Declaratively Provision Kanidm Clients

I have a NixOS server running Kanidm and I want to connect some ODIC clients (i.e. with client id and secret) to it. e.g. Example Configurations - Kanidm Administration

Is there a way to do this statically so I can share the secret between the client and Kanidm?

See options available under the services.kanidm.provision namespace after setting services.kanidm.package to one of the following: NixOS Search

There are already a few preexisting discussions on secret management