---
title: "Register an OAuth client"
url: https://docs.truemarkets.co/api/auth/register-o-auth-client
description: "Dynamic client registration (RFC 7591). A remote MCP client — Claude,"
---

Docs index: https://docs.truemarkets.co/llms.txt

# Register an OAuth client

```
POST https://api.truemarkets.co/v1/auth/oauth/register
```

Dynamic client registration (RFC 7591). A remote MCP client — Claude,
Meta Muse, MCP Inspector — calls this itself before starting an
authorization flow; none of them can be handed a `client_id` out of
band.

Registration is open in mechanism and closed in reach: every
`redirect_uri` must belong to one known client vendor, and a caller
whose callback belongs to none is refused. Clients registered here are
public, use PKCE with S256, and are marked unverified on the consent
screen because their name is self-asserted.

Errors answer in the OAuth envelope (RFC 6749 5.2), not the usual one.

## Request body

`application/json`, required

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `redirect_uris` | array of string (uri) | yes | Exact callback URLs. Matched byte-for-byte at /oauth/authorize, except for loopback, where the port is ignored (RFC 8252 7.3). Must be https outside loopback, and carry no fragment or userinfo. |
| `client_name` | string | no | Self-asserted; shown on the consent screen as unverified. |
| `client_uri` | string (uri) | no |  |
| `scope` | string | no | Space-delimited. Defaults to every supported scope when omitted. |
| `grant_types` | array of string, one of `authorization_code`, `refresh_token` | no |  |
| `response_types` | array of string, one of `code` | no |  |
| `token_endpoint_auth_method` | string, one of `none` | no | Only public clients are supported. |

Example:

```json
{
  "redirect_uris": [
    "https://claude.ai/api/mcp/auth_callback"
  ],
  "client_name": "Claude",
  "client_uri": "string",
  "scope": "mcp:read mcp:trade",
  "grant_types": [
    "authorization_code"
  ],
  "response_types": [
    "code"
  ],
  "token_endpoint_auth_method": "none"
}
```

## Responses

Every error status returns the same body, described in [Errors](https://docs.truemarkets.co/developer-resources/errors.md).

### 201

Client registered

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `client_id` | string | yes |  |
| `client_id_issued_at` | integer (int64) | yes | Seconds since the epoch. |
| `redirect_uris` | array of string (uri) | yes |  |
| `client_name` | string | no |  |
| `client_uri` | string | no |  |
| `scope` | string | yes |  |
| `grant_types` | array of string | yes |  |
| `response_types` | array of string | yes |  |
| `token_endpoint_auth_method` | string | yes |  |

### 400

Invalid client metadata, or a redirect_uri belonging to no known vendor. `error` is `invalid_redirect_uri`, `invalid_client_metadata` or `invalid_scope`.

### 500

Internal server error
