Registering an application
There are three ways to get a client id.
| How | Who | What you get |
|---|---|---|
| A club administrator registers it in the Sporty admin, under Settings → API clients | Anyone building for one club | A confidential client, already approved, tied to that club |
| We register it for you | Partners integrating across many clubs | A confidential client, plus a per-club grant for each club that agrees |
| Dynamic registration | Agents and MCP clients | A public client, pending review |
Redirect URIs
The authorization code is delivered to whatever you register here, so this is the one setting worth getting exactly right. We enforce:
httpsonly — with one exception below- no wildcards —
https://*.example.com/cbis refused - no fragments —
https://example.com/cb#anythingis refused - exact match at authorization time; a URI that is merely similar is not accepted
The exception is the loopback address. A desktop, CLI or native application has no https
address of its own, so http://127.0.0.1/callback and http://localhost/callback are
allowed, and the port is ignored when matching (RFC 8252).
Client secrets
A confidential client gets a secret once, in the response that creates it. It is stored hashed, so nobody — including us — can read it back. If it is lost, rotate it and update your application.
Rotating a secret does not revoke existing tokens. Sessions your application already holds keep working; only new token requests need the new secret.
A public client (anything that cannot keep a secret: a browser app, a mobile app, a CLI) has no secret at all. PKCE is what protects it, and PKCE is required for every client regardless.
Approval
A client registered by a club administrator, or by us, is approved from the start.
A client that registered itself is pending. It works — but only for the account that registered it. That is deliberate: you can build and test an integration end to end before anyone at Sporty has spoken to you, and until we have reviewed it nobody else's account is exposed. When you are ready, contact us and we will review it.
A member is told, on the consent screen, when an application has not been reviewed.
Being removed
Two things can end an integration:
- Deleting the application (its owner) revokes every token immediately.
- Banning it (Sporty staff) does the same and refuses new ones. Reserved for applications doing something they should not.
Neither is reversible from your side, and neither is a surprise — we will have talked to you first unless something is actively going wrong.