---
search:
  tags:
    - OAuth
    - POST
seo:
  description: >-
    Public clients only: token_endpoint_auth_method must be none (if present),…
    Reference for the POST /oauth/register endpoint in the agentsub Gateway API.
sidebar:
  label: Dynamic client registration (RFC 7591)
  badge: POST
title: Dynamic client registration (RFC 7591)
type: openapi-operation
---
Public clients only: `token_endpoint_auth_method` must be `none` (if present), grants only `authorization_code`. 1–10 HTTPS (or loopback http) redirect URIs without fragments/credentials. Registration is capped (429 at 1000 clients).

`POST /oauth/register`

**Request body** (`application/json`, required)

- `redirect_uris` (string<uri>[], required)
- `client_name` (string)
- `token_endpoint_auth_method` (string)
- `grant_types` (string[])

Request body example:

```json
{
  "redirect_uris": [
    "http://example.com"
  ],
  "client_name": "string",
  "token_endpoint_auth_method": "none",
  "grant_types": [
    "authorization_code"
  ]
}
```

**Responses**

- `201` — Client registered
- `400` — OAuth error JSON (\`invalid\_request\`, \`invalid\_client\`, \`invalid\_grant\`, \`invalid\_scope\`, \`invalid\_target\`, \`invalid\_redirect\_uri\`, \`invalid\_client\_metadata\`, \`unsupported\_grant\_type\`)
- `429` — OAuth error JSON (\`temporarily\_unavailable\` — registration/authorization caps reached)
- `503` — OAuth error JSON (\`temporarily\_unavailable\` — credentials or storage not configured)

Response example, 201:

```json
{
  "client_id": "string",
  "client_id_issued_at": 0,
  "client_name": "string",
  "redirect_uris": [
    "string"
  ],
  "token_endpoint_auth_method": "none",
  "grant_types": [
    "authorization_code"
  ],
  "response_types": [
    "code"
  ]
}
```
