Dynamically register an OAuth client

RFC 7591 dynamic client registration. Without an Authorization bearer the registration is anonymous and creates a public client (token_endpoint_auth_method must be none), which is how MCP clients such as Claude Code register themselves. With an initial access token as the bearer the client is Person-owned, may be confidential (client_secret_basic), and is limited to the token's scope ceiling. Either way the response carries a registration access token for RFC 7592 management.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params

RFC 7591 dynamic client registration request. Wingspan extensions are prefixed with wingspan_.

string
required
redirect_uris
array of uris, unique
required
length ≥ 1
redirect_uris*
grant_types
array of strings, unique
length ≥ 1
response_types
array of strings, unique
length ≥ 1
string

Space-delimited OAuth Role and OIDC scopes. Defaults to the IAT scope ceiling when omitted.

string
enum

Defaults to none when omitted.

Allowed:
string
enum
Allowed:
contacts
array of strings, unique
contacts
uri
uri
uri
uri
jwks
object
string
string
wingspan_protected_resources
array of uris, unique
length between 1 and 1

Optional Wingspan extension; defaults to the server's advertised protected resource.

wingspan_protected_resources
Responses

Language
Credentials
Bearer
OAuth-IAT
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json