> ## Documentation Index
> Fetch the complete documentation index at: https://auth0-chore-events-autoupdate.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# How to Configure Application (Client) Metadata

> Learn how to configure, update, and delete application metadata (client_metadata and clientMetadata).

Cient metadata is an optional field stored as part of the application (client) properties. It consists of customizable keys and values that you can set for each application.

You might store, for example, the URL for the application’s home page (a field that Auth0 doesn’t provide by default in the application settings).

## Where to store client secrets

Where to store the secret depends on the scope of the secret:

* Is it just one secret per application? Then `client_metadata` would be a good place.
* Is it the same secret for the whole system (i.e., for all applications or many)? Then the rule’s configuration values might be a better choice.
* Is it a different secret for each user? Then storing in the user profile's `app_metadata` might be better.

Claims in the ID token are not encrypted, so depending on the flow that you use, the user might be able to get the token and inspect the contents. Auth0 does **not** recommend storing a secret in that way.

## Configure application metadata

You can set application metadata using the Auth0 Dashboard or the <Tooltip tip="Management API: A product to allow customers to perform administrative tasks." cta="View Glossary" href="/docs/glossary?term=Management+API">Management API</Tooltip>.

<Tabs>
  <Tab title="Auth0 Dashboard">
    1. Go to [Dashboard > Applications > Applications](https://manage.auth0.com/#/applications) and select the application.

    2. On the **Settings** tab, scroll to the bottom of the page and select **Advanced Settings** to expand the section.

           <Frame>
             <img src="https://mintlify.s3.us-west-1.amazonaws.com/auth0-chore-events-autoupdate/docs/images/cdy7uua7fh8z/7GWHyQloNihda3fuYiVEWQ/b3cced7c53690e6f3cbf7b2e23ff8646/App_Metadata_-_English.png" alt="Dashboard Applications Applications Settings Tab Advanced Settings Application Metadata Tab" />
           </Frame>

    3. In the **Application Metadata** tab, you can:

       * Add metadata by entering a key and value, then selecting **+ Add**.
       * Update metadata by entering a key you want to update and a new value, then selecting **+ Add**.
       * Delete metadata by selecting the trash can icon next to the key/value pair.

    4. When you're done, select **Save Changes**.
  </Tab>

  <Tab title="Management API">
    When you create a new application with the `POST /api/v2/` applications endpoint, you can include a `clientMetadata` object to set its initial metadata.

    You can set client metadata for an existing application using the [`PATCH /api/v2/clients/{id}`](https://auth0.com/docs/api/management/v2#!/Users/patch_users_by_id) endpoint, supplying an application object with the `clientMetadata property`, which has a value that consists of an object containing the metadata you'd like to change.

    For example, if you call `PATCH /api/v2/client/myclientid123` with the following body:

    ```json theme={null}
    { "client_metadata": { "example_key": "example_value" } }
    ```

    It results in the following metadata:

    ```json Example metadata theme={null}
    {
      "name": "example_client",
      "client_metadata": {
        "example_key": "example_value"
      }
      ...
    }
    ```

    You can update existing metadata values with a similar `PATCH` call by supplying the updated value for the key. To continue the previous example, if your `PATCH` call uses the following body:

    ```json theme={null}
    { "client_metadata": { "example_key": "updated_value" } }
    ```

    It results in the following metadata:

    ```json Updated metadata theme={null}
    {
      "name": "example_client",
      "client_metadata": {
        "example_key": "updated_value"
      }
      ...
    }
    ```

    You can delete client metadata with a similar `PATCH` call by supplying `null` for the key value.
  </Tab>
</Tabs>

## View application metadata

Metadata is exposed in the `Client` object as `client_metadata`, and in Rules as `context.clientMetadata`.

You can access application metadata in [Actions](/docs/customize/actions):

```js theme={null}
exports.onExecutePostLogin = async (event, api) => {
  if (event.client.metadata.SKIP_VERIFICATION === "yes"){
    return;
  }
  // ... continue this Action
}
```

... or in [Rules](/docs/customize/rules):

```javascript theme={null}
function applicationMetadataExample (user, context, callback){
  context.clientMetadata = context.clientMetadata || {};
  if (context.clientMetadata.SKIP_VERIFICATION === "yes"){
    return callback();
  }
  // ... continue this Rule
}
```

Client metadata is also included in the responses from the Management API's `GET /api/v2/clients` and `GET /api/v2/client/{id}` endpoints.

## Limits

* The `client_metadata` field can have a maximum of 10 keys.

* `client_metadata` keys and values have a maximum length of 255 characters each.

* `client_metadata` keys and values cannot contain UTF-8 special characters.
