OAuth & Sign in with Sporty

Registering an application

How to get a client id, what a redirect URI may look like, and what "pending review" means.

There are three ways to get a client id.

HowWhoWhat you get
A club administrator registers it in the Sporty admin, under Settings → API clientsAnyone building for one clubA confidential client, already approved, tied to that club
We register it for youPartners integrating across many clubsA confidential client, plus a per-club grant for each club that agrees
Dynamic registrationAgents and MCP clientsA public client, pending review

Redirect URIs

The authorization code is delivered to whatever you register here, so this is the one setting worth getting exactly right. We enforce:

  • https only — with one exception below
  • no wildcards — https://*.example.com/cb is refused
  • no fragments — https://example.com/cb#anything is refused
  • exact match at authorization time; a URI that is merely similar is not accepted

The exception is the loopback address. A desktop, CLI or native application has no https address of its own, so http://127.0.0.1/callback and http://localhost/callback are allowed, and the port is ignored when matching (RFC 8252).

Client secrets

A confidential client gets a secret once, in the response that creates it. It is stored hashed, so nobody — including us — can read it back. If it is lost, rotate it and update your application.

Rotating a secret does not revoke existing tokens. Sessions your application already holds keep working; only new token requests need the new secret.

A public client (anything that cannot keep a secret: a browser app, a mobile app, a CLI) has no secret at all. PKCE is what protects it, and PKCE is required for every client regardless.

Approval

A client registered by a club administrator, or by us, is approved from the start.

A client that registered itself is pending. It works — but only for the account that registered it. That is deliberate: you can build and test an integration end to end before anyone at Sporty has spoken to you, and until we have reviewed it nobody else's account is exposed. When you are ready, contact us and we will review it.

A member is told, on the consent screen, when an application has not been reviewed.

Being removed

Two things can end an integration:

  • Deleting the application (its owner) revokes every token immediately.
  • Banning it (Sporty staff) does the same and refuses new ones. Reserved for applications doing something they should not.

Neither is reversible from your side, and neither is a surprise — we will have talked to you first unless something is actively going wrong.