---
title: "Register OAuth client (admin)"
method: POST
path: "/admin/oauth/clients"
tags: ["admin", "oauth-server"]
---

# Register OAuth client (admin)

`POST /admin/oauth/clients`

Manually register a new OAuth client (admin endpoint). Only available when OAuth server is enabled.

## Request body

- object
  - `client_name` string, required — Human-readable name of the client application
  - `client_uri` string, uri — URL of the client application's homepage
  - `logo_uri` string, uri — URL of the client application's logo
  - `redirect_uris` string[], required — Array of redirect URIs used by the client (maximum 10)
  - `client_type` 'public' | 'confidential' — Type of the client. Optional. If not provided, will be inferred from token_endpoint_auth_method or defaults to 'confidential'. Public clients are used for applications that cannot securely store credentials (e.g., SPAs, mobile apps). Confidential clients can securely store credentials (e.g., server-side applications).
  - `token_endpoint_auth_method` 'none' | 'client_secret_basic' | 'client_secret_post' — Authentication method for the token endpoint. Optional. 'none' is for public clients, 'client_secret_basic' and 'client_secret_post' are for confidential clients. If provided, must be consistent with client_type. If not provided, will be inferred from client_type.
  - `grant_types` string[] — OAuth grant types the client will use (defaults to both if not specified)
  - `response_types` string[] — OAuth response types the client can use
  - `scope` string — Space-separated list of scope values

## Response `201`

OAuth client created

- OAuthClientSchema — Represents an OAuth 2.1 client
  - `client_id` string — Unique client identifier
  - `client_name` string — Human-readable name of the client application
  - `client_secret` string — Client secret for confidential clients (only returned on registration/regeneration)
  - `client_type` 'public' | 'confidential' — Type of the client
  - `token_endpoint_auth_method` 'none' | 'client_secret_basic' | 'client_secret_post' — Authentication method for the token endpoint
  - `registration_type` 'dynamic' | 'manual' — Registration type of the client
  - `client_uri` string, uri — URL of the client application's homepage
  - `logo_uri` string, uri — URL of the client application's logo
  - `redirect_uris` string[] — Array of redirect URIs used by the client
  - `grant_types` string[] — OAuth grant types the client is authorized to use
  - `response_types` string[] — OAuth response types the client can use
  - `scope` string — Space-separated list of scope values
  - `created_at` string, date-time
  - `updated_at` string, date-time

## Other responses

- `400` — HTTP Bad Request response. Can occur if the passed in JSON cannot be unmarshalled properly or when CAPTCHA verification was not successful. In certain cases can also occur when features are disabled on the server (e.g. sign ups). It may also mean that the operation failed due to some constraint not being met (such a user already exists for example).
- `401` — HTTP Unauthorized response.
- `403` — HTTP Forbidden response.

---

[API](https://skmtc.net/supabase/apis/supabase-auth-rest-api.md) · [All operations](https://skmtc.net/supabase/apis/supabase-auth-rest-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/supabase/supabase-auth-rest-api/versions/2664b89bee49/schema)
