Inspect JWT, SAML, OIDC discovery, JWKS, WebAuthn, and SCIM artifacts locally. Flag structural risks, generate PKCE S256, and save a private workspace.
Paste a bounded compact JWT, SAML assertion, discovery document, JWKS, WebAuthn credential shape, or SCIM resource. The lab extracts normalized facts and flags unsafe algorithms, exposed private JWK parameters, missing fields, and validity-window concerns.
Parsing is not signature verification, issuer trust, audience validation, or authorization. Generate a PKCE S256 pair with Web Crypto, save only the normalized analysis, and continue into focused verification and federation tools.
No. Decoding only exposes structure. Signature verification also needs an expected algorithm and trusted key, while authentication additionally requires issuer, audience, time, nonce, and application-policy checks.
Raw identity artifacts and PKCE verifiers are not included in the workspace. Only normalized inspection facts, findings, and the non-secret PKCE challenge can be saved.
Yes. It accepts XML, base64-encoded XML, URL-encoded input, and a SAMLResponse form value. DTD and entity declarations are rejected, and signature presence is reported separately from verification.
Decode and inspect JWT tokens instantly. View header, payload, and verify signatures with security validation.
Comprehensive OAuth 2.0 and OpenID Connect debugging tool. Decode JWT tokens, generate PKCE challenges, test authorization flows, validate redirect URIs, and troubleshoot common OAuth errors - all in your browser.
Compare federated identity protocols including SAML 2.0, OpenID Connect, OAuth 2.0, and Kerberos. Answer environment and requirement questions to get scored protocol recommendations with visual authentication flow diagrams and a Kerberos troubleshooter.
Decode and analyze X.509 SSL/TLS certificates. Parse PEM, DER, and CRT formats with detailed certificate chain validation and security analysis.