Free Tool · Client-Side Only

OAuth 2.0 / OIDC
Token Debugger.

Decode and inspect OAuth 2.0 access tokens and OIDC ID tokens. Analyse scopes, claims, expiry, and detect authentication misconfigurations.

🔑

Token Decoder

🔐

PKCE Helper — code_verifier & code_challenge

Generate a PKCE pair for the Authorization Code with PKCE flow. The verifier is sent at token exchange; the challenge is sent at authorization.

Related free tools

Read next

OAuth 2.0 security vulnerabilities

Redirect URI tricks, missing state, implicit-flow leaks and token misuse — with the checks that prevent each.

The token looks fine. Does the code that accepts it?

Find broken auth flows
before an attacker does.

AquilaX SAST and API Security scanners trace how tokens are validated in your code — missing audience checks, alg:none acceptance, unbounded expiry, redirect URIs built from user input — and open the fix PR.

Free plan is permanent · unlimited scans · GitHub, GitLab, Bitbucket & Azure DevOps