---
category: [Administration & Integrations, Platform and Product Extensions, Platform and Product Extensions/Integration, Administration & Integrations/Custom Integrations & Apps, Platform and Product Extensions/Workday Extend]
keyword: [Extend, OAuth]
nav: wcp_docs
parent_url: /wcp_docs/
title: Create Your API Client
layout: subsection
---

### Context

<a id="context_N10027_N1001E_N10001"></a>
The Workday REST and Graph APIs use OAuth 2.0 to authorize access to resources in your Workday tenant. To use OAuth 2.0, you must use the Console to create your API client in your tenant. From the <b>Console</b> section of the Developer Site menu, select <b>API Clients</b> to create and manage API clients.

After you create your client, Workday Extend generates your client ID and secret for accessing the Workday Extend REST APIs.

<b>Note:</b> If you have a trusted client and the client secret is exposed to others, generate a new client secret. From the related actions menu of your client, click <b>Manage Client Secret</b>, and then click <b>Generate New Client Secret</b>.

### Steps

1.  <a id="step_N10031_N1002E_N1001E_N10001"></a>From the <b>Console</b> section of the Developer Site menu, select <b>API Clients</b>.
2.  Click the <b>Create API Client</b> button.
3.  <a id="step_N1003A_N1002E_N1001E_N10001"></a>As you create a new API client, consider:

<table><thead><tr><th>    Option</th><th>    Description</th></tr></thead><tbody><tr><td><b>Client Name</b></td><td>Enter a unique name.</td></tr><tr><td><b>Redirect URI</b></td><td>Enter a secure URL for OAuth to redirect your app users during authentication.</td></tr><tr><td><b>Authorized CORS Domains</b></td><td>Enter 1 or more authorized domain names using the format <code>protocol://domain:port</code>. <p>Example: <code>https://www.workday.com:1234</code></p> This enables secure access to selected resources from a server on a different domain than the current site.</td></tr><tr><td><b>Scopes</b></td><td>Select 1 or more scopes that apply to the functionality of your client. Selecting a scope enables your client to access resources from the REST APIs that are within that functional area of Workday. <p>To determine the scopes you need to select:</p><ul><li>    In the REST API Explorer, view the REST API resources you want your API client to use. You'll find the appropriate scopes in the endpoint descriptions.
</li><li>    In the Graph API Explorer, the schema documentation lists the scopes in:

<ul><li>    Query field and data source descriptions.
</li><li>    Mutation operation descriptions.
</li></ul></li></ul></td></tr></tbody></table><br/>



### Next Steps

<a id="postreq_N10057_N1001E_N10001"></a>
Consider the authorization flow you want to use for your API client.

When you migrate your client to a nondevelopment tenant such as an implementation or production tenant, you must allow the client ID on the target tenant. Only a Company Administrator can add or remove tenants from an API client's allowlist. When viewing an API client owned by your account, click <b>Modify Authorized Tenants</b>, and then add or remove tenants from the API client's allowlist.

