Skip to navigation

Register an MCP client

View as MarkdownOpen in Claude

Registers a public OAuth client (RFC 7591) so an MCP client can start the authorization flow. Use it once per client installation, then keep the returned client_id.

The client is public: it uses the authorization code flow with PKCE (S256) and no client secret. Any other RFC 7591 metadata you send is ignored. Registrations that never obtain a token are removed after 30 days.

Public and throttled to 10 requests per minute per IP address; the eleventh answers 429. Served at the root of the MCP host, without the /api prefix.

Body

  • redirect_uris (array of strings, required): 1 to 5 addresses the authorization code may be sent to. Each one must be one of these:

    • An https address on any host. The approval screen shows the user the origin the code will be sent to.
    • An http address on a loopback host (127.0.0.1, [::1] or localhost), on any port, for native and desktop clients (RFC 8252). http on any other host is refused.
    • A private-use scheme with a host, which native clients use for their callback (RFC 8252), such as cursor://anysphere.cursor-retrieval/oauth/callback. Any scheme is accepted except those a browser runs, reads from disk or keeps for itself (for example javascript, data, file, ftp, ws, chrome-extension).

    Whatever the origin or scheme, an address with a comma, @, backslash, whitespace, control character, user name, password or fragment is refused, and so is a host that Modular DS has blocked (with its subdomains). A refused address answers 400 with invalid_redirect_uri.

  • client_name (string, optional): the name the approval screen shows to the user, at most 100 characters and no control characters. It is shown next to the address the authorization will be sent to.

Errors

  • 400: a redirect URI is missing, more than five are sent or one is not accepted (invalid_redirect_uri).
  • 400: client_name is too long or contains control characters (invalid_client_metadata).

Request

This endpoint expects an object.
client_namestringOptional
redirect_urislist of stringsOptional

Response

201 Created
client_idstringOptional

Identifier of the new client; keep it to start the authorization flow.

grant_typeslist of enumsOptional

Grant types the client may use: authorization_code and refresh_token.

Allowed values:
redirect_urislist of stringsOptional
The redirect addresses that were registered.
response_typeslist of enumsOptional

Response types the client may use; always code.

Allowed values:
scopestringOptional

Scope granted to the client: mcp:use.

token_endpoint_auth_methodenumOptional

How the client authenticates at the token endpoint; always none, because the client is public.

Allowed values:

Errors

400
Bad Request Error