create_client
Register a new OAuth client with a unique identifier and secret. Optionally set redirect URIs, allowed scopes, and login page styling to control authorization and token issuance.
Instructions
Create a new OAuth client
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| client_id | Yes | Unique client identifier | |
| description | No | Human-readable description (optional) | |
| footer_color | No | Hex color (e.g. '#ffffff') for the /authorize login card footer band (optional) | |
| header_color | No | Hex color (e.g. '#0d6efd') for the /authorize login card header band (optional) | |
| client_secret | Yes | Client secret for authentication | |
| redirect_uris | No | Registered redirect URIs; when non-empty, /authorize enforces exact matching, except a registered loopback URI (http://127.0.0.1:{port}/..., http://[::1]:{port}/...) matches any port per RFC 8252 section 7.3; reverse-domain private-use schemes like com.example.app:/cb are accepted, schemes without a period such as myapp:// are rejected per section 7.1 (optional) | |
| allowed_scopes | No | Per-client scope allow-list (#186); when non-empty, /authorize and /token reject a requested scope outside this set with invalid_scope (RFC 6749 4.1.2.1/5.2). Empty = any scope in the global oauth.scopes_supported vocabulary is allowed (optional) | |
| show_client_id | No | Show client_id on the /authorize login page (optional, default true) | |
| background_color | No | Hex color (e.g. '#1a1a2e') behind the /authorize login card (optional) | |
| show_description | No | Show description on the /authorize login page (optional, default false) | |
| additional_audiences | No | Extra audiences added to the ID Token 'aud' alongside the client_id (optional) |