TheAngryPit/oauth-client-metadata

Public non-secret OAuth client metadata for TheHive-controlled integrations

★ 0Forks 0GitHub ↗Compare

README

TheHive OAuth Client Metadata

Public, non-secret OAuth client metadata used by TheHive-controlled MCP clients.

Security boundary

  • No access tokens, refresh tokens, client secrets, credentials, prompts, media, or client-project data belong in this repository.
  • Redirect URIs are exact and use OAuth Authorization Code with PKCE through the consuming client.
  • Changes require review because the metadata URL itself acts as the OAuth client identifier.

Artlist / OpenClaw

artlist-openclaw-v1.json describes the local OpenClaw MCP OAuth callback and includes its exact URL as the Client Identifier. OpenClaw stores the resulting OAuth credentials in its owner-only state store; they are never published here.

artlist-openclaw.json is retained as the initial superseded interoperability test and must not be used as the active client identifier.

Contributors

TheAngryPit

Issues