---
title: IAT and RAT management
description: Issue, replace, and revoke OIDC registration credentials in With.
editUrl: true
head: []
template: doc
sidebar:
  order: 3
  hidden: false
  attrs: {}
pagefind: true
draft: false
---

Dynamic registration uses two different Bearer credentials. Neither is a user access token.

| Credential | Holder can do | Does not permit |
|---|---|---|
| Initial Access Token (IAT) | Create clients within the selected template, approved host, expiry, finite quota, scopes, and flows. | Read another client's secret or sign in as a user. |
| Registration Access Token (RAT) | Read its client's current metadata and shared secret, and delete its OIDC registration. | Edit metadata, create another client, or create user sessions. |

Store both credentials on the backend. Do not put them in browser storage, URLs, logs, or support messages.

## Request host approval

1. Sign in to [With](https://with.sudomimus.com) as an organization OWNER.
2. Open the organization's Sector, then **OIDC**.
3. Request approval for the RP host that will receive authorization callbacks.
4. Wait for Sudomimus staff to approve the request. A pending or rejected request does not grant registration authority.

For multiple redirect hosts, prepare the `sector_identifier_uri` document described in the [registration API](/en-us/oidc/dynamic-registration/). Its host must have the approved Sector placement.

## Issue an IAT

On the same Sector OIDC page:

1. Select an `ACTIVE`, browser-ready [application template](/en-us/with-portal/application-templates/). Check its published revision.
2. Select the approved host placement.
3. Set a UTC expiry, no more than 90 days from issuance, and a finite registration quota.
4. Select permitted scopes, response types, and grants. Code requires `authorization_code`; Implicit and Hybrid require `implicit`; `offline_access` requires `refresh_token`.
5. Confirm **Create active applications**. This delegates application activation to the IAT holder.
6. Select **Issue initial access token** and save the one-time plaintext result securely.

The RP then [calls `POST /register`](/en-us/oidc/dynamic-registration/). Registration requests must fit the IAT's allowance. The template revision is fixed for that IAT.

An OWNER-issued IAT requires its issuing account to remain an active OWNER. Do not give an IAT to a party that should not be able to create active applications.

If the IAT has expired, is exhausted, or no longer has enough allowance, issue a new IAT for future registrations. Choose the required quota and current template revision. Never treat an old plaintext token as proof that its authority is still valid.

## Review and revoke

Open the organization's OIDC page to review registration credentials and their authority. Review expiry, remaining quota, permitted flows, and template revision before supplying an IAT to an RP.

Revoke an IAT to stop future registrations under it. Revoke a RAT to stop registration reads and deletes under that credential. Revoke organization registration authority when all existing IATs and RATs for that organization must stop working.

For a registered client's RAT and RP keys, open its Application OIDC page and follow the link to the organization's OIDC client management page. An OWNER can replace a RAT there. Save the replacement and update the backend; the prior RAT no longer works.

## Effects on existing clients

| Action | Effect |
|---|---|
| IAT expires, is exhausted, or is revoked | Stops new registrations. Previously created clients and RATs remain valid under their own current authority. |
| Issuing OWNER loses active OWNER membership | Stops that OWNER's IATs. Does not by itself revoke existing RATs. |
| Publish or retire a template | Does not change existing IAT snapshots or existing clients. |
| Revoke or replace a RAT | Invalidates that credential. Does not itself disable user sign-in. |
| Revoke organization registration authority | Invalidates existing registration credentials. Does not itself remove registered clients. |
| Disable an organization | Invalidates its registration credentials. Re-enabling does not restore old IATs or RATs. |
| Disable a client application | Stops its use and revokes its RAT. |
| Delete OIDC registration with the RAT | Disables the application, removes the registration, and revokes the RAT. |

To stop user sign-in for a particular client, use [application lifecycle controls](/en-us/with-portal/application-lifecycle/). Revoking an unused IAT is not a client shutdown operation.

## Related

- [Dynamic registration API](/en-us/oidc/dynamic-registration/)
- [RP keys](/en-us/oidc/relying-party-keys/)
- [OIDC troubleshooting](/en-us/oidc/troubleshooting/)