Skip to main content

ClientRegistrationResponse

Dynamic client registration response (RFC 7591 §3.2.1), returned with 201. No client_secret is issued: the endpoint is unauthenticated, so there would be no way to know who received the secret. The client is public and protected by PKCE.

client_idstring

The client identifier to use for /oauth/authorize and /oauth/token.

Example: uysot_app_9f86d081884c7d659a2feaa0c55ad0159f86d081
client_id_issued_atint64

When the client was registered, epoch seconds.

Example: 1787992445
client_namestring

The stored name — the requested one, or MCP client when none was sent.

Example: Claude
redirect_urisstring[]

Every redirect URI now registered on the client. On a repeat registration this is the union of what was already stored and what the request added.

Example: ["https://claude.ai/api/mcp/auth_callback"]
grant_typesstring[]

Always authorization_code and refresh_token.

Example: ["authorization_code","refresh_token"]
response_typesstring[]

Always code.

Example: ["code"]
token_endpoint_auth_methodstring

Always none — the client is public and holds no secret.

Example: none
scopestring

Always exactly PERMISSION_OPEN_API_MCP:READ.

Example: PERMISSION_OPEN_API_MCP:READ
ClientRegistrationResponse
{
"client_id": "uysot_app_9f86d081884c7d659a2feaa0c55ad0159f86d081",
"client_id_issued_at": 1787992445,
"client_name": "Claude",
"redirect_uris": [
"https://claude.ai/api/mcp/auth_callback"
],
"grant_types": [
"authorization_code",
"refresh_token"
],
"response_types": [
"code"
],
"token_endpoint_auth_method": "none",
"scope": "PERMISSION_OPEN_API_MCP:READ"
}