# OAuth And Partners Boundary

The root Partners app syncs runtime app metadata into Anan through the app registration contract. Anan stores only the mirror fields needed by OAuth:

- client id
- optional secret hash
- display metadata
- redirect URIs
- allowed scopes
- trusted/active flags
- client type
- timestamps

The sync token is `ANAN_APP_REGISTRATION_SYNC_TOKEN`. Anan OAuth flows use this mirror for client validation, redirect validation, scope validation, consent, grants, and token exchange. App reviews, developer orgs, app lifecycle state, portal audit logs, and developer auth do not belong in Anan.