#Matt1From the spec: "The authorization endpoint SHOULD fetch the client_id URL to retrieve application information and the client's registered redirect URLs". How does that work if the client is a mobile (or desktop) app that isn't addressable over the network?