Clientes OAuth 2

De MoodleDocs

Nota: Urgente de Traducir. ¡ Anímese a traducir esta muy importante página !.     ( y otras páginas muy importantes que urge traducir)

¿Qué son los cliente OAuth 2?

¡Nueva característica
en Moodle 5.3 !

An OAuth 2 client is an external app, such as a mobile app or another system, that an administrator registers so it can connect to Moodle's new REST API. Users sign in from the app and approve the access it asks for. The app then works within that user's existing permissions.

Nota: Los clientes Auth 2 son una característica separada de los Servicios OAuth 2, que le permiten a Moodle conectar con servicios externos, como por ejemplo, Google o Microsoft.


¿Qué necesita el sitio?

  • The site's Composer dependencies must be installed. Without them, the OAuth 2 clients page doesn't appear in Site administration.
  • Managing clients needs the capability moodle/site:manageoauth2clients, which the Manager role has by default.

How do I register a client?

  1. Go to Site administration > Server > OAuth 2 clients.
  2. Click Create client.
  3. Enter a Name and, if you like, a Description.
  4. Choose a Type:
    • Confidential: the app runs on a server you control and can safely hold a secret.
    • Public: the app runs on a device you don't control, such as a mobile app, and can't hold a secret.
  5. Choose the Primary flows:
    • Authorization Code: a user signs in and approves access.
    • Client credentials (confidential clients only): for machine-to-machine connections, with no user signing in. Moodle shows a warning when you select it.
  6. If you chose Authorization Code, add at least one Callback URI. Callback URIs must use HTTPS, except for localhost. Click Add another callback URI to add more.
  7. For a confidential client that uses Authorization Code, choose whether to Require PKCE. Public clients always require it.
  8. Select at least one scope.
  9. Click Create client.
Warning: Client type and primary flows can't be changed after the client is created.


Warning: With Client credentials, the app acts as the main site administrator, limited only by the client's scopes. Anyone with the client ID and a secret can use it, so use this flow only for trusted integrations.


How do I manage client secrets?

Confidential clients need a secret to connect. After you create a confidential client, Moodle opens its Manage secrets page. You can also click Manage secrets next to the client at any time. Public clients don't use secrets.

  • Click Generate secret. The secret is shown only once, with a Copy button, so copy it straight away.
  • A client can have up to 2 active secrets, so you can add a new secret before you revoke the old one.
  • Secrets expire after 1 year.
  • To revoke a secret, click Revoke. Apps using that secret lose access straight away, and this can't be undone.
  • A warning icon appears next to a confidential client that has no active secret.

How do I edit a client?

Click Edit next to the client. The page shows the client's status, type, primary flows and ID, followed by the settings you can change: the name, description, callback URIs, scopes and, for confidential clients, the PKCE setting. Make your changes, then click Save changes.

The edit page for a public OAuth 2 client, showing its status, type, primary flows and ID, with two scopes selected
The edit page for a public OAuth 2 client

Scope changes apply the next time the app gets or refreshes a token.

How do I disable or delete a client?

  • Click Disable next to the client to stop it working straight away: its tokens stop working and its secrets can't be used. The client, its settings and its secrets are kept.
  • Click Enable to turn a disabled client back on. Apps then need to connect again, because their old tokens stay invalid.
  • Click Delete to remove a disabled client permanently, with its secrets, callback URIs and users' approvals. Delete only appears once a client is disabled, and this can't be undone.

What do users see when an app connects?

  1. The app sends the user to Moodle to log in. Guest access and sign-up aren't offered on this page.
  2. A user who is already logged in sees Continue as with their name, and can change user if needed.
  3. The user sees the scopes the app is asking for, and approves them all or cancels. Scopes they've already approved are listed separately.
  4. Moodle sends the user back to the app.

If the user has already approved all the requested scopes, Moodle doesn't ask again. Users who are already logged in go straight back to the app.

To stop an app's access, an administrator can disable or delete its client. This affects everyone who uses the app.

How long do secrets and tokens last?

  • Client secrets last 1 year. Generate a new secret before the old one expires.
  • Access tokens last 1 hour. Apps using Authorization Code also get a refresh token, which lasts 1 month, so they can get new access tokens without the user signing in again.
  • Apps using Client credentials don't get a refresh token. They request a new access token when they need one.

See also