Register a client
POST /oauth/register
Dynamic client registration (RFC 7591). Unauthenticated; do it once per app.
Body
redirect_urisstring[]RequiredAt most 10.
httpsURLs, or loopback-address URLs for a native app (RFC 8252 §7.3). Matched exactly at authorize time.client_namestringRequiredShown to the person on the consent page.
scopestringSpace-separated scopes the client may ask for, from the catalogue on the OAuth guide. An authorize request that names none asks for these.
client_uristringAn
httpslink to the app, shown on the consent page.logo_uristringAn
httpsimage, shown on the consent page.
5 more fields (grant_types, response_types, token_endpoint_auth_method, software_id, software_version)
grant_typesstring[]authorization_codeandrefresh_token, which is also the default.response_typesstring[]Only
["code"].token_endpoint_auth_methodstringOnly
none: every client is a public client.software_idstringYour own identifier for the app, stored and returned.
software_versionstringYour own version string, stored and returned.
Request
curl -X POST "https://api.rasket.com/oauth/register" \
-H "User-Agent: acme-billing/1.0" \
-H "Content-Type: application/json" \
-d '{
"client_name": "Acme Invoices",
"redirect_uris": ["https://invoices.acme.example/rasket/callback"],
"scope": "emails:send emails:read"
}'const response = await fetch("https://api.rasket.com/oauth/register", {
method: "POST",
headers: {
"User-Agent": "acme-billing/1.0",
"Content-Type": "application/json",
},
body: JSON.stringify({
client_name: "Acme Invoices",
redirect_uris: ["https://invoices.acme.example/rasket/callback"],
scope: "emails:send emails:read"
}),
});
const data = await response.json();import os
import requests
response = requests.post(
"https://api.rasket.com/oauth/register",
headers={
"User-Agent": "acme-billing/1.0",
},
json={
"client_name": "Acme Invoices",
"redirect_uris": ["https://invoices.acme.example/rasket/callback"],
"scope": "emails:send emails:read"
},
)
print(response.json())Response 201
{
"client_id": "rkoc_7Fq2Lm9pXw3Kd8Vn1Zt5Rb4C",
"client_id_issued_at": 1789205400,
"registration_client_uri": "/oauth/register/rkoc_7Fq2Lm9pXw3Kd8Vn1Zt5Rb4C",
"client_name": "Acme Invoices",
"redirect_uris": ["https://invoices.acme.example/rasket/callback"],
"grant_types": ["authorization_code", "refresh_token"],
"response_types": ["code"],
"token_endpoint_auth_method": "none",
"scope": "emails:send emails:read",
"registration_access_token": "rkor_…"
}registration_access_tokenis shown exactly once. Store it: it is the only credential for reading, replacing or deleting this client.- Public clients only. A
token_endpoint_auth_methodother thannone, orresponse_typesother thancode, is400 invalid_client_metadata; a redirect URI that is nothttpsor loopback is400 invalid_redirect_uri. - At most 10 registrations per IP address per hour and 1,000 a day across the platform; past either,
429. - Errors from this route are RFC 7591's
{ error, error_description }, not the Rasket error body.