Application registration
How to register an application
Application registration is handled by the Klubero support team. To register a new application, contact support@klubero.cz with the following information:
| Required information | Description | Example |
|---|---|---|
| Application name | A human-readable name shown to users during consent | "My Awesome App" |
| Application description | A brief description of your application | "A project management tool" |
| Redirect URI | A list of allowed callback URLs (HTTPS required) | https://app.example.com/callback |
| Post-logout redirect URI | URL to redirect to after sign-out (optional) | https://app.example.com/ |
| Requested scopes | The permissions your application needs | openid profile email |
| Client type | Public or confidential (see below) | Confidential |
| Application logo | URL of your application's logo (optional) | https://app.example.com/logo.png |
Client types
Confidential clients
Use these for applications that can securely store a client secret:
- Server-side web applications (Node.js, PHP, Python, C#, Java)
- Backend services and APIs
Characteristics:
- Receive both a
client_idand aclient_secret - Must authenticate with the secret when exchanging tokens
- Higher level of security
- Can use all grant types
Public clients
Use these for applications that cannot securely store secrets:
- Single Page Applications (React, Vue, Angular)
- Mobile apps (iOS, Android)
- Desktop applications
Characteristics:
- Receive only a
client_id(no secret) - PKCE is required for the authorization code flow
- Cannot use the client credentials flow
- The
client_secretparameter is omitted from requests
What you'll receive
After registration you'll receive:
Client ID: your-app-client-id
Client Secret: your-app-client-secret (confidential clients only)
Important security notes
- Store the
client_secretsecurely (environment variables, a secret manager) - Never commit secrets to version control
- Never expose secrets in frontend/client-side code
- Rotate secrets regularly
Redirect URI requirements
- Must use HTTPS (except
localhostfor development) - Must match the registered URI exactly (including trailing slashes)
- Wildcards are not supported – matching is done by exact, full-string comparison
- Multiple URIs can be registered for different environments
Examples of valid redirect URIs:
https://app.example.com/callback
https://app.example.com/auth/callback
https://staging.example.com/callback
http://localhost:3000/callback (development only)