OAuth and OIDC Client Configuration Audit

Review declared OAuth or OIDC client redirects, flow settings and PKCE choices as an offline configuration worksheet.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Review client settings controls

Offline declared subset only: spa/native/web, HTTPS endpoints, redirect_uris, flows, PKCE/auth method and state/nonce booleans. Up to 50 redirects. Never paste a client secret or token.

Processed in your browser. Your inputs stay on this device.

Showing a generated example. Generate again for a new result.

How to use OAuth and OIDC Client Configuration Audit

  1. Supply the declared oauth/oidc client configuration using the supported input described beside the controls.
  2. Review the selected options and the declared scope, then run the oauth client configuration audit.
  3. Read the result and unresolved findings before downloading or sharing a report. The original input is not changed.

Example: OAuth and OIDC Client Configuration Audit

Check registered redirects and grant/response settings as a declared client configuration. This example uses synthetic public data.

You add
Declared OAuth/OIDC client configuration: { "client_type": "spa", "authorization_endpoint": "https://login.example/authorize", "token_endpoint": "https://login.example/token", "issuer": "https://login.example", "redirect_uris": [ "https://app.example/callback" ], "response_types": [ "code" ], "grant_types": [ "authorization_code" ], "pkce_method": "S256", "token_endpoint_auth_method": "none", "state_required": true, "oidc": true, "nonce_required": true, "exact_redirect_matching": true }
You get
0 configuration finding(s) need review across 8 declared checks. Endpoint declarations | Supported HTTPS form | No endpoint discovery or issuer trust is verified. Flows | Code scenario | The declared flow uses authorization code; actual server enforcement is unverified. PKCE | Declared S256 | S256 is the supported PKCE protection. A declaration is not evidence that verifier/challenge binding is enforced.

Options

Client type
Public and confidential clients have different assumptions. Supply the type actually used; never include a client secret.
Redirects and flows
Review exact redirect entries, grant/response settings and the declared PKCE method together. Provider-specific behavior remains untested.

Supported inputs and limits

Declared local configuration only. No issuer discovery, provider calls, authentication, client-secret handling or automatic configuration changes.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Configuration is one part of the flow

A registered redirect and a PKCE setting must still be enforced by the actual provider and client. This review cannot discover that behavior. Use the findings to compare the declared configuration with the intended client type; do not treat a clear report as protocol or security certification.

Questions about OAuth and OIDC Client Configuration Audit

Should I include a client secret?

No. This review uses public configuration and refuses secret fields.

Does it test my provider?

No. It compares the supplied declarations with its supported offline rules.

Will it change a redirect?

No. Findings are a worksheet for deliberate review in the real application.

Project manager: Tony Hines · Content updated 4 October 2026 · Report a problem