When you create an OAuth 2.0 client, it is enabled by default. You can disable an OAuth 2.0 client if needed. API consumers cannot use disabled OAuth 2.0 clients for authentication.
On the
Policies
page, click the
Authorization
tab.
The
OAuth 2.0 Clients
section displays all the OAuth clients and their details.
To enable or disable a client, click the
Actions
menu in the row that contains the OAuth 2.0 client, and select
Enable Client
or
Disable Client
.
Alternatively, you can double-click an OAuth 2.0 client, and click
Enable Client
or
Disable Client
.
When there are multiple bad attempts to get the token or when there are other violations for an OAuth 2.0 client, the OAuth2 Identify Provider sets the status of the client to locked. API consumers cannot use locked OAuth 2.0 clients for authentication.