mirror of
https://github.com/supabase/supabase.git
synced 2026-10-10 20:05:06 +03:00
## I have read the [CONTRIBUTING.md](https://github.com/supabase/supabase/blob/master/CONTRIBUTING.md) file. YES ## What kind of change does this PR introduce? Docs update ## Summary The OAuth server supports three token endpoint authentication methods (`none`, `client_secret_basic`, `client_secret_post`), but the docs only showed `client_secret_post` implicitly without labeling it, and never mentioned client_secret_basic (the actual default for confidential clients per RFC 7591). - Add `token_endpoint_auth_method` explanation with defaults/constraints to the client registration section in getting-started.mdx - Update registration examples (JS, Python, cURL) and response JSON to include token_endpoint_auth_method - Restructure token exchange and refresh token sections in oauth-flows.mdx to show all three auth methods with clear labels - Add `client_secret_basic` examples using HTTP Basic auth header