> ## Documentation Index
> Fetch the complete documentation index at: https://docs.relayapp.im/llms.txt
> Use this file to discover all available pages before exploring further.

# Set the agent's redirects and scopes

> Replace the redirects, the scopes, or both. A redirect is an https URL
(http only on localhost) with no fragment; the `redirect_uri` of a
login must match one exactly. An agent may have up to 10. Scopes are
`openid`, `profile`, `email` and `phone`; `openid` and `profile` are
always kept.



## OpenAPI

````yaml /api-reference/openapi.mint.yaml patch /v1/oauth2_client
openapi: 3.1.0
info:
  title: Relay API
  version: 1.0.0
  description: >-
    Create conversations between users and agents.


    Send multipart Messages, manage Chats, upload Attachments, and receive agent
    events.
  license:
    name: Proprietary
    identifier: LicenseRef-Proprietary
servers:
  - url: https://api.relayapp.im
    description: Relay API
security:
  - BearerAuth: []
tags:
  - name: Agents
    x-page-title: Agents
    description: >-
      Read who owns the authenticated agent, manage who is always and never
      allowed to message it, manage its OAuth2 client for Log in with Relay, and
      delete existing developer-managed agents.
  - name: Chats
    x-page-title: Chats
    description: Create, retrieve, and update direct or group chats.
  - name: Messages
    x-page-title: Messages
    description: Send and retrieve messages, replies, reactions, and receipts.
  - name: Attachments
    x-page-title: Attachments
    description: Allocate, upload, retrieve, and delete attachment bytes.
  - name: Blocked Handles
    x-page-title: Blocked Handles
    description: |-
      Block or unblock registered Relay Handles. In a direct Chat, a block in
      either direction means a Message is stored for the sender and never
      delivered to the other party, silently. In a group Chat, blocking is one
      way: you do not receive Messages from a Handle you blocked, but that
      Handle still receives yours, and every other member receives as normal.
      Blocking does not delete existing Chats or history.
  - name: Contact Card
    x-page-title: Contact Card
    description: Manage the authenticated agent's Relay contact card.
  - name: Webhooks
    x-page-title: Webhooks
    description: Register signed webhook destinations.
  - name: WebSocket
    description: Receive agent events over a durable acknowledged WebSocket.
  - name: Contacts
    description: Request a user Contact.
  - name: Directory
    description: Find public agents by category or task. No credential is needed.
  - name: Payments
    x-page-title: Payments
    description: Ask a person to pay, on your organization's own connected Stripe account.
  - name: Calls
    description: >-
      Start, answer, end and read individual user-agent audio calls. Call events
      use Relay's normal agent event delivery, and both Contacts join the
      authenticated Call room as WebRTC audio participants.
paths:
  /v1/oauth2_client:
    patch:
      tags:
        - Agents
      summary: Set the agent's redirects and scopes
      description: |-
        Replace the redirects, the scopes, or both. A redirect is an https URL
        (http only on localhost) with no fragment; the `redirect_uri` of a
        login must match one exactly. An agent may have up to 10. Scopes are
        `openid`, `profile`, `email` and `phone`; `openid` and `profile` are
        always kept.
      operationId: updateOAuth2Client
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              additionalProperties: false
              minProperties: 1
              properties:
                redirect_uris:
                  type: array
                  maxItems: 10
                  items:
                    type: string
                    format: uri
                scopes:
                  type: array
                  items:
                    $ref: '#/components/schemas/OAuth2Scope'
      responses:
        '200':
          description: The updated client
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OAuth2ClientResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/AgentOnly'
        '404':
          $ref: '#/components/responses/NotFound'
        '500':
          $ref: '#/components/responses/InternalServerError'
        '503':
          $ref: '#/components/responses/LoginUnavailable'
      security:
        - BearerAuth: []
components:
  schemas:
    OAuth2Scope:
      type: string
      description: >-
        An OpenID Connect scope a Log in with Relay client may ask for.
        `birthdate` asks for the person's birthday as the OpenID `birthdate`
        claim (YYYY-MM-DD, or 0000-MM-DD when they gave no year).
      enum:
        - openid
        - profile
        - email
        - phone
        - birthdate
    OAuth2ClientResponse:
      type: object
      additionalProperties: false
      required:
        - client
      properties:
        client:
          $ref: '#/components/schemas/OAuth2Client'
        client_secret:
          type: string
          description: >-
            The client secret, starting `rel_cs_`. Present only when the client
            was just made or its secret was just reset.
    OAuth2Client:
      type: object
      additionalProperties: false
      required:
        - client_id
        - redirect_uris
        - scopes
        - created_at
        - updated_at
      properties:
        client_id:
          type: string
          description: The agent's ID.
        redirect_uris:
          type: array
          items:
            type: string
            format: uri
        scopes:
          type: array
          items:
            $ref: '#/components/schemas/OAuth2Scope'
        created_at:
          type: string
          format: date-time
        updated_at:
          type: string
          format: date-time
    ErrorResponse:
      type: object
      required:
        - error
        - success
      properties:
        error:
          $ref: '#/components/schemas/ErrorDetail'
        success:
          type: boolean
          description: Always false for error responses
        trace_id:
          type: string
          description: Unique trace ID for request tracing and debugging
    ErrorDetail:
      type: object
      required:
        - status
        - code
        - message
        - doc_url
      properties:
        status:
          type: integer
          description: HTTP status code (e.g., 400, 404, 500)
        code:
          $ref: '#/components/schemas/ErrorCode'
        message:
          type: string
          description: Human-readable error message
        doc_url:
          type: string
          description: Link to documentation for this error code
        retry_after:
          type: integer
          description: >-
            Number of seconds to wait before retrying. Only present on 429 rate
            limit errors.
    ErrorCode:
      type: integer
      description: Relay API error code.
  responses:
    BadRequest:
      description: Invalid request - validation error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Unauthorized:
      description: Unauthorized - missing or invalid authentication
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    AgentOnly:
      description: >-
        Forbidden - the route requires an active agent principal (error code
        `2003`).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    NotFound:
      description: Resource not found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    InternalServerError:
      description: Internal server error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    LoginUnavailable:
      description: >-
        Log in with Relay is not available on this server (error code `3006`).
        Nothing was changed.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >
        Bearer token authentication. Include your API token in the Authorization
        header.


        Format: `Authorization: Bearer <your-token>`

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.