Skip to content
NewAgent-ready

OAuth clients can register themselves and discover the server

OAuth client credentials frameworks can now find the authorization server metadata and register a client with no human.

A client built on an OAuth client credentials framework can now set itself up without anyone's help. This is an additional way in, not a replacement: registering with one call for an API key works exactly as before, and so do the other ways in. The standard authorization server metadata document lists where to register, where to get a token, and exactly which grant and client authentication methods are supported.

Registering returns a client id and secret for a new sandbox workspace, with the same limits and the same claim link as agent registration. The secret works at the token endpoint and also as an API key. Requests for flows the server does not offer, such as the authorization code flow, are refused with a clear reason. There is no authorization code flow, so clients that need one should use an API key instead. The secret expires with the sandbox, and claiming the workspace lifts that limit.

While self-registration is closed on a deployment, OAuth registration is closed too, and the discovery documents stop listing it.

The MCP manifest now says plainly that credentials are optional: the tool list and the demo pricing tools work without one, and a credential unlocks the workspace tools.

Every discovery document and the agent sign-in guide now open with a short list of the independent ways in, one line each on when to choose which: the keyless demo, a free key with one call, an OAuth client, pay per call with no account where it is offered, and a signed-in account owned by an agent or a person.