RFC 7591, OAuth 2.0 dynamic client registration
Published in July 2015, this lets a client register itself with an authorization server and receive credentials without a human filling in a form. It is how agent tooling connects to servers nobody pre arranged, and it is also the mechanism the confused deputy attack abuses. The July 2026 MCP revision deprecates it.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AAL-2026-0011
- Kind
- Standard or protocol
- Jurisdiction
- Global
- Last verified
- Added
- The specification defines mechanisms for dynamically registering OAuth 2.0 clients with authorization servers.
- MCP originally recommended it so clients could connect to servers they did not know in advance.
- The MCP security guidance shows an attacker registering a client with an attacker controlled redirect URI to harvest an authorization code.
- The MCP specification of 28 July 2026 marks dynamic client registration deprecated and retained only for backwards compatibility.
Dimension by dimension
2 dimensions, each one stated, silent or open
Identity, Human approval. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentityStated
- A client identity can be created on demand, which means an identifier alone proves nothing about who is behind it.RFC Editor, RFC 7591, primary source, 1 July 2015.
- Human approvalSilent
- The specification does not require a person to approve a new registration, which is why proxies must add their own consent step.RFC Editor, RFC 7591, primary source, 1 July 2015.
What it changes
For a team deploying an agent
If your authorization server accepts dynamic registration, anyone can mint a client. Pair it with per client consent and exact redirect URI matching, or move to client identity documents as MCP now advises. Treat a self registered client id as an unverified claim, not an identity.
Sources
What this record was verified against
- RFC Editor, RFC 7591Primary · 1 July 2015
- Model Context Protocol specification 2026-07-28, AuthorizationPrimary · 28 July 2026
Related
Records that sit beside this one
Model Context Protocol security best practices
Global · verified 15 September 2026
Token passthrough is an anti pattern where a server accepts a token from a client without validating it was issued to that server, and the document forbids it.
MCP 2026-07-28 authorization hardening
Global · verified 15 September 2026
The release post states that authorization servers should return the iss parameter per RFC 9207, and clients must validate it before redeeming a code.
Does a spending limit belong to the agent or to the principal
Global · verified 15 September 2026
The Visa Trusted Agent Protocol addresses recognising an approved agent and its intent, and does not itself carry a spending ceiling.
How does a sub agent's authority attenuate
Global · verified 15 September 2026
RFC 8693 lets a token record that one party is acting for another, but does not require the exchanged token to be narrower.
Can an agent hold a credential of its own
Global · verified 15 September 2026
NIST SP 800-63-4 states that for that publication, person refers only to natural persons.
Who is liable when a delegated agent exceeds its mandate
Global · verified 15 September 2026
The EU AI Act allocates duties to providers and deployers, and does not address an agent acting beyond its instructions.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AAL-2026-0011 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Authority Ledger (as of 15 September 2026), rfc 7591, oauth 2.0 dynamic client registration.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). RFC 7591, OAuth 2.0 dynamic client registration. Agent Authority Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0011-rfc-7591-oauth-2-0-dynamic-client-registration
- MLA
- "RFC 7591, OAuth 2.0 dynamic client registration." Agent Authority Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0011-rfc-7591-oauth-2-0-dynamic-client-registration.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "RFC 7591, OAuth 2.0 dynamic client registration." Agent Authority Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0011-rfc-7591-oauth-2-0-dynamic-client-registration.
- Permalink
- https://www.gage.academy/tools/agent-authority-ledger/records/AAL-2026-0011-rfc-7591-oauth-2-0-dynamic-client-registration
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any NIST, IETF or MCP publication.
Back to the full ledger, or every record for Global and every standard or protocol record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.