# Create an app

Register your app to get a client ID, and a client secret if it runs on a server.

Anyone with a Street Art Cities account can create apps. You can have up to 10.

<Admonition kind="tip" title="Test in the sandbox first">
  While you're building your app, create it on
  [streetartdev.com](https://streetartdev.com) instead, so your tests don't end
  up on the live website. See [Testing
  sandbox](/getting-started/testing-sandbox/).
</Admonition>

## Add your app

1. Log in on [streetartcities.com](https://streetartcities.com).
2. Go to **[Settings → Developers](https://streetartcities.com/me/settings#developers)**.
3. Click **Create app** and fill in:
   - **Name** and **description**: shown to people on the consent page, so make it clear who you are.
   - **Website** (optional): a link to your app or project.
   - **Redirect links**: where we send people back to after they've said yes or no, for example `https://example.com/callback` or `myapp://oauth`.
   - **Where does your app run?**: on a server, or in a browser or on a phone.
4. Save, and copy your **client ID** (and **client secret**, if you get one).

<Admonition kind="warning" title="Keep your secret safe">
  We only show the client secret once. Store it somewhere safe on your server,
  and never put it in a mobile app, a browser app or a public repository. If it
  leaks, create a new one from the same settings page; the old one stops working
  right away.
</Admonition>

## Server apps and public apps

| Your app runs…                      | Client secret | How it proves who it is |
| ----------------------------------- | ------------- | ----------------------- |
| On a server you control             | Yes           | Client secret           |
| On a phone, desktop or in a browser | No            | PKCE only               |

Apps that run on someone's own device can't keep a secret, so they're _public_ apps. You pick this when you create the app, and it can't be changed later. Create a new app if you need to switch.

## Redirect links

Redirect links need to match **exactly**: same scheme, host, path and query. If you use different links for local development and production, add them all.

## Changing or deleting your app

You can change the name, description, website and redirect links at any time. Deleting an app logs out everyone who's using it: their refresh tokens stop working straight away.
