OIDC Debugger — Debug OpenID Connect Authorization Flows Free
Build and inspect OpenID Connect authorization URLs for Google, Microsoft, Auth0, Okta, and custom providers.
Jump to tool ↓Frequently Asked Questions
OpenID Connect Authorization Flow
OpenID Connect (OIDC) is the identity layer built on OAuth 2.0 that enables SSO (Single Sign-On) across modern web applications. It is used by Google Sign-In, Microsoft Login, Auth0, Okta, and virtually every enterprise identity provider.
The Authorization Code flow works like this: your application redirects the user to the identity provider with an authorization URL containing your client_id, redirect_uri, requested scopes, and a state value (for CSRF protection). After the user authenticates, the provider redirects back with an authorization code. Your backend exchanges this code for tokens using the token endpoint.
For single-page apps and mobile apps, always use the Authorization Code + PKCEflow instead of the Implicit flow. Implicit flow (response_type=token) is deprecated and insecure.
Standards & References
Built and maintained by DevDecode. This tool processes your input in your browser; it is not uploaded for processing. Found an issue? Let us know.
Related Tools
Related Guides
PKCE Code Verifier and Challenge: S256 Example
Generate a compliant PKCE code verifier, derive its S256 challenge, and place each value in the correct OAuth authorization and token requests.
AuthenticationWhat Is OAuth 2.0 and How Does It Work?
OAuth 2.0 lets apps access resources on your behalf without sharing your password. Learn the roles, the authorization flow, access vs refresh tokens, and OAuth vs OIDC.
AuthenticationWhat Is SAML and How Does Single Sign-On Work?
SAML is an XML standard that enables single sign-on between identity providers and apps. Learn how SAML works, what a SAML assertion is, and how it compares to OAuth.
Authentication'"audiences in jwt are not allowed" — Fix It'
Learn why you're seeing "audiences in jwt are not allowed" and how to fix JWT audience validation errors in your application.