Manage OAuth Apps

Download skillThe skill is a reference md and part of wix-manage skill. You can use the following command to add the full wix-manage skill to your project:
Copy

An OAuth app is a site-level credential holder. Its id is the client_id (the two terms are interchangeable — Wix uses appId in provisioning responses, clientId in token requests, and id in the OAuth Apps API; they all refer to the same value).

When a headless site is provisioned it gets one OAuth app automatically (see Create Headless Site); use this recipe to create additional apps, inspect existing ones, or update their redirect configuration.

client_id is not a secret — it is a public identifier safe to embed in frontend code. The visitor token it mints is also non-privileged: it represents an anonymous visitor, not an admin. The client_secret is different — shown once in the Headless Settings dashboard, never returned by the API, and rotation is dashboard-only.


Create an OAuth App

Endpoint: POST https://www.wixapis.com/oauth-app/v1/oauth-apps

Copy

Response:

Copy

id is the OAuth client_id. After creating the app, retrieve the client_secret from the Headless Settings dashboard.


Get an OAuth App

Endpoint: GET https://www.wixapis.com/oauth-app/v1/oauth-apps/{id}

Copy

Query OAuth Apps

Endpoint: POST https://www.wixapis.com/oauth-app/v1/oauth-apps/query

Copy

Returns all OAuth apps for the site.


Update an OAuth App

Endpoint: PATCH https://www.wixapis.com/oauth-app/v1/oauth-apps/{id}

Update requires an explicit mask.paths — omitting it silently updates nothing.

Updatable fields: name, description, loginUrl, logoutUrl, allowedRedirectUris, allowedRedirectDomains, technology.

Copy

Key Fields

FieldNotes
idThe OAuth client_id. Read-only.
nameRequired on create. 2–256 chars.
loginUrlExternal login redirect. Defaults to Wix login if omitted.
logoutUrlCalled when the user logs out at Wix.
allowedRedirectUrisExact-match URIs for post-authentication redirect. Max 20.
allowedRedirectDomainsDomain-level allow-list for non-auth redirects (e.g. checkout). Max 20.
applicationTypeWEB_APP, MOBILE, OTHER

Minting a Visitor Token

Once you have a client_id, frontends use it to mint an anonymous visitor token for buyer-facing API calls.

Endpoint: POST https://www.wixapis.com/oauth2/token

Copy
Copy

Use the access_token as the Authorization header on subsequent API calls.

Never re-mint anonymous on every load. The visitor token is the cart/session identity — a fresh anonymous mint creates a new visitor and silently empties the cart. Persist the refresh_token and use it to renew.


API Reference

Last updated: 28 September 2026

Did this help?