Public, non-secret OAuth client metadata used by TheHive-controlled MCP clients.
- No access tokens, refresh tokens, client secrets, credentials, prompts, media, or client-project data belong in this repository.
- Redirect URIs are exact and use OAuth Authorization Code with PKCE through the consuming client.
- Changes require review because the metadata URL itself acts as the OAuth client identifier.
artlist-openclaw-v1.json describes the local OpenClaw MCP OAuth callback and includes its exact URL as the Client Identifier. OpenClaw stores the resulting OAuth credentials in its owner-only state store; they are never published here.
artlist-openclaw.json is retained as the initial superseded interoperability test and must not be used as the active client identifier.