What this does
Builds the URL that sends a user to an OAuth 2.0 or OpenID Connect authorization endpoint, with every value correctly percent-encoded. It also works in reverse: paste an existing authorization URL and the form fills itself in, so you can inspect or tweak a request copied from a browser's address bar or a log.
Parameters
response_type:codefor the authorization code flow. Token-returning types such astokenandid_tokenare legacy or for hybrid flows.client_idandredirect_uri: the redirect URI must match the one registered with the provider exactly.scope: space separated; addopenidto get an ID token.state: an unguessable value you check on the callback to prevent CSRF.noncebinds the ID token to the session.code_challengeandcode_challenge_method: PKCE. The page can generate the verifier and an S256 challenge in one click.response_mode,prompt,login_hint, and any extra provider-specific parameters such asaudience.
Checks
The page points out risky requests: no PKCE on a code flow, plain PKCE, nostate, an ID token requested without a nonce,response_mode=query combined with token responses, a redirect URI that uses plain http outside localhost, contains a fragment or a wildcard, and aclient_secret that should never be in this URL. Parameters repeated in a pasted URL are reported too.
Privacy
The URL is assembled in your browser and is not sent anywhere. Opening it is your decision. The PKCE verifier stays in memory and is not stored.