> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sharedgraph.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Register an application

> Request controlled admission for a server-backed confidential client.

Email [hello@sharedgraph.com](mailto:hello@sharedgraph.com) with the template below. Registration is operator-reviewed, not self-serve. The supported integration is a [server-backed confidential client](/authorization); browser-only and mobile-only public clients are unsupported.

```text theme={null}
Application name:
Operator name:
Operator contact:
Redirect URI:
Requested scopes:

Safety scope justification (if requesting blocks or reports):
Preferred secure channel for credential delivery:
```

The application operator is the party accountable for the application's behavior and lifecycle obligations. Name that party and provide a reachable contact. The registration request names the operator. The registry records the application name, operator contact, exact registered redirect URI, approved scope set and application lifecycle status. This information supports admission, contact and suspension decisions.

Use an exact callback URI, such as `https://localhost:4303/callback` for the starter's default local HTTPS development server. A production deployment needs its own exact HTTPS callback. A local synthetic HTTP loopback exception is explicit and operator-controlled; it is not a general HTTP redirect allowance.

The starter requests:

```text theme={null}
openid profile offline_access read post:create post:edit post:delete inbox:read inbox:write
```

Request only the capabilities you need. Add a justification for safety scopes `block:read`, `block:write` or `report:write`; they are granted on request. See [scopes](/scopes) for the complete capability list. Registration approves only the requested scopes, not every supported capability.

## Receive and protect credentials

After approval, the operator registers the application and deploys its client configuration. You receive a client identifier and client secret through the agreed secure channel. `APP_ID` and `CLIENT_ID` in the starter must both equal that registered identifier. Do not send credentials in a public issue, commit, screenshot or log.

The registration command displays the generated secret once, and the provider stores a hash. The pilot also requires the plaintext secret in deployed Worker secret configuration for introspection; it is not written to a credential file or evidence artifact by the registration command. Protect your received copy in server-side secret storage. Never ship it to browser or mobile code. If it is lost or exposed, contact the operator rather than attempting to recover it from logs.

A new application begins active and remains subject to network suspension and reinstatement. Registration is not a user authorization grant: users must still deliberately consent before it can act for their actor. Read the [lifecycle and safety rules](/lifecycle-and-safety) before serving users.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.