0.x — pre-release, no compatibility promise yet.What this means
Register a client (RFC 7591 dynamic client registration)
Register a client (RFC 7591) - how MCP clients connect without a developer account. The client is public: no secret, PKCE on every authorization. No authentication; limited per address.
Request Bodyrequired
Section titled “Request Bodyrequired”The metadata a client sends to register itself. Unknown fields are ignored (RFC 7591 §2).
object
Shown on the consent screen
Exact strings: https, http on a loopback host (localhost, any port), or a desktop client’s scheme (cursor, vscode, vscode-insiders, claude)
Must be none: a registered client is public and proves itself with PKCE; it never gets a secret
Responses
Section titled “ Responses ”Successful Response
Returned by oauth.register.
object
Public identifier (tkdc_…). There is no client secret.
Unix seconds
The scopes the client may ask for, space-separated
Example
{ "client_id": "tkdc_Q2x9eLr0v2Zk5n8WcHt1YpUo", "client_id_issued_at": 1790500000, "client_name": "Claude Code", "grant_types": [ "authorization_code", "refresh_token" ], "redirect_uris": [ "http://localhost:53682/callback" ], "response_types": [ "code" ], "scope": "tasks:read tasks:write projects:read teams:read members:read", "token_endpoint_auth_method": "none"}The metadata is refused: invalid_client_metadata or invalid_redirect_uri (RFC 7591)
Too many registrations from this address; wait Retry-After seconds
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "Forbidden", "status": 403, "detail": "This task is restricted to other users", "instance": "/v1/tasks/T123", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11", "errors": [ {} ], "mfa": { "enrolled": false, "required_for": "all", "reason": "org_policy" }}Registration is closed for now (too many registered clients)
An RFC 9457 problem details object - the body of every error response. detail is the human-readable explanation; request_id identifies the request for support.
object
about:blank or a urn:taskadence:problem:* identifier
Human-readable explanation (a string; for a 422, the list of validation errors)
Structured failures: validation errors, or {loc, msg, allowed} for a bad parameter
object
On an mfa-required problem only: enrolled (does the person have an authenticator app set up), required_for (all or admins) and reason (org_policy: the organization’s requirement; step_up: this action needs a second step)
object
Example
{ "type": "about:blank", "title": "Forbidden", "status": 403, "detail": "This task is restricted to other users", "instance": "/v1/tasks/T123", "request_id": "9b2f1c1e-8c1a-4a53-9f9e-0f5f1f2d7c11", "errors": [ {} ], "mfa": { "enrolled": false, "required_for": "all", "reason": "org_policy" }}