>_devtools

OAuth Authorization URL Builder

Build or parse an OAuth 2.0 and OpenID Connect authorization URL with scope, state, nonce, PKCE, and extra parameters, and get warnings about risky settings.

What this does

Builds the URL that sends a user to an OAuth 2.0 or OpenID Connect authorization endpoint, with every value correctly percent-encoded. It also works in reverse: paste an existing authorization URL and the form fills itself in, so you can inspect or tweak a request copied from a browser's address bar or a log.

Parameters

  • response_type: code for the authorization code flow. Token-returning types such as token and id_token are legacy or for hybrid flows.
  • client_id and redirect_uri: the redirect URI must match the one registered with the provider exactly.
  • scope: space separated; add openid to get an ID token.
  • state: an unguessable value you check on the callback to prevent CSRF. nonce binds the ID token to the session.
  • code_challenge and code_challenge_method: PKCE. The page can generate the verifier and an S256 challenge in one click.
  • response_mode, prompt, login_hint, and any extra provider-specific parameters such as audience.

Checks

The page points out risky requests: no PKCE on a code flow, plain PKCE, nostate, an ID token requested without a nonce,response_mode=query combined with token responses, a redirect URI that uses plain http outside localhost, contains a fragment or a wildcard, and aclient_secret that should never be in this URL. Parameters repeated in a pasted URL are reported too.

Privacy

The URL is assembled in your browser and is not sent anywhere. Opening it is your decision. The PKCE verifier stays in memory and is not stored.