Register your app
Create a client, register callback URLs, and test with your own account.
Create a client
Sign in with a verified Comick account and open My apps. Each developer can register up to ten apps.
Choose a confidential backend client or a public browser/native client. Client type and platform cannot be changed after creation; register a new app if that architecture changes.
Supply a name (3–80 characters), description and reason for access (10–2,000 characters each), and 1–10 callback URLs. Explain what you will synchronize and why. Keep descriptions understandable to users: the registered name and description appear on Comick's consent page.
Save your credentials
Copy the client_id. Confidential clients also receive a client_secret, shown once. Store it in your server's secret manager or environment configuration. Do not commit it or include it in browser JavaScript, mobile binaries, URLs, or logs.
Public clients have no secret. Their authorization requests are protected by PKCE and exact callback validation.
Register callbacks
Comick matches the entire callback URL, including its path. Wildcards are not supported. Register development and production callbacks separately.
- Use HTTPS for hosted callbacks, such as
https://your-app.example/oauth/comick/callback. - HTTP is allowed for loopback development, such as
http://127.0.0.1:3000/oauth/comick/callback. - Public native clients may use reverse-domain schemes, such as
dev.example.reader:/oauth/comick. - Keep every URL at most 2,048 characters. Register the exact callback you send in authorization and token requests.
For public browser clients, the origins of registered HTTP(S) callbacks also determine allowed cross-origin token and library requests. Send those requests with credentials: "omit".
Test before review
A new app can connect only its owner's eligible account. Consent still appears and cannot be bypassed. Other users cannot authorize it until approval. The consent page labels development apps accordingly.
When testing works, add screenshots and submit for review.
Rotate a secret
Use the dashboard's rotation control if a secret is lost or exposed. Save the replacement immediately; it is shown once. Rotation invalidates the old secret immediately, so coordinate deployment of the new value across your backend workers.
Existing access tokens are not automatically revoked by secret rotation. Future exchanges and refreshes require the new secret. Public clients do not rotate a secret because they do not have one.