Hi, Sakit.
You can always refer to [OIDC core spec](http://openid.net/specs/openid-connect-core-1_0.html). Depending on what flow you are using, you may be forced to use `https` scheme in `redirect_uri`. For `authz code` flow it's just recommended, but only in cases when OIDC client is of type "confidential". For `implicit` flow usage of `http` scheme in `redirect_uri` is prohibited with only exception when the client is a native app.