The ArgoCD mobile app and CLI are native clients that cannot hold a
secret, and Authentik derives the iss claim from the application slug,
so they cannot have a client of their own either. Serve all three
clients from the one provider.
- switch client_type to public
- add argocd://auth/callback as a strict redirect URI