---
title: Organization application templates
description: Create and publish organization templates for controlled OIDC registration.
editUrl: true
head: []
template: doc
sidebar:
  order: 4
  hidden: false
  attrs: {}
pagefind: true
draft: false
---

An organization application template defines the browser authentication and identity admission rules for new dynamically registered clients. It belongs to the organization. It has no client ID, private key, or client secret.

The [rule recipes](/en-us/application-rules/templates/) are configuration examples. An organization application template is a resource that you create and publish in With.

## Create and publish

1. Sign in to [With](https://with.sudomimus.com) as an organization OWNER. Open the organization, then **Application templates**.
2. Select **Create template** and enter a display name.
3. Configure the authentication rules and identity admission rules. Include a browser authentication method that your users can complete. Use [Layer 1](/en-us/application-rules/authentication-rules/) and [Layer 2](/en-us/application-rules/realize-rules/) to check their meaning.
4. Select **Save draft**. Review the saved rules.
5. Select **Publish**. The template becomes `ACTIVE` and has a published revision.
6. Select that revision when you [issue an IAT](/en-us/oidc/registration-access/). The IAT also restricts scopes, response types, grants, quota, expiry, and activation.

A draft cannot be used to issue an IAT. The published rules must support browser login. If publication fails, correct the reported rule error and save the draft again.

## Update a template

Edit the draft and select **Save draft**. Select **Publish new revision** when the new rules are ready for future registrations.

Each IAT keeps the published template revision selected at issuance. Later draft edits and publications do not change that IAT. They also do not update applications already created from it. To use a new revision, issue a new IAT. Edit an existing application's rules on its application page.

If another OWNER changed the template while you were editing, reload it and review the current draft before saving again.

## Retire a template

Select **Retire** to prevent new IATs from using the template. Retirement does not revoke previously issued IATs or disable existing clients.

To stop unused registration authority, revoke the relevant IATs separately. To stop a registered client, disable that application or remove its OIDC registration. See [registration access management](/en-us/oidc/registration-access/).

## Related

- [Dynamic registration API](/en-us/oidc/dynamic-registration/)
- [Organizations and applications](/en-us/with-portal/organizations-and-applications/)
- [Application lifecycle](/en-us/with-portal/application-lifecycle/)