> ## Documentation Index
> Fetch the complete documentation index at: https://www.vitalog.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# OAuth register client

> RFC 7591 dynamic registration for clients without a metadata document or configured client ID. Accepts HTTPS, literal loopback HTTP and reverse-domain native callbacks. Public clients explicitly use token_endpoint_auth_method=none. The default is client_secret_basic; client_secret_post and private_key_jwt are also supported. JWT clients supply exactly one public jwks or HTTPS jwks_uri and receive no symmetric secret. Only authorization_code/code and health:read/health:write scopes are issued. Requests listing authorization_code plus refresh_token are accepted with an authorization_code-only response. Declared web clients require non-loopback HTTPS callbacks; native clients can use loopback or native schemes. Unapproved registrations expire after one hour and are reclaimed before admitting new clients; successful root consent retains the client. Unknown metadata fields are ignored and external logos or client URIs are never fetched. Registration grants no ledger access. Limited to ten registrations per source address per minute and 1,000 persisted clients. Store any returned client secret privately; only its SHA-256 digest is retained.



## OpenAPI

````yaml /openapi.json post /oauth/register
openapi: 3.1.1
info:
  title: Vitalog
  version: 1.0.1
  description: >-
    Single-user structured observations with equivalent REST and MCP domain
    services. Environment AUTH_KEY or revocable personal Bearer keys with
    required name, permissions and explicit expiry (including Never); Primary
    key management requires AUTH_KEY; the UI uses separate, root-verified
    30-minute management sessions. MCP clients use OAuth authorization code with
    S256 PKCE, issued after root sign-in. Clients are resolved through HTTPS
    metadata, pre-registration or dynamic registration. OAuth tokens grant MCP
    access only.
servers:
  - url: https://vitalog-api.example.com
    description: Production REST and MCP API
  - url: http://localhost:3000
    description: Loopback development; production requires TLS ingress
security: []
paths:
  /oauth/register:
    post:
      tags:
        - OAuth
      summary: OAuth register client
      description: >-
        RFC 7591 dynamic registration for clients without a metadata document or
        configured client ID. Accepts HTTPS, literal loopback HTTP and
        reverse-domain native callbacks. Public clients explicitly use
        token_endpoint_auth_method=none. The default is client_secret_basic;
        client_secret_post and private_key_jwt are also supported. JWT clients
        supply exactly one public jwks or HTTPS jwks_uri and receive no
        symmetric secret. Only authorization_code/code and
        health:read/health:write scopes are issued. Requests listing
        authorization_code plus refresh_token are accepted with an
        authorization_code-only response. Declared web clients require
        non-loopback HTTPS callbacks; native clients can use loopback or native
        schemes. Unapproved registrations expire after one hour and are
        reclaimed before admitting new clients; successful root consent retains
        the client. Unknown metadata fields are ignored and external logos or
        client URIs are never fetched. Registration grants no ledger access.
        Limited to ten registrations per source address per minute and 1,000
        persisted clients. Store any returned client secret privately; only its
        SHA-256 digest is retained.
      operationId: oauth_register_client
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $schema: https://json-schema.org/draft/2020-12/schema
              type: object
              properties:
                client_name:
                  $ref: '#/components/schemas/Schema_992221d3595b___schema0'
                application_type:
                  $ref: '#/components/schemas/Schema_992221d3595b___schema1'
                redirect_uris:
                  $ref: '#/components/schemas/Schema_992221d3595b___schema2'
                token_endpoint_auth_method:
                  $ref: '#/components/schemas/Schema_992221d3595b___schema5'
                grant_types:
                  $ref: '#/components/schemas/Schema_992221d3595b___schema6'
                response_types:
                  $ref: '#/components/schemas/Schema_992221d3595b___schema8'
                scope:
                  $ref: '#/components/schemas/Schema_992221d3595b___schema10'
                jwks_uri:
                  $ref: '#/components/schemas/Schema_992221d3595b___schema11'
                jwks:
                  $ref: '#/components/schemas/Schema_992221d3595b___schema12'
                token_endpoint_auth_signing_alg:
                  $ref: '#/components/schemas/Schema_992221d3595b___schema15'
              required:
                - redirect_uris
              additionalProperties: true
      responses:
        '201':
          description: >-
            Persisted client registration; optional client secret is returned
            once
          content:
            application/json:
              schema:
                $schema: https://json-schema.org/draft/2020-12/schema
                type: object
                properties:
                  client_name:
                    $ref: '#/components/schemas/Schema_e45cd92df024___schema0'
                  application_type:
                    $ref: '#/components/schemas/Schema_e45cd92df024___schema1'
                  redirect_uris:
                    $ref: '#/components/schemas/Schema_e45cd92df024___schema2'
                  token_endpoint_auth_method:
                    $ref: '#/components/schemas/Schema_e45cd92df024___schema5'
                  grant_types:
                    type: array
                    items:
                      const: authorization_code
                    minItems: 1
                    maxItems: 1
                  response_types:
                    $ref: '#/components/schemas/Schema_e45cd92df024___schema8'
                  scope:
                    $ref: '#/components/schemas/Schema_e45cd92df024___schema10'
                  jwks_uri:
                    $ref: '#/components/schemas/Schema_e45cd92df024___schema11'
                  jwks:
                    $ref: '#/components/schemas/Schema_e45cd92df024___schema12'
                  token_endpoint_auth_signing_alg:
                    $ref: '#/components/schemas/Schema_e45cd92df024___schema15'
                  client_id:
                    type: string
                    pattern: ^vcl_[A-Za-z0-9_-]{43}$
                  client_id_issued_at:
                    type: integer
                  client_secret:
                    type: string
                    pattern: ^vcs_[A-Za-z0-9_-]{43}$
                    writeOnly: true
                  client_secret_expires_at:
                    const: 0
                required:
                  - client_id
                  - client_id_issued_at
                  - client_name
                  - redirect_uris
                  - token_endpoint_auth_method
                  - grant_types
                  - response_types
                  - scope
        '400':
          description: OAuth protocol error
          content:
            application/json:
              schema:
                type: object
                additionalProperties: false
                required:
                  - error
                  - error_description
                properties:
                  error:
                    type: string
                  error_description:
                    type: string
        '413':
          description: Request exceeds 4 KiB
        '429':
          description: 'Registration rate exceeded; Retry-After: 60'
        '503':
          description: OAuth protocol error
          content:
            application/json:
              schema:
                type: object
                additionalProperties: false
                required:
                  - error
                  - error_description
                properties:
                  error:
                    type: string
                  error_description:
                    type: string
      security: []
components:
  schemas:
    Schema_992221d3595b___schema0:
      default: MCP client
      type: string
      minLength: 1
      maxLength: 100
      pattern: ^[^\u0000-\u001f\u007f\u202a-\u202e\u2066-\u2069]+$
    Schema_992221d3595b___schema1:
      type: string
      enum:
        - native
        - web
    Schema_992221d3595b___schema2:
      minItems: 1
      maxItems: 10
      type: array
      items:
        $ref: '#/components/schemas/Schema_992221d3595b___schema3'
    Schema_992221d3595b___schema5:
      default: client_secret_basic
      type: string
      enum:
        - none
        - client_secret_basic
        - client_secret_post
        - private_key_jwt
    Schema_992221d3595b___schema6:
      default:
        - authorization_code
      minItems: 1
      maxItems: 2
      type: array
      items:
        $ref: '#/components/schemas/Schema_992221d3595b___schema7'
    Schema_992221d3595b___schema8:
      default:
        - code
      minItems: 1
      maxItems: 1
      type: array
      items:
        $ref: '#/components/schemas/Schema_992221d3595b___schema9'
    Schema_992221d3595b___schema10:
      default: health:read health:write
      type: string
      maxLength: 128
    Schema_992221d3595b___schema11:
      $ref: '#/components/schemas/Schema_992221d3595b___schema4'
    Schema_992221d3595b___schema12:
      type: object
      properties:
        keys:
          $ref: '#/components/schemas/Schema_992221d3595b___schema13'
      required:
        - keys
    Schema_992221d3595b___schema15:
      type: string
      enum:
        - RS256
        - PS256
        - ES256
    Schema_e45cd92df024___schema0:
      default: MCP client
      type: string
      minLength: 1
      maxLength: 100
      pattern: ^[^\u0000-\u001f\u007f\u202a-\u202e\u2066-\u2069]+$
    Schema_e45cd92df024___schema1:
      type: string
      enum:
        - native
        - web
    Schema_e45cd92df024___schema2:
      minItems: 1
      maxItems: 10
      type: array
      items:
        $ref: '#/components/schemas/Schema_e45cd92df024___schema3'
    Schema_e45cd92df024___schema5:
      default: client_secret_basic
      type: string
      enum:
        - none
        - client_secret_basic
        - client_secret_post
        - private_key_jwt
    Schema_e45cd92df024___schema8:
      default:
        - code
      minItems: 1
      maxItems: 1
      type: array
      items:
        $ref: '#/components/schemas/Schema_e45cd92df024___schema9'
    Schema_e45cd92df024___schema10:
      default: health:read health:write
      type: string
      maxLength: 128
    Schema_e45cd92df024___schema11:
      $ref: '#/components/schemas/Schema_e45cd92df024___schema4'
    Schema_e45cd92df024___schema12:
      type: object
      properties:
        keys:
          $ref: '#/components/schemas/Schema_e45cd92df024___schema13'
      required:
        - keys
    Schema_e45cd92df024___schema15:
      type: string
      enum:
        - RS256
        - PS256
        - ES256
    Schema_992221d3595b___schema3:
      $ref: '#/components/schemas/Schema_992221d3595b___schema4'
    Schema_992221d3595b___schema7:
      type: string
      enum:
        - authorization_code
        - refresh_token
    Schema_992221d3595b___schema9:
      type: string
      const: code
    Schema_992221d3595b___schema4:
      type: string
      minLength: 1
      maxLength: 512
      pattern: ^[^\s\u0000-\u001f\u007f]+$
    Schema_992221d3595b___schema13:
      minItems: 1
      maxItems: 10
      type: array
      items:
        $ref: '#/components/schemas/Schema_992221d3595b___schema14'
    Schema_e45cd92df024___schema3:
      $ref: '#/components/schemas/Schema_e45cd92df024___schema4'
    Schema_e45cd92df024___schema9:
      type: string
      const: code
    Schema_e45cd92df024___schema4:
      type: string
      minLength: 1
      maxLength: 512
      pattern: ^[^\s\u0000-\u001f\u007f]+$
    Schema_e45cd92df024___schema13:
      minItems: 1
      maxItems: 10
      type: array
      items:
        $ref: '#/components/schemas/Schema_e45cd92df024___schema14'
    Schema_992221d3595b___schema14:
      type: object
      properties:
        kty:
          type: string
          enum:
            - RSA
            - EC
      required:
        - kty
      additionalProperties: {}
    Schema_e45cd92df024___schema14:
      type: object
      properties:
        kty:
          type: string
          enum:
            - RSA
            - EC
      required:
        - kty
      additionalProperties: {}

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.