Skip to navigation

OAuth · Register client (RFC 7591)

View as MarkdownOpen in Claude

RFC 7591 dynamic client registration. Answers 201 with the client document.

Unauthenticated and throttled to 10 requests/min per IP.

Redirect URIs (redirect_uris, required, 1 to 5 entries). Each one is parsed and compared whole:

  • https (or http) whose scheme, host and port equal an allowed domain exactly - a subdomain, another port or a longer host is not the same domain.
  • http on a loopback host (127.0.0.1, [::1], localhost) on any port, for native and desktop clients (RFC 8252).
  • An allowed private-use scheme with a host, such as cursor://anysphere.cursor-retrieval/oauth/callback.
  • Never a comma, @, backslash, whitespace, user, password or fragment.

Anything else answers 400 invalid_redirect_uri.

Client name (client_name, optional): at most 100 characters, no control characters; otherwise 400 invalid_client_metadata. The approval screen shows it next to the address the authorization will be sent to.

Registered clients are public (PKCE S256, no secret) and own no user. Registrations that never obtained a token are removed after 30 days.

Host root, no /api prefix.

Request

This endpoint expects an object.
client_namestringOptional
redirect_urislist of stringsOptional

Response

201 Created
client_idstringOptional
grant_typeslist of stringsOptional
redirect_urislist of stringsOptional
response_typeslist of stringsOptional
scopestringOptional
token_endpoint_auth_methodstringOptional

Errors

400
Bad Request Error