OAuth / OIDC Flow Debugger

Paste a redirect URI or authorization request. Detect open redirects, missing PKCE, implicit-flow smell, and scope over-grants.

Pro

Responsible use

This tool sends requests to a live third-party endpoint. Use it only on systems you own or have explicit written authorization to test. Unauthorized testing may be illegal in your jurisdiction.

Authorization request / flow config

Misconfigurations

Paste a flow config to check for common OAuth/OIDC pitfalls.

Related tools