# Register a client

`POST /oauth/register`

Dynamic client registration (RFC 7591). `redirect_uris` must be https or loopback (`http://localhost`, `127.0.0.1`, `[::1]`); max 10. `token_endpoint_auth_method: none` registers a public client; `client_secret_post` / `client_secret_basic` a confidential one.

## Body

| Field | Type | Description |
|---|---|---|
| `redirect_uris` (required) | array<string> | Redirect URIs. |
| `client_name` | string | Name shown on the consent screen. |
| `client_uri` | string | App website (https). |
| `token_endpoint_auth_method` | string | Client authentication. Values: `none`, `client_secret_post`, `client_secret_basic` |
| `grant_types` | array<string> | `authorization_code`, `refresh_token`. |

## Response

```json 201
{
  "client_id": "crm_sN-deD6QaASdSwwlE2np8BWe",
  "client_id_issued_at": 1790960821,
  "client_name": "Örnek Entegrasyon",
  "grant_types": [
    "authorization_code",
    "refresh_token"
  ],
  "redirect_uris": [
    "https://uygulamaniz.com/oauth/callback"
  ],
  "response_types": [
    "code"
  ],
  "token_endpoint_auth_method": "none"
}
```
