Shown to users on the wallet consent screen.
Exact‑match allow‑list for the OAuth redirect. http(s) only.
Attributes you may receive if the user discloses them. Empty = login only (just the alias sub). Request the least you need.
You must accept the terms to receive a client secret.