Should the Auth token and/or client ID be secret?

Your redirect URL is incomplete it should be the URL Encoding of “http://localhost/

After hitting “continue” you’ll be sent to the Default Redirect URI, which will contain an error_description query strin parameter, that will describe the error.