Register an agent as an OAuth client
Dynamic Client Registration (RFC 7591). An AI assistant registers itself as a public client (PKCE, no secret) and can do nothing until a person approves a grant for it in the console. Registration is open on purpose, so it is bounded: a per-IP hourly budget on top of the global limit, and a client that nobody ever approves into a workspace is deleted after a while. Other client metadata (client_uri, logo_uri, scope, contacts, ...) is accepted and ignored. A client_name that claims a well known brand (Claude, ChatGPT, ...) is refused unless every redirect host belongs to that brand or is a loopback address. Errors use the RFC 7591 envelope.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
RFC 7591 client metadata. Anything else a client sends (client_uri, logo_uri, scope, contacts and so on) is accepted and ignored.
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/oauth/agent/register" \ -H "Content-Type: application/json" \ -d '{ "client_name": "string", "redirect_uris": [ "http://example.com" ] }'{ "client_id": "string", "client_id_issued_at": 0, "client_name": "string", "redirect_uris": [ "string" ], "token_endpoint_auth_method": "none", "grant_types": [ "authorization_code", "refresh_token" ], "response_types": [ "code" ]}{ "error": "string", "error_description": "string"}{ "code": "string", "title": "string", "details": "string"}{ "code": "string", "title": "string", "details": "string"}