If you want no secret then you need to change your client metadata, in whatever format, to reflect what client authn methods you want to allow, namely "none" I believe. -- Scott