> ## Documentation Index
> Fetch the complete documentation index at: https://docs.guild.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Register an OAuth client

> Dynamic client registration ([RFC 7591](https://www.rfc-editor.org/rfc/rfc7591)). An MCP client registers itself before its first authorization request, so nobody has to add it by hand. This endpoint requires no authentication. Every client registered here is public: it holds no secret and proves itself on each authorization with PKCE, so registering grants nothing on its own -- the user's consent is still required. Each `redirect_uri` must use `https`, or `http` on a loopback address, and must not contain a fragment. Registration is rate-limited to 10 requests per hour per IP address. Fields a client sends that are not listed here are ignored.



## OpenAPI

````yaml /api-reference/openapi.yaml post /oauth/register
openapi: 3.0.3
info:
  title: Guild Public API
  version: 1.0.0
  description: >-
    The Guild public API, served at https://api.guild.ai/v1 and authenticated
    with account API keys (HTTP Basic, key id as the username and the secret as
    the password). See https://docs.guild.ai/api-reference/introduction for
    scopes and behavior. A session-events websocket also exists at
    wss://api.guild.ai/v1/sessions/{session_id}/events/ws with the same Basic
    auth on the handshake; OpenAPI cannot describe websockets, so it is not
    listed in paths.
servers:
  - url: https://api.guild.ai/v1
    description: Production
security: []
tags:
  - name: accounts
  - name: agents
  - name: oauth
  - name: sessions
  - name: skills
  - name: workspaces
paths:
  /oauth/register:
    post:
      tags:
        - oauth
      summary: Register an OAuth client
      description: >-
        Dynamic client registration ([RFC
        7591](https://www.rfc-editor.org/rfc/rfc7591)). An MCP client registers
        itself before its first authorization request, so nobody has to add it
        by hand. This endpoint requires no authentication. Every client
        registered here is public: it holds no secret and proves itself on each
        authorization with PKCE, so registering grants nothing on its own -- the
        user's consent is still required. Each `redirect_uri` must use `https`,
        or `http` on a loopback address, and must not contain a fragment.
        Registration is rate-limited to 10 requests per hour per IP address.
        Fields a client sends that are not listed here are ignored.
      operationId: register_oauth_client
      requestBody:
        required: true
        content:
          application/json:
            schema:
              title: RegisterOAuthClientInput
              type: object
              required:
                - client_name
                - redirect_uris
              properties:
                client_name:
                  type: string
                  minLength: 1
                  maxLength: 128
                  description: A display name for the client.
                redirect_uris:
                  type: array
                  minItems: 1
                  maxItems: 5
                  items:
                    type: string
                    maxLength: 1024
                  description: >-
                    Where to send the user back after authorization. An `http`
                    loopback redirect URI matches a registered redirect URI on
                    any port, per [RFC 8252 section
                    7.3](https://www.rfc-editor.org/rfc/rfc8252#section-7.3).
                token_endpoint_auth_method:
                  type: string
                  enum:
                    - none
                  default: none
                grant_types:
                  type: array
                  items:
                    type: string
                    enum:
                      - authorization_code
                      - refresh_token
                  default:
                    - authorization_code
                    - refresh_token
                response_types:
                  type: array
                  items:
                    type: string
                    enum:
                      - code
                  default:
                    - code
      responses:
        '201':
          description: The registered client
          content:
            application/json:
              schema:
                type: object
                properties:
                  client_id:
                    type: string
                  client_id_issued_at:
                    type: integer
                    description: >-
                      When the client was registered, in seconds since the Unix
                      epoch.
                  client_name:
                    type: string
                  redirect_uris:
                    type: array
                    items:
                      type: string
                  token_endpoint_auth_method:
                    type: string
                  grant_types:
                    type: array
                    items:
                      type: string
                  response_types:
                    type: array
                    items:
                      type: string
        '400':
          description: Bad Request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '429':
          description: Too Many Requests
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security: []
components:
  schemas:
    ErrorResponse:
      type: object
      properties:
        error:
          type: string
        message:
          type: string

````