# rpk ai oauth-client dcr update

> For the complete documentation index, see [llms.txt](https://docs.redpanda.com/llms.txt). Component-specific: [agentic-data-plane-full.txt](https://docs.redpanda.com/agentic-data-plane-full.txt)

---
title: rpk ai oauth-client dcr update
latest-operator-version: v26.2.1
latest-console-tag: v3.10.0
latest-connect-version: 4.105.0
latest-redpanda-tag: v26.2.1
docname: rpk/rpk-ai/rpk-ai-oauth-client-dcr-update
page-component-name: agentic-data-plane
page-version: master
page-component-version: master
page-component-title: Agentic Data Plane
page-relative-src-path: rpk/rpk-ai/rpk-ai-oauth-client-dcr-update.adoc
page-edit-url: https://github.com/redpanda-data/adp-docs/edit/main/modules/reference/pages/rpk/rpk-ai/rpk-ai-oauth-client-dcr-update.adoc
description: Update the tenant's DCR settings. Only the flags you pass change; everything else keeps its current value (the CLI reads the current settings and writes back the merged result).
page-git-created-date: "2026-06-25"
page-git-modified-date: "2026-08-06"
---

<!-- Source: https://docs.redpanda.com/agentic-data-plane/reference/rpk/rpk-ai/rpk-ai-oauth-client-dcr-update.md -->

Update the tenant’s DCR settings. Only the flags you pass change; everything else keeps its current value (the CLI reads the current settings and writes back the merged result).

Enable open self-registration:

```text
rpk ai oauth-client dcr update --enabled --admission-mode open
```

Require admin-minted Initial Access Tokens instead:

```text
rpk ai oauth-client dcr update --admission-mode initial-access-token
```

Turn the endpoint off again:

```text
rpk ai oauth-client dcr update --enabled=false
```

## [](#usage)Usage

```bash
rpk ai oauth-client dcr update [flags]
```

## [](#flags)Flags

| Value | Type | Description |
| --- | --- | --- |
| --admission-mode | string | how callers are admitted: open, initial-access-token. |
| --allowed-resource | strings | MCP URL every DCR-issued client may request tokens for; "*" = any. repeatable. |
| --client-cap | int32 | max concurrent DCR-issued clients (0 = runtime default). |
| --enabled | bool | whether the public registration endpoint accepts requests. |
| --inactive-ttl-days | int32 | days of inactivity before a DCR client is removed (0 = never). |
| --rate-per-hour | int32 | max registrations per hour (0 = runtime default). |

## [](#global-flags)Global flags

| Value | Type | Description |
| --- | --- | --- |
| --config | string | Redpanda or rpk config file; default search paths are ~/.config/rpk/rpk.yaml, $PWD/redpanda.yaml, and /etc/redpanda/redpanda.yaml. |
| -X, --config-opt | stringArray | Override rpk configuration settings; -X help for detail or -X list for terser detail. |
| --ignore-profile | bool | Ignore rpk.yaml and redpanda.yaml; use default settings. |
| --profile | string | rpk profile to use. |
| -v, --verbose | bool | Enable verbose logging. |