CIMD Validator
Back to clients

Tool

Lovable

Observed from OAuth traffic.

observed: cimd
Observed evidence
Lovable authorization used client_id metadata URL https://api.lovable.dev/.well-known/oauth-client.
Observed at
2026-08-19T19:46:52.652Z
Metadata URL
https://api.lovable.dev/.well-known/oauth-client
Vendor
Unknown
Source URL
https://api.lovable.dev/.well-known/oauth-client
Claimed status
unknown

Known Metadata

Client name
Lovable
Client URI
https://lovable.dev
Logo URI
Not observed
Grant types
authorization_code, refresh_token
Response types
code
Token endpoint auth method
none
Application type
Not observed
Redirect URIs
https://api.lovable.dev/workspaces/connectors/mcp/oauth/callback

Latest OAuth Attempt

Timestamp
2026-08-19T19:46:52.652Z
Path
POST /token
Client ID
https://api.lovable.dev/.well-known/oauth-client
Client name
Go-http-client
Client version
2.0
Redirect URI
https://api.lovable.dev/workspaces/connectors/mcp/oauth/callback
Scope
Unknown
PKCE
Unknown
User agent
Go-http-client/2.0

Validation Result

pass at 2026-08-19T19:46:52.220Z

Errors

No validation errors.

Warnings

  • metadata.application_type is missing
  • metadata.logo_uri is missing

Raw metadata JSON

{
  "client_id": "https://api.lovable.dev/.well-known/oauth-client",
  "client_name": "Lovable",
  "redirect_uris": [
    "https://api.lovable.dev/workspaces/connectors/mcp/oauth/callback"
  ],
  "grant_types": [
    "authorization_code",
    "refresh_token"
  ],
  "response_types": [
    "code"
  ],
  "token_endpoint_auth_method": "none",
  "client_uri": "https://lovable.dev",
  "policy_uri": "https://lovable.dev/privacy",
  "tos_uri": "https://lovable.dev/terms",
  "software_id": "lovable",
  "code_challenge_methods_used": [
    "S256"
  ]
}