OIDC
Compare HTTPS discovery endpoints and supported grants. JWT verification requires an explicit issuer, audience and trusted JWKS; no token-provided key URL is followed.
Inspect OIDC discovery, verify JWTs and test authorized service clients.
Start with a sample or add your own input.
Your result will appear here.
Understand the format, the calculation, and what to look for.
Compare HTTPS discovery endpoints and supported grants. JWT verification requires an explicit issuer, audience and trusted JWKS; no token-provided key URL is followed.
Client Credentials sends one authorized request and masks token material. No production credential storage, refresh loop, automatic revocation or user-password collection occurs.
Metadata and assertion structure inspection only. XML signature, trust-chain, replay protection, PKCE login and SP-initiated sessions are not implemented by this inspector; parsing is never reported as authentication success.