The URI for this method is `http://www.w3.org/TR/2001/REC-xml-c14n-20010315#WithComments`

`application.samlv2Configuration.xmlSignatureLocation`StringAvailable since 1.21.0

The location to place the XML signature when signing a successful SAML response.

The possible values are:

*   `Assertion` - The XML signature will be added as a child element of the Assertion.
*   `Response` - The XML signature will be added as a child element of the Response.

In most cases the default configuration will be adequate. If you encounter a SAML v2 Service Provider that requires the signature to be a child of the Response, use this configuration to change the signature location. Prior to version `1.21.0`, the XML signature was always located as a child element of the Assertion when the response was successful.

`application.themeId`UUIDoptionalAvailable since 1.27.0

The unique Id of the theme to be used to style the login page and other end user templates.

**Note:** To use application themes, you'll need a paid plan.

`application.universalConfiguration.universal`BooleanoptionalAvailable since 1.58.0

Indicates if this application is a [universal application](https://fusionauth.io/docs/get-started/core-concepts/applications.md#universal-applications).

`application.verificationEmailTemplateId`UUIDoptional

The Id of the Email Template that is used to send the Registration Verification emails to users. If the **verifyRegistration** field is `true` this field is required.

`application.verifyRegistration`Booleanoptional

Whether or not registrations to this Application may be verified. When this is set to `true` the **verificationEmailTemplateId** parameter is also required.

`application.webAuthnConfiguration.bootstrapWorkflow.enabled`BooleanoptionalAvailable since 1.41.0

Whether the WebAuthn bootstrap workflow is enabled for this application. This overrides the tenant configuration. Has no effect if **application.webAuthnConfiguration.enabled** is `false`.

**Note:** To use WebAuthn, you'll need a license.

`application.webAuthnConfiguration.enabled`BooleanoptionalAvailable since 1.41.0

Indicates if this application enables WebAuthn workflows based on the configuration defined here or the Tenant WebAuthn configuration. If this is `false`, WebAuthn workflows will be enabled based on the Tenant configuration. If `true`, WebAuthn workflows will be enabled according to the configuration of this application.

**Note:** To use WebAuthn, you'll need a license.

`application.webAuthnConfiguration.reauthenticationWorkflow.enabled`BooleanoptionalAvailable since 1.41.0

Whether the WebAuthn reauthentication workflow is enabled for this application. This overrides the tenant configuration. Has no effect if **application.webAuthnConfiguration.enabled** is `false`.

**Note:** To use WebAuthn, you'll need a license.

`webhookIds`Array<UUID>optionalDEPRECATED

An array of Webhook Ids. For Webhooks that are not already configured for All Applications, specifying an Id on this request will indicate the associated Webhook should handle events for this application.

Removed in 1.37.0

In version 1.37.0 and beyond, Webhooks configuration can be managed in the [Tenant API](https://fusionauth.io/docs/apis/tenants.md).

*Example Request JSON*

```json
{
  "application": {
    "accessControlConfiguration": {
      "uiIPAccessControlListId": "11d49de7-69f6-46fc-8270-0b3aa626327a"
    },
    "active": true,
    "baseURL": "https://example.com",
    "cleanSpeakConfiguration": {
      "applicationIds": [
        "6b4253e0-cee0-47dd-973a-a27b9e23987c",
        "76a556ec-4ba8-4140-9085-555ee9a8bb1a"
      ],
      "usernameModeration": {
        "applicationId": "2338dc41-bed0-4cdb-8251-ac68701e9bc7",
        "enabled": true
      }
    },
    "data": {
      "externalApplication": "Acme. Customer Support Forum",
      "productOwner": "john@acme.com"
    },
    "emailConfiguration": {
      "emailUpdateEmailTemplateId": "ec3045c7-97d8-47f8-8725-61b93deacf5d",
      "emailVerificationEmailTemplateId": "e6c74b53-d43d-471e-ae7e-906456d0f341",
      "emailVerifiedEmailTemplateId": "1c3045c7-97d8-47f8-8725-61b93deacf5d",
      "forgotPasswordEmailTemplateId": "162b3719-3d71-4638-b9bf-f3e2093f7fe1",
      "loginIdInUseOnCreateEmailTemplateId": "1c3045c7-97d8-47f8-8725-61b93deacf5d",
      "loginIdInUseOnUpdateEmailTemplateId": "2c3045c7-97d8-47f8-8725-61b93deacf5d",
      "loginNewDeviceEmailTemplateId": "3c3045c7-97d8-47f8-8725-61b93deacf5d",
      "loginSuspiciousEmailTemplateId": "4c3045c7-97d8-47f8-8725-61b93deacf5d",
      "passwordlessEmailTemplateId": "162b3719-3d71-4638-b9bf-f3e2093f7fe1",
      "passwordResetSuccessEmailTemplateId": "5c3045c7-97d8-47f8-8725-61b93deacf5d",
      "passwordUpdateEmailTemplateId": "6c3045c7-97d8-47f8-8725-61b93deacf5d",
      "setPasswordEmailTemplateId": "e160cc59-a73e-4d95-8287-f82e5c541a5c",
      "twoFactorMethodAddEmailTemplateId": "7c3045c7-97d8-47f8-8725-61b93deacf5d",
      "twoFactorMethodRemoveEmailTemplateId": "8c3045c7-97d8-47f8-8725-61b93deacf5d"
    },
    "formConfiguration": {
      "adminRegistrationFormId": "e37dff97-9a94-48af-a0a6-c0bdfdd62c48"
    },
    "jwtConfiguration": {
      "accessTokenKeyId": "025233ca-d4f3-2aa4-eca9-7e4200e9b472",
      "enabled": true,
      "idTokenKeyId": "092dbedc-30af-4149-9c61-b578f2c72f59",
      "refreshTokenTimeToLiveInMinutes": 43200,
      "timeToLiveInSeconds": 3600
    },
    "lambdaConfiguration": {
      "accessTokenPopulateId": "cbb303a4-0968-479c-ad62-de46b3fad130",
      "idTokenPopulateId": "9987eec8-af37-4339-a969-bb462ff8b491",
      "samlv2PopulateId": "0e58eb2b-b39e-41ad-bc06-52cd189b5908",
      "userinfoPopulateId": "faaa713c-befd-43ee-9387-907828f80882"
    },
    "multiFactorConfiguration": {
      "email": {
        "templateId": "859f394b-22a6-4fa6-ba55-de700df9e950"
      },
      "loginPolicy": "Required",
      "sms": {
        "templateId": "17760f96-dca7-448b-9a8f-c49016aa7210"
      },
      "trustPolicy": "Any"
    },
    "name": "Forum",
    "loginConfiguration": {
      "allowTokenRefresh": false,
      "generateRefreshTokens": false,
      "requireAuthentication": true
    },
    "oauthConfiguration": {
      "authorizedOriginURLs": [
        "http://www.example.com"
      ],
      "authorizedRedirectURLs": [
        "http://www.example.com/oauth-callback"
      ],
      "authorizedURLValidationPolicy": "ExactMatch",
      "clientAuthenticationPolicy": "Required",
      "consentMode": "AlwaysPrompt",
      "enabledGrants": [
        "authorization_code",
        "refresh_token"
      ],
      "logoutBehavior": "AllApplications",
      "logoutURL": "http://www.example.com/logout",
      "proofKeyForCodeExchangePolicy": "NotRequired",
      "relationship": "FirstParty",
      "scopeHandlingPolicy": "Compatibility",
      "unknownScopePolicy": "Reject"
    },
    "phoneConfiguration": {
      "forgotPasswordTemplateId": "f90c8a8f-db77-4f2f-a3dd-5f692faf5d55",
      "identityUpdateTemplateId": "77df7e94-2dbf-44ab-b58c-06ac4224c449",
      "loginIdInUseOnCreateTemplateId": "7880dac6-809b-489e-8a69-363b043dd0f4",
      "loginIdInUseOnUpdateTemplateId": "de14b495-a358-4941-bb6b-0ddce04370ef",
      "loginNewDeviceTemplateId": "d77ac611-ddff-4a06-903c-fafe5c1f9f7a",
      "loginSuspiciousTemplateId": "73a8408a-e857-4ce2-82bb-d15b94d7c709",
      "passwordResetSuccessTemplateId": "6a0f3a7a-3511-4936-a546-3bd8f68dbdd3",
      "passwordUpdateTemplateId": "3ca81208-5678-434f-92b8-7fcc3b62bc7a",
      "passwordlessTemplateId": "e8449783-60a7-483f-8c66-bcdf0d05705f",
      "setPasswordTemplateId": "a6655c95-d94c-4dea-8191-0190f562bc39",
      "twoFactorMethodAddTemplateId": "c450521d-7f39-4a21-ba02-ced83225efcc",
      "twoFactorMethodRemoveTemplateId": "fba4fe64-3a29-45f8-895f-520d73d93659",
      "verificationCompleteTemplateId": "7b6b80bd-e3a5-42ff-b333-93ef37c192df",
      "verificationTemplateId": "c96ed02d-fbc6-4b27-9e74-54444747d18a"
    },
    "registrationDeletePolicy": {
      "unverified": {
        "enabled": true,
        "numberOfDaysToRetain": 30
      }
    },
    "universalConfiguration": {
      "universal": false
    },
    "webAuthnConfiguration": {
      "bootstrapWorkflow": {
        "enabled": false
      },
      "enabled": false,
      "reauthenticationWorkflow": {
        "enabled": false
      }
    }
  }
}
```

## Response

The response for this API contains the new information for the Application that was updated.

*Response Codes*

| Code | Description |
| --- | --- |
| 200 | The request was successful. The response will contain a JSON body. |
| 400 | The request was invalid and/or malformed. The response will contain an [Errors](https://fusionauth.io/docs/apis/errors.md) JSON Object with the specific errors. This status will also be returned if a paid FusionAuth license is required and is not present. |
| 401 | You did not supply a valid Authorization header. The header was omitted or your API key was not valid. The response will be empty. See [Authentication](https://fusionauth.io/docs/apis/authentication.md). |
| 404 | The object you are trying to update doesn't exist. The response will be empty. |
| 500 | There was an internal error. A stack trace is provided and logged in the FusionAuth log files. The response will be empty. |

#### Response Body

`application.accessControlConfiguration.uiIPAccessControlListId`UUIDAvailable since 1.30.0

The Id of the [IP Access Control List](https://fusionauth.io/docs/apis/ip-acl.md) limiting access to this application.

`application.active`BooleanDEPRECATED

Whether or not the Application is active.

Deprecated since 1.22.0

In version 1.22.0 and beyond, prefer the use of **state**.

`application.authenticationTokenConfiguration.enabled`Boolean

Whether or not Users can have Authentication Tokens associated with this Application.

`application.baseURL`StringAvailable since 1.68.0

The base URL used when rendering links in templates for this Application. When defined, this value overrides `tenant.baseURL`.

`application.cleanSpeakConfiguration.applicationIds`Array<UUID>

An array of UUIDs that map to the CleanSpeak applications for this Application. It is possible that a single Application in FusionAuth might have multiple Applications in CleanSpeak. For example, a FusionAuth Application for a game might have one CleanSpeak Application for usernames and another Application for chat.

This property is used when CleanSpeak sends user action notifications to FusionAuth (when users are disciplined for example). FusionAuth will translate the CleanSpeak ids to FusionAuth ids and then apply the user action.

`application.cleanSpeakConfiguration.enabled`Boolean

True if CleanSpeak integration is enabled. This setting is global and is not modifiable using this API.

`application.cleanSpeakConfiguration.usernameModeration.applicationId`UUID

The Id of the CleanSpeak application that usernames are sent to for moderation.

`application.cleanSpeakConfiguration.usernameModeration.enabled`Boolean

True if CleanSpeak username moderation is enabled.

`application.data`Object

An object that can hold any information about the Application that should be persisted.

`application.emailConfiguration.emailVerificationEmailTemplateId`UUIDoptionalAvailable since 1.19.0

The Id of the Email Template used to send emails to users to verify that their email address is valid. When configured, this value will take precedence over the same configuration from the Tenant when an application context is known.

`application.emailConfiguration.emailUpdateEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when their email address is updated. When configured, this value will take precedence over the same configuration from the Tenant when an application context is known.

`application.emailConfiguration.emailVerifiedEmailTemplateId`UUIDoptionalAvailable since 1.19.0

The Id of the Email Template used to notify a user that their email address has been verified. When configured, this value will take precedence over the same configuration from the Tenant when an application context is known.

`application.emailConfiguration.forgotPasswordEmailTemplateId`UUIDoptionalAvailable since 1.19.0

The Id of the Email Template that is used when a user is sent a forgot password email. When configured, this value will take precedence over the same configuration from the Tenant when an application context is known.

`application.emailConfiguration.loginIdInUseOnCreateEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when another user attempts to create an account with their login Id. When configured, this value will take precedence over the same configuration from the Tenant when an application context is known.

`application.emailConfiguration.loginIdInUseOnUpdateEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when another user attempts to update an existing account to use their login Id. When configured, this value will take precedence over the same configuration from the Tenant when an application context is known.

`application.emailConfiguration.loginNewDeviceEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when they log in on a new device. When configured, this value will take precedence over the same configuration from the Tenant when an application context is known.

`application.emailConfiguration.loginSuspiciousEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when a suspicious login occurs. When configured, this value will take precedence over the same configuration from the Tenant when an application context is known.

`application.emailConfiguration.passwordlessEmailTemplateId`UUIDoptionalAvailable since 1.19.0

The Id of the Passwordless Email Template, sent to users when they start a passwordless login. When configured, this value will take precedence over the same configuration from the Tenant when an application context is known.

`application.emailConfiguration.passwordResetSuccessEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when they have completed a 'forgot password' workflow and their password has been reset. When configured, this value will take precedence over the same configuration from the Tenant when an application context is known.

`application.emailConfiguration.passwordUpdateEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when their password has been updated. When configured, this value will take precedence over the same configuration from the Tenant when an application context is known.

`application.emailConfiguration.setPasswordEmailTemplateId`UUIDoptionalAvailable since 1.19.0

The Id of the Email Template that is used when a user had their account created for them and they must set their password manually and they are sent an email to set their password. When configured, this value will take precedence over the same configuration from the Tenant when an application context is known.

`application.emailConfiguration.twoFactorMethodAddEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when a MFA method has been added to their account. When configured, this value will take precedence over the same configuration from the Tenant when an application context is known.

`application.emailConfiguration.twoFactorMethodRemoveEmailTemplateId`UUIDoptionalAvailable since 1.30.0

The Id of the Email Template used to send emails to users when a MFA method has been removed from their account. When configured, this value will take precedence over the same configuration from the Tenant when an application context is known.

`application.formConfiguration.adminRegistrationFormId`UUIDAvailable since 1.20.0

The unique Id of the form to use for the Add and Edit User Registration form when used in the FusionAuth admin UI.

`application.formConfiguration.selfServiceFormConfiguration.requireCurrentPasswordOnPasswordChange`BooleanAvailable since 1.45.0

When enabled a user will be required to provide their current password when changing their password on a self-service account form.

`application.formConfiguration.selfServiceFormId`UUIDAvailable since 1.26.0

The unique Id of the form to enable authenticated users to manage their profile on the account page.

`application.id`UUID

The unique identifier for this Application.

`application.insertInstant`LongAvailable since 1.18.0

The [instant](https://fusionauth.io/docs/reference/data-types.md#instants) that the Application was added to the FusionAuth database.

`application.jwtConfiguration.accessTokenKeyId`UUIDAvailable since 1.6.0

The Id of the signing key used to sign the access token.

`application.jwtConfiguration.enabled`Boolean

Indicates if this application is using the JWT configuration defined here or the global JWT configuration defined by the Tenant. If this is `false` the signing algorithm configured in the Tenant will be used. If `true` the signing algorithm defined in this application will be used.

`application.jwtConfiguration.idTokenKeyId`UUIDAvailable since 1.6.0

The Id of the signing key used to sign the Id token.

`application.jwtConfiguration.refreshTokenExpirationPolicy`StringAvailable since 1.17.0

The Refresh Token expiration policy.

The possible values are:

*   `Fixed` - the expiration is calculated from the time the token is issued.
*   `SlidingWindow` - the expiration is calculated from the last time the token was used.
*   `SlidingWindowWithMaximumLifetime` - the expiration is calculated from the last time the token was used, or until the **maximumTimeToLiveInMinutes** is reached. Available since 1.46.0

`application.jwtConfiguration.refreshTokenOneTimeUseConfiguration.gracePeriodInSeconds`IntegerAvailable since 1.55.1

The length of time specified in seconds that a one-time use token can be reused.

This value must be greater than `0` and less than `86400` which is equal to 24 hours. Setting this value to `0` effectively disables the grace period which means a one-time token may not be reused. For security reasons, you should keep this value as small as possible, and only increase past `0` to improve reliability for an asynchronous or clustered integration that may require a brief grace period.

Note that one-time use tokens refreshed within a grace period are not considered for revocation when **tenant.jwtConfiguration.refreshTokenRevocationPolicy.onOneTimeTokenReuse** is `true`. When a token is reused within the grace period the current token will be returned on the API response and the token will not be rotated.

`application.jwtConfiguration.refreshTokenSlidingWindowConfiguration.maximumTimeToLiveInMinutes`IntegerAvailable since 1.46.0

The maximum lifetime of a refresh token when using a **refreshTokenExpirationPolicy** of `SlidingWindowWithMaximumLifetime`.

`application.jwtConfiguration.refreshTokenTimeToLiveInMinutes`IntegerAvailable since 1.2.0

The length of time in minutes the JWT refresh token will live before it is expired and is not able to be exchanged for a JWT.

`application.jwtConfiguration.refreshTokenUsagePolicy`StringAvailable since 1.17.0

The refresh token usage policy. The following are valid values:

*   `Reusable` - the token does not change after it was issued.
*   `OneTimeUse` - the token value will be changed each time the token is used to refresh a JWT. The client must store the new value after each usage.

`application.jwtConfiguration.timeToLiveInSeconds`Integer

The length of time in seconds the JWT will live before it is expired and no longer valid.

`application.lambdaConfiguration.accessTokenPopulateId`UUIDAvailable since 1.6.0

The Id of the Lambda that will be invoked when an access token is generated for this application. This will be utilized during OAuth2 and OpenID Connect authentication requests as well as when an access token is generated for the Login API.

`application.lambdaConfiguration.idTokenPopulateId`UUIDAvailable since 1.6.0

The Id of the Lambda that will be invoked when an Id token is generated for this application during an OpenID Connect authentication request.

`application.lambdaConfiguration.multiFactorRequirementId`UUIDoptionalAvailable since 1.62.0

The Id of the lambda that will be invoked during logins, password changes, and MFA Status API calls to perform various validations to decide whether to challenge the user on one of their MFA methods.

`application.lambdaConfiguration.samlv2PopulateId`UUIDAvailable since 1.6.0

The Id of the Lambda that will be invoked when a SAML response is generated during a SAML authentication request.

`application.lambdaConfiguration.selfServiceRegistrationValidationId`UUIDAvailable since 1.43.0

The unique Id of the lambda that will be used to perform additional validation on registration form steps.

`application.lambdaConfiguration.userinfoPopulateId`UUIDAvailable since 1.50.0

The Id of the Lambda that will be invoked when a UserInfo response is generated for this application.

`application.lastUpdateInstant`LongAvailable since 1.18.0

The [instant](https://fusionauth.io/docs/reference/data-types.md#instants) that the Application was last updated in the FusionAuth database.

`application.name`String

The name of the Application.

`application.loginConfiguration.allowTokenRefresh`BooleanAvailable since 1.5.0

Indicates if a JWT may be refreshed using a Refresh Token for this application. This configuration is separate from issuing new Refresh Tokens which is controlled by the `generateRefreshTokens` parameter. This configuration indicates specifically if an existing Refresh Token may be used to request a new JWT using the [Refresh API](https://fusionauth.io/docs/apis/jwt/refresh-a-jwt.md).

`application.loginConfiguration.generateRefreshTokens`BooleanAvailable since 1.5.0

Indicates if a Refresh Token should be issued from the Login API.

`application.loginConfiguration.requireAuthentication`BooleanAvailable since 1.5.0

Indicates if the Login API should require an API key. If you set this value to `false` and your FusionAuth API is on a public network, anyone may attempt to use the Login API.

`application.multiFactorConfiguration.email.templateId`UUIDAvailable since 1.26.0

The Id of the email template that is used when notifying a user to complete a multi-factor authentication request.

`application.multiFactorConfiguration.sms.templateId`UUIDAvailable since 1.26.0

The Id of the SMS template that is used when notifying a user to complete a multi-factor authentication request.

`application.multiFactorConfiguration.voice.templateId`UUIDAvailable since 1.65.0

The Id of the voice template that is used when notifying a user to complete a multi-factor authentication request.

`application.oauthConfiguration.authorizedOriginURLs`Array<String>

An array of URLs that are the authorized origins for this Application.

When this configuration is omitted, all HTTP origins are allowed to use the browser based grants and the HTTP response header of `X-Frame-Options: DENY` will be added to each response to disallow iframe loading.

`application.oauthConfiguration.authorizedRedirectURLs`Array<String>

An array of URLs that are the authorized redirect URLs for this Application.

`application.oauthConfiguration.authorizedURLValidationPolicy`StringAvailable since 1.43.0

Controls the validation policy for **application.oauthConfiguration.authorizedOriginURLs** and **application.oauthConfiguration.authorizedRedirectURLs**.

The possible values are:

*   `ExactMatch` - Only the configured values that do not contain wildcards are considered for validation. Values during OAuth 2.0 workflows must match a configured value exactly.
*   `AllowWildcards` - Configured values with and without wildcards are considered for validation. Values during OAuth 2.0 workflows can be matched against wildcard patterns or exactly match a configured value.

`application.oauthConfiguration.clientAuthenticationPolicy`StringAvailable since 1.28.0

Determines the client authentication requirements for the OAuth 2.0 Token endpoint.

The possible values are:

*   `Required` - The client must provide client credentials when using the Token endpoint. The `client_id` and `client_secret` may be provided using a Basic Authorization HTTP header, or by sending these parameters in the request body using POST data.
*   `NotRequired` - Providing client credentials is optional when using the Token endpoint.
*   `NotRequiredWhenUsingPKCE` - The client must provide client credentials when using the Token endpoint unless a valid PCKE `code_verifier` has been provided in the request body using POST data.

`application.oauthConfiguration.clientId`String

The OAuth client Id of the Application.

`application.oauthConfiguration.clientSecret`String

The OAuth client secret.

`application.oauthConfiguration.consentMode`StringAvailable since 1.50.0

Controls the policy for prompting a user to consent to requested OAuth scopes. This configuration only takes effect when **application.oauthConfiguration.relationship** is `ThirdParty`.

The possible values are:

*   `AlwaysPrompt` - Always prompt the user for consent.
*   `RememberDecision` - Remember previous consents; only prompt if the choice expires or if the requested or required scopes have changed. The duration of this persisted choice is controlled by the Tenant's **externalIdentifierConfiguration.rememberOAuthScopeConsentChoiceTimeToLiveInSeconds** value.
*   `NeverPrompt` - The user will be never be prompted to consent to requested OAuth scopes. Permission will be granted implicitly as if this were a `FirstParty` application. This configuration is meant for testing purposes only and should not be used in production.

`application.oauthConfiguration.debug`BooleanAvailable since 1.25.0

Whether or not FusionAuth will log a debug Event Log. This is particular useful for debugging the authorization code exchange with the Token endpoint during an Authorization Code grant.

`application.oauthConfiguration.deviceVerificationURL`StringAvailable since 1.11.0

The device verification URL to be used with the Device Code grant type.

`application.oauthConfiguration.enabledGrants`Array<String>Available since 1.5.0

The enabled grants for this application.

Supported values include:

*   `authorization_code`
*   `implicit`
*   `password`
*   `refresh_token`
*   `urn:ietf:params:oauth:grant-type:device_code` Available since 1.11.0

`application.oauthConfiguration.generateRefreshTokens`BooleanAvailable since 1.3.0

Determines if the OAuth 2.0 Token endpoint will generate a refresh token when the `offline_access` scope is requested.

`application.oauthConfiguration.logoutBehavior`StringAvailable since 1.11.0

Behavior when `/oauth2/logout` is called.

Valid values:

*   `RedirectOnly`: end the SSO session and redirect to the configured Logout URL or the passed in **post\_logout\_redirect\_uri** value.
*   `AllApplications`: end the SSO session and make a `GET` request to all configured Logout URLs for every application in the tenant.

`application.oauthConfiguration.logoutURL`String

The logout URL for the Application. FusionAuth will redirect to this URL after the user logs out of OAuth.

`application.oauthConfiguration.proofKeyForCodeExchangePolicy`StringAvailable since 1.28.0

Determines the PKCE requirements when using the authorization code grant.

The possible values are:

*   `Required` - The client must provide a valid `code_verifier` on the request body when completing the authorization code grant.
*   `NotRequired` - Providing a `code_verifier` is optional when completing the authorization code grant.
*   `NotRequiredWhenUsingClientAuthentication` - The client must provide a valid `code_verifier` on the request body when completing the authorization code grant unless valid client credentials have been provided using a Basic Authorization HTTP header, or by sending these parameters in the request body using POST data.

`application.oauthConfiguration.providedScopePolicy.address.enabled`BooleanAvailable since 1.50.0

Whether the `address` OAuth scope provided by FusionAuth is enabled for this application.

`application.oauthConfiguration.providedScopePolicy.address.required`BooleanAvailable since 1.50.0

Whether consent to the `address` OAuth scope provided by FusionAuth is required for this application when present on the OAuth request.

`application.oauthConfiguration.providedScopePolicy.email.enabled`BooleanAvailable since 1.50.0

Whether the `email` OAuth scope provided by FusionAuth is enabled for this application.

`application.oauthConfiguration.providedScopePolicy.email.required`BooleanAvailable since 1.50.0

Whether consent to the `email` OAuth scope provided by FusionAuth is required for this application when present on the OAuth request.

`application.oauthConfiguration.providedScopePolicy.phone.enabled`BooleanAvailable since 1.50.0

Whether the `phone` OAuth scope provided by FusionAuth is enabled for this application.

`application.oauthConfiguration.providedScopePolicy.phone.required`BooleanAvailable since 1.50.0

Whether consent to the `phone` OAuth scope provided by FusionAuth is required for this application when present on the OAuth request.

`application.oauthConfiguration.providedScopePolicy.profile.enabled`BooleanAvailable since 1.50.0

Whether the `profile` OAuth scope provided by FusionAuth is enabled for this application.

`application.oauthConfiguration.providedScopePolicy.profile.required`BooleanAvailable since 1.50.0

Whether consent to the `profile` OAuth scope provided by FusionAuth is required for this application when present on the OAuth request.

`application.oauthConfiguration.relationship`StringAvailable since 1.50.0

The application's relationship to the OAuth server.

The possible values are:

*   `FirstParty` - The application has the same owner as the authorization server. Consent to requested OAuth scopes is granted implicitly.
*   `ThirdParty` - The application is external to the authorization server. Users will be prompted to consent to requested OAuth scopes based on **application.oauthConfiguration.consentMode**.

`application.oauthConfiguration.requireClientAuthentication`BooleanAvailable since 1.3.0DEPRECATED

Determines if the OAuth 2.0 Token endpoint requires client authentication. If this is enabled, the client must provide client credentials when using the Token endpoint. The `client_id` and `client_secret` may be provided using a Basic Authorization HTTP header, or by sending these parameters in the request body using POST data.

In version 1.28.0 and beyond, client authentication can be managed via **application.oauthConfiguration.clientAuthenticationPolicy**.

`application.oauthConfiguration.requireRegistration`BooleanAvailable since 1.28.0

Determines if the user will be required to be registered, or complete registration before redirecting to the configured callback in the authorization code grant or the implicit grant. This configuration does not affect any other grant, and does not affect the API usage.

`application.oauthConfiguration.scopeHandlingPolicy`StringAvailable since 1.50.0

Controls the policy for handling of OAuth scopes when populating JWTs and the UserInfo response.

The possible values are:

*   `Compatibility` - OAuth workflows will populate JWT and UserInfo claims in a manner compatible with versions of FusionAuth before version 1.50.0.
*   `Strict` - OAuth workflows will populate token and UserInfo claims according to the OpenID Connect 1.0 specification based on requested and consented scopes.

`application.oauthConfiguration.unknownScopePolicy`StringAvailable since 1.50.0

Controls the policy for handling unknown scopes on an OAuth request.

The possible values are:

*   `Allow` - Unknown scopes will be allowed on the request, passed through the OAuth workflow, and written to the resulting tokens without consent.
*   `Remove` - Unknown scopes will be removed from the OAuth workflow, but the workflow will proceed without them.
*   `Reject` - Unknown scopes will be rejected and cause the OAuth workflow to fail with an error.

`application.passwordlessConfiguration.enabled`BooleanAvailable since 1.5.0

Determines if passwordless login is enabled for this application.

`application.passwordlessConfiguration.emailLoginStrategy`StringAvailable since 1.64.0

The default login strategy by which the user will complete the passwordless login via email. The possible values are:

*   `ClickableLink` - send the user a clickable link that they can open in a web browser to authenticate
*   `FormField` - send the user a short code that they can enter into a form field to authenticate

`application.passwordlessConfiguration.phoneLoginStrategy`StringAvailable since 1.64.0

The default login strategy by which the user will complete the passwordless login via phone. The possible values are:

*   `ClickableLink` - send the user a clickable link that they can open in a web browser to authenticate
*   `FormField` - send the user a short code that they can enter into a form field to authenticate

`application.phoneConfiguration.forgotPasswordTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template that is used when sending a user a forgot password message.

`application.phoneConfiguration.identityUpdateTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when their phone number has been updated. The message will be sent to both their new and old phone numbers.

`application.phoneConfiguration.loginIdInUseOnCreateTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when another user attempts to create an account with their login Id.

`application.phoneConfiguration.loginIdInUseOnUpdateTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when another user attempts to update an existing account to use their login Id.

`application.phoneConfiguration.loginNewDeviceTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when they log in on a new device.

`application.phoneConfiguration.loginSuspiciousTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when a suspicious login using their login Id occurs.

`application.phoneConfiguration.passwordlessTemplateId`UUIDAvailable since 1.59.0

The Id of the Passwordless Message Template, sent to users when they start a passwordless login.

`application.phoneConfiguration.passwordResetSuccessTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when they have completed a 'forgot password' workflow and their password has been reset.

`application.phoneConfiguration.passwordUpdateTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when their password has been updated.

`application.phoneConfiguration.setPasswordTemplateId`UUIDoptionalAvailable since 1.59.0

The Id of the SMS Message Template used when a user must set their password manually after their account was created for them (by an admin, for example).

`application.phoneConfiguration.twoFactorMethodRemoveTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when a MFA method has been removed from their account.

`application.phoneConfiguration.twoFactorMethodAddTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send a message to a user when a MFA method has been added to their account.

`application.phoneConfiguration.verificationCompleteTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to notify a user that their phone number has been verified.

`application.phoneConfiguration.verificationTemplateId`UUIDAvailable since 1.59.0

The Id of the Message Template used to send SMS messages to users to verify that their phone number is valid.

`application.registrationConfiguration.birthDate.enabled`BooleanAvailable since 1.4.0

Determines if the **birthDate** field will be included on the registration form.

`application.registrationConfiguration.birthDate.required`BooleanAvailable since 1.4.0

Determines if the **birthDate** field is required when displayed on the registration form.

`application.registrationConfiguration.confirmPassword`BooleanAvailable since 1.4.0

Determines if the password should be confirmed during self service registration, this means that the user will be required to type the password twice.

`application.registrationConfiguration.completeRegistration`BooleanAvailable since 1.65.0

Users cannot self-register, but can complete missing information from an existing registration. Defaults to `false`.

When `true`, any registered user logging in to this application using hosted login pages is prompted to complete missing registration information based on the application's configured registration form.

If `application.registrationConfiguration.enabled` is `true`, `completeRegistration` is ignored. In that case, users can create a registration or complete profile information.

`application.registrationConfiguration.enabled`BooleanAvailable since 1.4.0

Determines if self service registration is enabled for this application. When this value is false, you may still use the Registration API, this only affects if the self service option is available during the OAuth 2.0 login.

`application.registrationConfiguration.firstName.enabled`BooleanAvailable since 1.4.0

Determines if the **firstName** field will be included on the registration form.

`application.registrationConfiguration.firstName.required`BooleanAvailable since 1.4.0

Determines if the **firstName** field is required when displayed on the registration form.

`application.registrationConfiguration.formId`UUIDAvailable since 1.18.0

The Id of an associated [Form](https://fusionauth.io/docs/apis/custom-forms/forms.md) when using `advanced` registration configuration type.

`application.registrationConfiguration.fullName.enabled`BooleanAvailable since 1.4.0

Determines if the **fullName** field will be included on the registration form.

`application.registrationConfiguration.fullName.required`BooleanAvailable since 1.4.0

Determines if the **fullName** field is required when displayed on the registration form.

`application.registrationConfiguration.lastName.enabled`BooleanAvailable since 1.4.0

Determines if the **lastName** field will be included on the registration form.

`application.registrationConfiguration.lastName.required`BooleanAvailable since 1.4.0

Determines if the **lastName** field is required when displayed on the registration form.

`application.registrationConfiguration.loginIdType`StringAvailable since 1.4.0

The unique login Id that will be collected during registration. A value of `email` or `phoneNumber` is preferred because an email or phone number is unique. The possible values are:

*   `email`
*   `phoneNumber` Available since 1.59.0
*   `username`

`application.registrationConfiguration.middleName.enabled`BooleanAvailable since 1.4.0

Determines if the **middleName** field will be included on the registration form.

`application.registrationConfiguration.middleName.required`BooleanAvailable since 1.4.0

Determines if the **middleName** field is required when displayed on the registration form.

`application.registrationConfiguration.mobilePhone.enabled`BooleanAvailable since 1.4.0

Determines if the **mobilePhone** field will be included on the registration form.

`application.registrationConfiguration.mobilePhone.required`BooleanAvailable since 1.4.0

Determines if the **mobilePhone** field is required when displayed on the registration form.

`application.registrationConfiguration.preferredLanguages.enabled`BooleanAvailable since 1.47.0

Determines if the **preferredLanguages** field will be included on the registration form.

`application.registrationConfiguration.preferredLanguages.required`BooleanAvailable since 1.47.0

Determines if the **preferredLanguages** field is required when displayed on the registration form.

`application.registrationConfiguration.type`StringAvailable since 1.18.0

The type of registration flow.

Supported values include:

*   `basic` - the basic self registration options available prior to version `1.18.0`.
*   `advanced` - advanced usage of custom forms, requires a paid plan.

`application.registrationDeletePolicy.unverified.enabled`BooleanAvailable since 1.13.0

Indicates that users without a verified registration for this application will have their registration permanently deleted after **application.registrationDeletePolicy.unverified.numberOfDaysToRetain** days.

`application.registrationDeletePolicy.unverified.enabledInstant`LongAvailable since 1.48.0

The [instant](https://fusionauth.io/docs/reference/data-types.md#instants) that this policy was enabled.

User registrations created before this time will not be eligible to be deleted. This means that you can safely enable this feature and the policy will only be enforced for user registrations created after this policy was enabled.

Please note that prior to version `1.48.0`, when enabling this policy all unverified user registrations are eligible for deletion.

`application.registrationDeletePolicy.unverified.numberOfDaysToRetain`IntegerAvailable since 1.13.0

The number of days from registration a user's registration will be retained before being deleted for not completing registration verification. Value must be greater than 0.

`application.roles`Array

An array of Role objects.

`application.roles[x].description`String

A description of the role.

`application.roles[x].id`UUID

The Id of the Role.

`application.roles[x].name`String

The name of the Role.

`application.roles[x].isDefault`Boolean

Whether or not the Role is a default role. A default role is automatically assigned to a user during registration if no roles are provided.

`application.roles[x].isSuperRole`Boolean

Whether or not the Role is a considered to be a super user role. This is a marker to indicate that it supersedes all other roles. FusionAuth will attempt to enforce this contract when using the web UI, it is not enforced programmatically when using the API.

`application.samlv2Configuration.assertionEncryptionConfiguration.digestAlgorithm`StringAvailable since 1.47.0

The message digest algorithm to use when encrypting the symmetric key for transport. The possible values are:

*   `SHA1` - SHA-1 hashing algorithm
*   `SHA256` - SHA-256 hashing algorithm
*   `SHA384` - SHA-384 hashing algorithm
*   `SHA512` - SHA-512 hashing algorithm

`application.samlv2Configuration.assertionEncryptionConfiguration.enabled`BooleanAvailable since 1.47.0

Whether or SAML assertion encryption is enabled for this Application.

`application.samlv2Configuration.assertionEncryptionConfiguration.encryptionAlgorithm`StringAvailable since 1.47.0

The symmetric key encryption algorithm that will be used to encrypt SAML assertions. A new symmetric key will be generated every time an assertion is encrypted. AES ciphers can operate in Cipher Block Chaining (CBC) or Galois/Counter Mode (GCM). The possible values are:

*   `AES128` - AES in CBC mode with a 128-bit key
*   `AES192` - AES in CBC mode with a 192-bit key
*   `AES256` - AES in CBC mode with a 256-bit key
*   `AES128GCM` - AES using GCM with a 128-bit key
*   `AES192GCM` - AES using GCM with a 192-bit key
*   `AES256GCM` - AES using GCM with a 256-bit key
*   `TripleDES` - Triple DES with a 192-bit key

`application.samlv2Configuration.assertionEncryptionConfiguration.keyLocation`StringAvailable since 1.47.0

The location that the encrypted symmetric key information will be placed in the SAML response in relation to the `EncryptedData` element containing the encrypted assertion value. The possible values are:

*   `Child` - The `EncryptedKey` element will be wrapped in a `KeyInfo` element and added inside the `EncryptedData`
*   `Sibling` - The `EncryptedKey` element will be added to the document as a sibling of `EncryptedData`

`application.samlv2Configuration.assertionEncryptionConfiguration.keyTransportAlgorithm`StringAvailable since 1.47.0

The encryption algorithm used to encrypt the symmetric key for transport in the SAML response. The possible values are:

*   `RSAv15` - RSA version 1.5
*   `RSA_OAEP` - RSA encryption with Optimal Asymmetric Encryption Padding using the mask generation function and hash specified by **application.samlv2Configuration.assertionEncryptionConfiguration.maskGenerationFunction**
*   `RSA_OAEP_MGF1P` - RSA encryption with Optimal Asymmetric Encryption Padding using the MGF1 mask generation function and SHA-1 hash

`application.samlv2Configuration.assertionEncryptionConfiguration.keyTransportEncryptionKeyId`UUIDAvailable since 1.47.0

The unique Id of the Key used to encrypt the symmetric key for transport in the SAML response.

`application.samlv2Configuration.assertionEncryptionConfiguration.maskGenerationFunction`StringAvailable since 1.47.0

The mask generation function and hash function to use for the Optimal Asymmetric Encryption Padding when encrypting a symmetric key for transport. The possible values are:

*   `MGF1_SHA1` - MGF1 mask generation function with SHA-1 hash
*   `MGF1_SHA224` - MGF1 mask generation function with SHA-224 hash
*   `MGF1_SHA256` - MGF1 mask generation function with SHA-256 hash
*   `MGF1_SHA384` - MGF1 mask generation function with SHA-384 hash
*   `MGF1_SHA512` - MGF1 mask generation function with SHA-512 hash

This value is only used when the **application.samlv2Configuration.assertionEncryptionConfiguration.keyTransportAlgorithm** is set to **RSA\_OAEP**. **RSAv15** does not require a message digest function, and `RSA_OAEP_MGF1P` will always use `MGF1_SHA1` regardless of this value.

`application.samlv2Configuration.audience`StringAvailable since 1.6.0

The audience for the SAML response sent to back to the service provider from FusionAuth. Some service providers require different audience values than the `issuer` and this configuration option lets you change the `audience` in the response.

`application.samlv2Configuration.authorizedRedirectURLs`Array<String>Available since 1.20.0

One or more authorized URLS that may be specified by the SAML v2 Service Provider in the Authentication request `[AssertionConsumerServiceURL]` element. If a requested URL is not in this list the request will be rejected by FusionAuth.

This is the URL that FusionAuth will send the SAML response during a SAML login request, this URL is also referred to as the Assertion Consumer Service or ACS). If the Authentication request does not contain the `[AssertionConsumerServiceURL]` element, the first URL found in this list will be used to send the SAML response back to the Service Provider.

`application.samlv2Configuration.callbackURL`StringAvailable since 1.6.0DEPRECATED

The URL of the callback (sometimes called the Assertion Consumer Service or ACS). This is where FusionAuth sends the browser after the user logs in via SAML.

This field is preserved for backwards compatibility and may be removed in a future release. This is the first value found in the **authorizedRedirectURLs** parameter.

`application.samlv2Configuration.debug`BooleanAvailable since 1.6.0

Whether or not FusionAuth will log SAML debug messages to the event log. This is useful for debugging purposes.

`application.samlv2Configuration.defaultVerificationKeyId`UUIDAvailable since 1.20.0

The verification key used to verify a signature when the SAML v2 Service Provider is using HTTP Redirect Bindings.

When HTTP POST Bindings are used, this is the default verification key used if a `[KeyInfo]` element is not found in the SAML AuthNRequest. If a `[KeyInfo]` element is found, Key Master will be used to resolve the key and this configuration will not be used to verify the request signature.

`application.samlv2Configuration.enabled`BooleanAvailable since 1.6.0

Whether or not the SAML IdP for this Application is enabled or not.

`application.samlv2Configuration.initiatedLogin.enabled`BooleanAvailable since 1.41.0

Determines if SAML v2 IdP initiated login is enabled for this application.

`application.samlv2Configuration.initiatedLogin.nameIdFormat`StringAvailable since 1.41.0

The value sent in the AuthN response to the SAML v2 Service Provider in the NameID assertion.

`application.samlv2Configuration.issuer`StringAvailable since 1.6.0

The issuer that identifies the service provider and allows FusionAuth to load the correct Application and SAML configuration.

`application.samlv2Configuration.keyId`UUIDAvailable since 1.6.0

The unique Id of the Key used to sign the SAML response.

`application.samlv2Configuration.loginHintConfiguration.enabled`BooleanAvailable since 1.47.0

Determines if support for a login hint sent by a SAML service provider is enabled for this application.

`application.samlv2Configuration.loginHintConfiguration.parameterName`StringAvailable since 1.47.0

The name of the login hint parameter provided by the service provider on an AuthnRequest. If this parameter is present, its value will be used to pre-populate the username field on the FusionAuth login form.

`application.samlv2Configuration.logout.behavior`StringAvailable since 1.25.0

The possible values are:

*   `AllParticipants` - each session participant that has enabled single logout will be sent a Logout Request
*   `OnlyOriginator` - no other session participants will be notified when a logout request is sent for this application

This configuration is functionally equivalent to the Logout Behavior found in the OAuth2 configuration.

`application.samlv2Configuration.logout.defaultVerificationKeyId`UUIDAvailable since 1.25.0

The unique Id of the Key used to verify the signature if the public key cannot be determined by the `KeyInfo` element when using POST bindings, or the key used to verify the signature when using HTTP Redirect bindings.

`application.samlv2Configuration.logout.keyId`UUIDAvailable since 1.25.0

The unique Id of the Key used to sign the SAML Logout response.

`application.samlv2Configuration.logout.requireSignedRequests`BooleanAvailable since 1.25.0

When this value is `true` all Logout requests missing a signature will be rejected.

`application.samlv2Configuration.logout.singleLogout.enabled`BooleanAvailable since 1.25.0

Whether or not SAML Single Logout for this SAML IdP is enabled.

`application.samlv2Configuration.logout.singleLogout.keyId`UUIDAvailable since 1.25.0

The unique Id of the Key used to sign the SAML Single Logout response.

`application.samlv2Configuration.logout.singleLogout.url`StringAvailable since 1.25.0

The URL at which you want to receive the `LogoutRequest` from FusionAuth.

`application.samlv2Configuration.logout.singleLogout.xmlSignatureC14nMethod`StringAvailable since 1.25.0

The XML signature canonicalization method used when digesting and signing the Single Logout response.

The possible values are:

*   `exclusive`: The URI for this method is `http://www.w3.org/2001/10/xml-exc-c14n#`
*   `exclusive_with_comments`: The URI for this method is `http://www.w3.org/2001/10/xml-exc-c14n#WithComments`
*   `inclusive`: The URI for this method is `http://www.w3.org/TR/2001/REC-xml-c14n-20010315`
*   `inclusive_with_comments`: The URI for this method is `http://www.w3.org/TR/2001/REC-xml-c14n-20010315#WithComments`

`application.samlv2Configuration.logout.xmlSignatureC14nMethod`StringAvailable since 1.25.0

The XML signature canonicalization method used when digesting and signing the Logout response.

The possible values are:

*   `exclusive`: The URI for this method is `http://www.w3.org/2001/10/xml-exc-c14n#`
*   `exclusive_with_comments`: The URI for this method is `http://www.w3.org/2001/10/xml-exc-c14n#WithComments`
*   `inclusive`: The URI for this method is `http://www.w3.org/TR/2001/REC-xml-c14n-20010315`
*   `inclusive_with_comments`: The URI for this method is `http://www.w3.org/TR/2001/REC-xml-c14n-20010315#WithComments`

`application.samlv2Configuration.logoutURL`StringAvailable since 1.6.0

The URL that the browser is taken to after the user logs out of the SAML service provider.

`application.samlv2Configuration.requireSignedRequests`BooleanAvailable since 1.20.0

When this value is `true` all requests missing a signature will be rejected.

`application.samlv2Configuration.xmlSignatureC14nMethod`StringAvailable since 1.6.0

The XML signature canonicalization method used when digesting and signing the SAML response.

The possible values are:

*   `exclusive`: The URI for this method is `http://www.w3.org/2001/10/xml-exc-c14n#`
*   `exclusive_with_comments`: The URI for this method is `http://www.w3.org/2001/10/xml-exc-c14n#WithComments`
*   `inclusive`: The URI for this method is `http://www.w3.org/TR/2001/REC-xml-c14n-20010315`
*   `inclusive_with_comments`: The URI for this method is `http://www.w3.org/TR/2001/REC-xml-c14n-20010315#WithComments`

`application.samlv2Configuration.xmlSignatureLocation`StringAvailable since 1.21.0

The location to place the XML signature when signing the SAML response.

The possible values are:

*   `Assertion` - The XML signature will be added as a child element of the Assertion.
*   `Response` - The XML signature will be added as a child element of the Response.

`application.scopes`ArrayAvailable since 1.50.0

An array of OAuth Scope objects.

`application.scopes[x].defaultConsentDetail`StringAvailable since 1.50.0

The default detail to display on the OAuth consent screen if one cannot be found in the theme.

`application.scopes[x].defaultConsentMessage`StringAvailable since 1.50.0

The default message to display on the OAuth consent screen if one cannot be found in the theme.

`application.scopes[x].description`StringAvailable since 1.50.0

A description of the OAuth Scope for internal use.

`application.scopes[x].id`UUIDAvailable since 1.50.0

The Id of the OAuth Scope.

`application.scopes[x].insertInstant`LongAvailable since 1.50.0

The [instant](https://fusionauth.io/docs/reference/data-types.md#instants) that the OAuth Scope was added to the FusionAuth database.

`application.scopes[x].lastUpdateInstant`LongAvailable since 1.50.0

The [instant](https://fusionauth.io/docs/reference/data-types.md#instants) that the OAuth Scope was last updated in the FusionAuth database.

`application.scopes[x].name`StringAvailable since 1.50.0

The name of the OAuth Scope. This is the value that will be used to request the scope in OAuth workflows.

`application.scopes[x].required`BooleanAvailable since 1.50.0

Determines if the OAuth Scope is required when requested in an OAuth workflow.

`application.state`StringAvailable since 1.22.0

The current state of the application. The following are valid values:

*   `Active` - The Application is active.
*   `Inactive` - The Application is not active. An Application can not be modified or authenticated against when inactive.

`application.tenantId`UUID

The unique Id of the Tenant.

`application.themeId`UUIDAvailable since 1.27.0

The unique Id of the theme to be used to style the login page and other end user templates.

`application.universalConfiguration.universal`BooleanoptionalAvailable since 1.58.0

Indicates if this application is a [universal application](https://fusionauth.io/docs/get-started/core-concepts/applications.md#universal-applications).

`application.verificationEmailTemplateId`UUID

The Id of the Email Template that is used to send the Registration Verification emails to users.

`application.verifyRegistration`Boolean

Whether or not registrations to this Application may be verified.

`application.webAuthnConfiguration.bootstrapWorkflow.enabled`BooleanAvailable since 1.41.0

Whether the WebAuthn bootstrap workflow is enabled for this application. This overrides the tenant configuration. Has no effect if **application.webAuthnConfiguration.enabled** is `false`.

`application.webAuthnConfiguration.enabled`BooleanAvailable since 1.41.0

Indicates if this application enables WebAuthn workflows based on the configuration defined here or the Tenant WebAuthn configuration. If this is `false`, WebAuthn workflows are enabled based on the Tenant configuration. If `true`, WebAuthn workflows are enabled according to the configuration of this application.

`application.webAuthnConfiguration.reauthenticationWorkflow.enabled`BooleanAvailable since 1.41.0

Whether the WebAuthn reauthentication workflow is enabled for this application. This overrides the tenant configuration. Has no effect if **application.webAuthnConfiguration.enabled** is `false`.

*Example Response JSON for a Single Application*

```json
{
  "application": {
    "id": "8174f72f-5ecd-4eae-8de8-7fef597b3473",
    "accessControlConfiguration": {
      "uiIPAccessControlListId": "11d49de7-69f6-46fc-8270-0b3aa626327a"
    },
    "active": true,
    "baseURL": "https://example.com",
    "cleanSpeakConfiguration": {
      "applicationIds": [
        "6b4253e0-cee0-47dd-973a-a27b9e23987c",
        "76a556ec-4ba8-4140-9085-555ee9a8bb1a"
      ],
      "enabled": true,
      "usernameModeration": {
        "applicationId": "2338dc41-bed0-4cdb-8251-ac68701e9bc7",
        "enabled": true
      }
    },
    "data": {
      "externalApplication": "Acme. Customer Support Forum",
      "productOwner": "john@acme.com"
    },
    "emailConfiguration": {
      "emailUpdateEmailTemplateId": "ec3045c7-97d8-47f8-8725-61b93deacf5d",
      "emailVerificationEmailTemplateId": "e6c74b53-d43d-471e-ae7e-906456d0f341",
      "emailVerifiedEmailTemplateId": "1c3045c7-97d8-47f8-8725-61b93deacf5d",
      "forgotPasswordEmailTemplateId": "162b3719-3d71-4638-b9bf-f3e2093f7fe1",
      "loginIdInUseOnCreateEmailTemplateId": "1c3045c7-97d8-47f8-8725-61b93deacf5d",
      "loginIdInUseOnUpdateEmailTemplateId": "2c3045c7-97d8-47f8-8725-61b93deacf5d",
      "loginNewDeviceEmailTemplateId": "3c3045c7-97d8-47f8-8725-61b93deacf5d",
      "loginSuspiciousEmailTemplateId": "4c3045c7-97d8-47f8-8725-61b93deacf5d",
      "passwordlessEmailTemplateId": "162b3719-3d71-4638-b9bf-f3e2093f7fe1",
      "passwordResetSuccessEmailTemplateId": "5c3045c7-97d8-47f8-8725-61b93deacf5d",
      "passwordUpdateEmailTemplateId": "6c3045c7-97d8-47f8-8725-61b93deacf5d",
      "setPasswordEmailTemplateId": "e160cc59-a73e-4d95-8287-f82e5c541a5c",
      "twoFactorMethodAddEmailTemplateId": "7c3045c7-97d8-47f8-8725-61b93deacf5d",
      "twoFactorMethodRemoveEmailTemplateId": "8c3045c7-97d8-47f8-8725-61b93deacf5d"
    },
    "formConfiguration": {
      "adminRegistrationFormId": "e37dff97-9a94-48af-a0a6-c0bdfdd62c48"
    },
    "insertInstant": 1595361142909,
    "jwtConfiguration": {
      "accessTokenKeyId": "025233ca-d4f3-2aa4-eca9-7e4200e9b472",
      "enabled": true,
      "idTokenKeyId": "092dbedc-30af-4149-9c61-b578f2c72f59",
      "refreshTokenTimeToLiveInMinutes": 43200,
      "timeToLiveInSeconds": 3600
    },
    "lambdaConfiguration": {
      "accessTokenPopulateId": "cbb303a4-0968-479c-ad62-de46b3fad130",
      "idTokenPopulateId": "9987eec8-af37-4339-a969-bb462ff8b491",
      "samlv2PopulateId": "0e58eb2b-b39e-41ad-bc06-52cd189b5908",
      "userinfoPopulateId": "faaa713c-befd-43ee-9387-907828f80882"
    },
    "lastUpdateInstant": 1595361143101,
    "multiFactorConfiguration": {
      "email": {
        "templateId": "859f394b-22a6-4fa6-ba55-de700df9e950"
      },
      "loginPolicy": "Required",
      "sms": {
        "templateId": "17760f96-dca7-448b-9a8f-c49016aa7210"
      },
      "trustPolicy": "Any"
    },
    "name": "Forum",
    "loginConfiguration": {
      "allowTokenRefresh": false,
      "generateRefreshTokens": false,
      "requireAuthentication": true
    },
    "oauthConfiguration": {
      "authorizedOriginURLs": [
        "http://www.example.com"
      ],
      "authorizedRedirectURLs": [
        "http://www.example.com/oauth-callback"
      ],
      "authorizedURLValidationPolicy": "ExactMatch",
      "clientAuthenticationPolicy": "Required",
      "clientId": "8174f72f-5ecd-4eae-8de8-7fef597b3473",
      "clientSecret": "+fcXet9Iu2kQi61yWD9Tu4ReZ113P6yEAkr32v6WKOQ=",
      "consentMode": "AlwaysPrompt",
      "debug": false,
      "enabledGrants": [
        "authorization_code",
        "refresh_token"
      ],
      "generateRefreshTokens": true,
      "logoutBehavior": "AllApplications",
      "logoutURL": "http://www.example.com/logout",
      "proofKeyForCodeExchangePolicy": "NotRequired",
      "providedScopePolicy": {
        "address": {
          "enabled": true,
          "required": false
        },
        "email": {
          "enabled": true,
          "required": false
        },
        "phone": {
          "enabled": true,
          "required": false
        },
        "profile": {
          "enabled": true,
          "required": false
        }
      },
      "relationship": "FirstParty",
      "requireClientAuthentication": true,
      "requireRegistration": false,
      "scopeHandlingPolicy": "Compatibility",
      "unknownScopePolicy": "Reject"
    },
    "passwordlessConfiguration": {
      "enabled": false,
      "emailLoginStrategy": "ClickableLink",
      "phoneLoginStrategy": "FormField"
    },
    "phoneConfiguration": {
      "forgotPasswordTemplateId": "f90c8a8f-db77-4f2f-a3dd-5f692faf5d55",
      "identityUpdateTemplateId": "77df7e94-2dbf-44ab-b58c-06ac4224c449",
      "loginIdInUseOnCreateTemplateId": "7880dac6-809b-489e-8a69-363b043dd0f4",
      "loginIdInUseOnUpdateTemplateId": "de14b495-a358-4941-bb6b-0ddce04370ef",
      "loginNewDeviceTemplateId": "d77ac611-ddff-4a06-903c-fafe5c1f9f7a",
      "loginSuspiciousTemplateId": "73a8408a-e857-4ce2-82bb-d15b94d7c709",
      "passwordResetSuccessTemplateId": "6a0f3a7a-3511-4936-a546-3bd8f68dbdd3",
      "passwordUpdateTemplateId": "3ca81208-5678-434f-92b8-7fcc3b62bc7a",
      "passwordlessTemplateId": "e8449783-60a7-483f-8c66-bcdf0d05705f",
      "setPasswordTemplateId": "a6655c95-d94c-4dea-8191-0190f562bc39",
      "twoFactorMethodAddTemplateId": "c450521d-7f39-4a21-ba02-ced83225efcc",
      "twoFactorMethodRemoveTemplateId": "fba4fe64-3a29-45f8-895f-520d73d93659",
      "verificationCompleteTemplateId": "7b6b80bd-e3a5-42ff-b333-93ef37c192df",
      "verificationTemplateId": "c96ed02d-fbc6-4b27-9e74-54444747d18a"
    },
    "registrationConfiguration": {
      "enabled": false,
      "type": "basic"
    },
    "registrationDeletePolicy": {
      "unverified": {
        "enabled": true,
        "enabledInstant": 1698772159415,
        "numberOfDaysToRetain": 30
      }
    },
    "roles": [
      {
        "description": "Administrators that have access to everything",
        "id": "ce485a91-906f-4615-af75-81d37dc71e90",
        "name": "admin",
        "isDefault": false
      },
      {
        "description": "Normal users that have access to nothing",
        "id": "ce485a91-906f-4615-af75-81d37dc71e91",
        "name": "user",
        "isDefault": true
      }
    ],
    "samlv2Configuration": {
      "audience": "example.com",
      "authorizedRedirectURLs": [
        "https://www.example.com/samlv2/acs"
      ],
      "callbackURL": "https://www.example.com/samlv2/acs",
      "debug": false,
      "defaultVerificationKeyId": "be980e51-c94c-49f9-bfb5-90571c34a791",
      "enabled": true,
      "initiatedLogin": {
        "enabled": false,
        "nameIdFormat": "urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"
      },
      "issuer": "example.com",
      "keyId": "0a52ace4-3016-47da-906a-f7d272fbdaed",
      "loginHintConfiguration": {
        "enabled": true,
        "parameterName": "login_hint"
      },
      "logout": {
        "behavior": "OnlyOriginator",
        "defaultVerificationKeyId": "0a52ace4-3016-47da-906a-f7d272fbdaed",
        "keyId": "0a52ace4-3016-47da-906a-f7d272fbdaed",
        "requireSignedRequests": true,
        "singleLogout": {
          "enabled": true,
          "keyId": "0a52ace4-3016-47da-906a-f7d272fbdaed",
          "url": "https://www.example.com/logout",
          "xmlSignatureC14nMethod": "exclusive_with_comments"
        },
        "xmlSignatureC14nMethod": "exclusive_with_comments"
      },
      "logoutURL": "https://www.example.com/logout",
      "requireSignedRequests": true,
      "xmlSignatureC14nMethod": "exclusive_with_comments",
      "xmlSignatureLocation": "Assertion"
    },
    "scopes": [
      {
        "defaultConsentDetail": "Your calendar data will be used to provide you enhanced reminders",
        "defaultConsentMessage": "Read your calendar",
        "id": "b1e5afb2-e18f-4174-82c2-1fa7975ac598",
        "name": "calendar:read",
        "required": true
      },
      {
        "defaultConsentDetail": "Create new events to remind you of upcoming discussions",
        "defaultConsentMessage": "Write your calendar",
        "id": "a9ae0a21-be87-4f04-850d-20a75020448b",
        "name": "calendar:write",
        "required": false
      }
    ],
    "state": "Active",
    "tenantId": "50435e55-6e95-4d54-96d0-9c953dd53eeb",
    "universalConfiguration": {
      "universal": false
    },
    "verifyRegistration": false,
    "webAuthnConfiguration": {
      "bootstrapWorkflow": {
        "enabled": false
      },
      "enabled": false,
      "reauthenticationWorkflow": {
        "enabled": false
      }
    }
  }
}
```