How to use OAuth and OIDC Client Configuration Audit
- Supply the declared oauth/oidc client configuration using the supported input described beside the controls.
- Review the selected options and the declared scope, then run the oauth client configuration audit.
- Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.
Example: OAuth and OIDC Client Configuration Audit
Check registered redirects and grant/response settings as a declared client configuration. This example uses synthetic public data.
Options
- Client type
- Public and confidential clients have different assumptions. Supply the type actually used; never include a client secret.
- Redirects and flows
- Review exact redirect entries, grant/response settings and the declared PKCE method together. Provider-specific behavior remains untested.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
Configuration is one part of the flow
A registered redirect and a PKCE setting must still be enforced by the actual provider and client. This review cannot discover that behavior. Use the findings to compare the declared configuration with the intended client type; do not treat a clear report as protocol or security certification.
Questions about OAuth and OIDC Client Configuration Audit
Should I include a client secret?
No. This review uses public configuration and refuses secret fields.
Does it test my provider?
No. It compares the supplied declarations with its supported offline rules.
Will it change a redirect?
No. Findings are a worksheet for deliberate review in the real application.