Shown to people on the consent screen, next to what the application asks for.
Drop an image or click to browse
Square image, 1 MB maximum, shown on the sign-in and consent screens. Uploaded here: links to images elsewhere are not accepted.
Decides which redirect URIs are accepted. Cannot be changed later.
One per line, matched exactly.
Optional, one per line: where the application may send people after signing them out.
Need people's email address or their Cube Community groups? Ask [email protected], saying which application and why: an admin grants them.
Has a client secret (a server-side application). Off for a single-page or native app, which must use PKCE instead. Cannot be changed later.
How the application authenticates at the token endpoint: any other method is refused.
Keep on unless the application cannot do PKCE: its secret then authenticates it on its own.