https://localhost:4303/callback for the starter’s default local HTTPS development server. A production deployment needs its own exact HTTPS callback. A local synthetic HTTP loopback exception is explicit and operator-controlled; it is not a general HTTP redirect allowance.
The starter requests:
block:read, block:write or report:write; they are granted on request. See scopes for the complete capability list. Registration approves only the requested scopes, not every supported capability.
Receive and protect credentials
After approval, the operator registers the application and deploys its client configuration. You receive a client identifier and client secret through the agreed secure channel.APP_ID and CLIENT_ID in the starter must both equal that registered identifier. Do not send credentials in a public issue, commit, screenshot or log.
The registration command displays the generated secret once, and the provider stores a hash. The pilot also requires the plaintext secret in deployed Worker secret configuration for introspection; it is not written to a credential file or evidence artifact by the registration command. Protect your received copy in server-side secret storage. Never ship it to browser or mobile code. If it is lost or exposed, contact the operator rather than attempting to recover it from logs.
A new application begins active and remains subject to network suspension and reinstatement. Registration is not a user authorization grant: users must still deliberately consent before it can act for their actor. Read the lifecycle and safety rules before serving users.