Skip to main content

ClientRegistrationRequest

Dynamic client registration request (RFC 7591). Only the fields that affect the flow are read; anything else the standard defines (contacts, policy_uri, tos_uri, jwks, …) is accepted and ignored.

client_namestring

Display name of the client, shown to the employee on the consent page. Also the idempotency key: registering again under the same name returns the existing client_id. Defaults to MCP client when omitted.

Possible values: <= 255 characters

Example: Claude
redirect_urisstring[]required

Where authorization codes may be delivered. At least one entry is required, each must be HTTPS, carry no fragment, and belong to an allow-listed host.

Example: ["https://claude.ai/api/mcp/auth_callback"]
grant_typesstring[]

Optional. When present, may only contain authorization_code and refresh_token — anything else is rejected. The response always states the server's own list.

Example: ["authorization_code","refresh_token"]
response_typesstring[]

Optional. When present, may only contain code.

Example: ["code"]
token_endpoint_auth_methodstring

Accepted but not honoured — a dynamically registered client is always public, so the response says none whatever was asked for.

Example: none
scopestring

Accepted but not honoured — the client always receives exactly PERMISSION_OPEN_API_MCP:READ.

Example: PERMISSION_OPEN_API_MCP:READ
client_uristring

Homepage of the client. Stored as the application's description (first 1024 characters).

Example: https://claude.ai
logo_uristring

Accepted for RFC compatibility; not used when rendering the consent page.

Example: https://claude.ai/logo.png
ClientRegistrationRequest
{
"client_name": "Claude",
"redirect_uris": [
"https://claude.ai/api/mcp/auth_callback"
],
"grant_types": [
"authorization_code",
"refresh_token"
],
"response_types": [
"code"
],
"token_endpoint_auth_method": "none",
"scope": "PERMISSION_OPEN_API_MCP:READ",
"client_uri": "https://claude.ai",
"logo_uri": "https://claude.ai/logo.png"
}