curl --request POST \
--url https://vitalog-api.example.com/oauth/register \
--header 'Content-Type: application/json' \
--data '
{
"redirect_uris": [
"<string>"
],
"client_name": "MCP client",
"token_endpoint_auth_method": "client_secret_basic",
"grant_types": [
"authorization_code"
],
"response_types": [
"code"
],
"scope": "health:read health:write",
"jwks_uri": "<string>"
}
'import requests
url = "https://vitalog-api.example.com/oauth/register"
payload = {
"redirect_uris": ["<string>"],
"client_name": "MCP client",
"token_endpoint_auth_method": "client_secret_basic",
"grant_types": ["authorization_code"],
"response_types": ["code"],
"scope": "health:read health:write",
"jwks_uri": "<string>"
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
redirect_uris: ['<string>'],
client_name: 'MCP client',
token_endpoint_auth_method: 'client_secret_basic',
grant_types: ['authorization_code'],
response_types: ['code'],
scope: 'health:read health:write',
jwks_uri: '<string>'
})
};
fetch('https://vitalog-api.example.com/oauth/register', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://vitalog-api.example.com/oauth/register",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'redirect_uris' => [
'<string>'
],
'client_name' => 'MCP client',
'token_endpoint_auth_method' => 'client_secret_basic',
'grant_types' => [
'authorization_code'
],
'response_types' => [
'code'
],
'scope' => 'health:read health:write',
'jwks_uri' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://vitalog-api.example.com/oauth/register"
payload := strings.NewReader("{\n \"redirect_uris\": [\n \"<string>\"\n ],\n \"client_name\": \"MCP client\",\n \"token_endpoint_auth_method\": \"client_secret_basic\",\n \"grant_types\": [\n \"authorization_code\"\n ],\n \"response_types\": [\n \"code\"\n ],\n \"scope\": \"health:read health:write\",\n \"jwks_uri\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://vitalog-api.example.com/oauth/register")
.header("Content-Type", "application/json")
.body("{\n \"redirect_uris\": [\n \"<string>\"\n ],\n \"client_name\": \"MCP client\",\n \"token_endpoint_auth_method\": \"client_secret_basic\",\n \"grant_types\": [\n \"authorization_code\"\n ],\n \"response_types\": [\n \"code\"\n ],\n \"scope\": \"health:read health:write\",\n \"jwks_uri\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://vitalog-api.example.com/oauth/register")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"redirect_uris\": [\n \"<string>\"\n ],\n \"client_name\": \"MCP client\",\n \"token_endpoint_auth_method\": \"client_secret_basic\",\n \"grant_types\": [\n \"authorization_code\"\n ],\n \"response_types\": [\n \"code\"\n ],\n \"scope\": \"health:read health:write\",\n \"jwks_uri\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"client_name": "MCP client",
"redirect_uris": [
"<string>"
],
"token_endpoint_auth_method": "client_secret_basic",
"grant_types": [
"authorization_code"
],
"response_types": [
"code"
],
"scope": "health:read health:write",
"client_id": "<string>",
"client_id_issued_at": 123,
"application_type": "native",
"jwks_uri": "<string>",
"jwks": {
"keys": [
{
"kty": "RSA"
}
]
},
"token_endpoint_auth_signing_alg": "RS256",
"client_secret_expires_at": 0
}{
"error": "<string>",
"error_description": "<string>"
}{
"error": "<string>",
"error_description": "<string>"
}OAuth register client
RFC 7591 dynamic registration for clients without a metadata document or configured client ID. Accepts HTTPS, literal loopback HTTP and reverse-domain native callbacks. Public clients explicitly use token_endpoint_auth_method=none. The default is client_secret_basic; client_secret_post and private_key_jwt are also supported. JWT clients supply exactly one public jwks or HTTPS jwks_uri and receive no symmetric secret. Only authorization_code/code and health:read/health:write scopes are issued. Requests listing authorization_code plus refresh_token are accepted with an authorization_code-only response. Declared web clients require non-loopback HTTPS callbacks; native clients can use loopback or native schemes. Unapproved registrations expire after one hour and are reclaimed before admitting new clients; successful root consent retains the client. Unknown metadata fields are ignored and external logos or client URIs are never fetched. Registration grants no ledger access. Limited to ten registrations per source address per minute and 1,000 persisted clients. Store any returned client secret privately; only its SHA-256 digest is retained.
curl --request POST \
--url https://vitalog-api.example.com/oauth/register \
--header 'Content-Type: application/json' \
--data '
{
"redirect_uris": [
"<string>"
],
"client_name": "MCP client",
"token_endpoint_auth_method": "client_secret_basic",
"grant_types": [
"authorization_code"
],
"response_types": [
"code"
],
"scope": "health:read health:write",
"jwks_uri": "<string>"
}
'import requests
url = "https://vitalog-api.example.com/oauth/register"
payload = {
"redirect_uris": ["<string>"],
"client_name": "MCP client",
"token_endpoint_auth_method": "client_secret_basic",
"grant_types": ["authorization_code"],
"response_types": ["code"],
"scope": "health:read health:write",
"jwks_uri": "<string>"
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
redirect_uris: ['<string>'],
client_name: 'MCP client',
token_endpoint_auth_method: 'client_secret_basic',
grant_types: ['authorization_code'],
response_types: ['code'],
scope: 'health:read health:write',
jwks_uri: '<string>'
})
};
fetch('https://vitalog-api.example.com/oauth/register', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://vitalog-api.example.com/oauth/register",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'redirect_uris' => [
'<string>'
],
'client_name' => 'MCP client',
'token_endpoint_auth_method' => 'client_secret_basic',
'grant_types' => [
'authorization_code'
],
'response_types' => [
'code'
],
'scope' => 'health:read health:write',
'jwks_uri' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://vitalog-api.example.com/oauth/register"
payload := strings.NewReader("{\n \"redirect_uris\": [\n \"<string>\"\n ],\n \"client_name\": \"MCP client\",\n \"token_endpoint_auth_method\": \"client_secret_basic\",\n \"grant_types\": [\n \"authorization_code\"\n ],\n \"response_types\": [\n \"code\"\n ],\n \"scope\": \"health:read health:write\",\n \"jwks_uri\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://vitalog-api.example.com/oauth/register")
.header("Content-Type", "application/json")
.body("{\n \"redirect_uris\": [\n \"<string>\"\n ],\n \"client_name\": \"MCP client\",\n \"token_endpoint_auth_method\": \"client_secret_basic\",\n \"grant_types\": [\n \"authorization_code\"\n ],\n \"response_types\": [\n \"code\"\n ],\n \"scope\": \"health:read health:write\",\n \"jwks_uri\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://vitalog-api.example.com/oauth/register")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"redirect_uris\": [\n \"<string>\"\n ],\n \"client_name\": \"MCP client\",\n \"token_endpoint_auth_method\": \"client_secret_basic\",\n \"grant_types\": [\n \"authorization_code\"\n ],\n \"response_types\": [\n \"code\"\n ],\n \"scope\": \"health:read health:write\",\n \"jwks_uri\": \"<string>\"\n}"
response = http.request(request)
puts response.read_body{
"client_name": "MCP client",
"redirect_uris": [
"<string>"
],
"token_endpoint_auth_method": "client_secret_basic",
"grant_types": [
"authorization_code"
],
"response_types": [
"code"
],
"scope": "health:read health:write",
"client_id": "<string>",
"client_id_issued_at": 123,
"application_type": "native",
"jwks_uri": "<string>",
"jwks": {
"keys": [
{
"kty": "RSA"
}
]
},
"token_endpoint_auth_signing_alg": "RS256",
"client_secret_expires_at": 0
}{
"error": "<string>",
"error_description": "<string>"
}{
"error": "<string>",
"error_description": "<string>"
}Body
1 - 10 elements1 - 512^[^\s\u0000-\u001f\u007f]+$1 - 100^[^\u0000-\u001f\u007f\u202a-\u202e\u2066-\u2069]+$native, web none, client_secret_basic, client_secret_post, private_key_jwt 1 - 2 elementsauthorization_code, refresh_token 1 element"code"1281 - 512^[^\s\u0000-\u001f\u007f]+$Show child attributes
Show child attributes
RS256, PS256, ES256 Response
Persisted client registration; optional client secret is returned once
1 - 100^[^\u0000-\u001f\u007f\u202a-\u202e\u2066-\u2069]+$1 - 10 elements1 - 512^[^\s\u0000-\u001f\u007f]+$none, client_secret_basic, client_secret_post, private_key_jwt 1 element1 element"code"128^vcl_[A-Za-z0-9_-]{43}$native, web 1 - 512^[^\s\u0000-\u001f\u007f]+$Show child attributes
Show child attributes
RS256, PS256, ES256 Was this page helpful?
