Dynamically registered in-browser public clients are effectively one-time-use and shouldn't outlive their active tokens by very much, if at all. Should we have a parameter that indicates the client is one such thing to allow the auth server to expire the registration at a future point? This would let auth servers clean up after public clients.