OAuth · Register client (RFC 7591)
RFC 7591 dynamic client registration. Answers 201 with the client document.
Unauthenticated and throttled to 10 requests/min per IP.
Redirect URIs (redirect_uris, required, 1 to 5 entries). Each one is parsed and compared whole:
https(orhttp) whose scheme, host and port equal an allowed domain exactly - a subdomain, another port or a longer host is not the same domain.httpon a loopback host (127.0.0.1,[::1],localhost) on any port, for native and desktop clients (RFC 8252).- An allowed private-use scheme with a host, such as
cursor://anysphere.cursor-retrieval/oauth/callback. - Never a comma,
@, backslash, whitespace, user, password or fragment.
Anything else answers 400 invalid_redirect_uri.
Client name (client_name, optional): at most 100 characters, no control characters; otherwise 400 invalid_client_metadata. The approval screen shows it next to the address the authorization will be sent to.
Registered clients are public (PKCE S256, no secret) and own no user. Registrations that never obtained a token are removed after 30 days.
Host root, no /api prefix.
Request
This endpoint expects an object.
client_name
redirect_uris
Response
201 Created
client_id
grant_types
redirect_uris
response_types
scope
token_endpoint_auth_method
Errors
400
Bad Request Error
