Client ID Metadata Document
Host a JSON document over HTTPS at the exact URL you use asclient_id. It must include your app’s name, its redirect_uris, and how it authenticates at the token endpoint. Whirl fetches and validates the document.
Metadata documents support none and private_key_jwt. You can allow both with token_endpoint_auth_methods_supported. To use private_key_jwt, publish a jwks_uri over HTTPS. Whirl only accepts the methods you list. If an assertion is rejected, the request fails; Whirl won’t retry it as a public client.
none with PKCE. Only list private_key_jwt if your app supports it.
Dynamic Client Registration
Post your metadata as JSON to the registration endpoint:client_id it returns for sign-in and token requests. Server-side apps can choose client_secret_basic, client_secret_post or private_key_jwt. For private_key_jwt, send either an inline jwks with your public keys or a jwks_uri, not both. Never send your private key.
Redirect URIs
Whirl checks the redirect URI before sending the user back. Web apps must use an exact HTTPS URL they registered. Native apps can also usehttp on a loopback address, or a private-use URI scheme. Loopback redirects can use any port, but the host, path and query must match. Fragments, non-loopback http, wildcards and some schemes are rejected.

