A public client identifies itself to the provider with a hosted Client ID Metadata Document. Serve it unauthenticated and outside the auth group, since the provider fetches it server-to-server, exposing the deployment-derived client_id and redirect_uri alongside the Probo brand name, homepage and logo. Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>