New application

Its client secret is shown once, right after it is created.

Shown to people on the consent screen, next to what the application asks for.
Drop an image or click to browse
Square image, 1 MB maximum, shown on the sign-in and consent screens. Uploaded here: links to images elsewhere are not accepted.
Decides which redirect URIs are accepted. Cannot be changed later.
One per line, matched exactly.
Optional, one per line: where the application may send people after signing them out.

Required for OpenID Connect: an ID token identifying the user.

Display name, username and avatar.

Linked accounts (Discord, BeatLeader, ScoreSaber, Steam) and the game account, with their ids.

The Discord user id, as a discord_id claim.

Refresh tokens, to stay signed in without the user.

Need people's email address or their Cube Community groups? Ask [email protected], saying which application and why: an admin grants them.

Has a client secret (a server-side application). Off for a single-page or native app, which must use PKCE instead. Cannot be changed later.

How the application authenticates at the token endpoint: any other method is refused.

Keep on unless the application cannot do PKCE: its secret then authenticates it on its own.

Cancel
Cube Community © 2026