OIDC Discovery Auditor
Pricing
Pay per usage
OIDC Discovery Auditor
Audit a public OpenID Connect provider's /.well-known/openid-configuration discovery metadata. Check issuer match, required keys, https endpoints, signing algorithms, and PKCE. Returns a score and grade.
Pricing
Pay per usage
Rating
0.0
(0)
Developer
Sanskar Jaiswal
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
a day ago
Last modified
Categories
Share
Audit a public OpenID Connect provider's /.well-known/openid-configuration discovery metadata in one API call. Validates the document against the OpenID Connect Discovery 1.0 specification: required metadata keys, issuer match against the fetched URL, https endpoint URLs, ID token signing algorithms, subject types, and PKCE support. Returns a readiness score, letter grade, per-check analysis, and recommendations. Built for identity engineers, SaaS platform teams, security auditors, and QA pipelines.
Use cases
- Identity engineers - verify discovery metadata before pointing RP/client libraries at a new or upgraded IdP
- SaaS platform teams - confirm multi-tenant OIDC providers publish correct issuer values per tenant and conformant endpoint URLs
- Security auditors and pen-testers - check for issuer mismatch (clients MUST reject mismatched metadata), unsigned ID token support (
none), missing https endpoints, and weak PKCE (plain) - Site migration QA - catch discovery regressions after domain moves, CDN changes, or IdP upgrades
- CI/CD pipelines - schedule conformance checks and alert on score drops
What it checks
- Discovery document - served at
/.well-known/openid-configurationwith HTTP 200 andapplication/jsonContent-Type - JSON validity - the document body parses as a JSON object
- Required metadata keys -
issuer,authorization_endpoint,jwks_uri,response_types_supported(OIDC Discovery 1.0 section 3) - Issuer match - the declared
issuervalue matches the URL the document was fetched from (OIDC clients MUST reject mismatches); issuer must not contain query or fragment components - Endpoint URLs - every documented endpoint (
authorization_endpoint,token_endpoint,userinfo_endpoint,jwks_uri,registration_endpoint,end_session_endpoint,revocation_endpoint,introspection_endpoint,pushed_authorization_request_endpoint,device_authorization_endpoint, and more) is a parseable https URL; off-issuer-origin endpoints are flagged as a warning (common on shared IdP platforms) - ID token signing algorithms -
id_token_signing_alg_values_supportedcontains recognized JWS algorithms and does not includenone(prohibited for ID tokens) - PKCE support -
code_challenge_methods_supportedadvertisesS256;plainis flagged per RFC 7636 - Recommended keys -
token_endpoint,id_token_signing_alg_values_supported,subject_types_supportedpresence;subject_types_supportedvalues limited topublic/pairwise
Endpoint URLs found inside the metadata are never fetched - only the discovery document on the provided issuer host is read.
Input
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
startUrl | string | yes | - | Issuer URL of the OIDC provider (root domain, no path) |
timeoutSeconds | integer | no | 10 | Per-request timeout (3-30 seconds) |
Example input
{"issuer": "https://accounts.google.com","timeoutSeconds": 10}
Output
A single dataset item with the full audit:
| Field | Type | Description |
|---|---|---|
inputIssuer | string | The issuer URL provided as input |
discoveryUrl | string | The /.well-known/openid-configuration URL that was fetched |
finalUrl | string | Final URL after redirects |
https | boolean | Whether the discovery document was served over HTTPS |
status | integer | Final HTTP status code |
documentFound | boolean | Whether a 200 discovery document was served |
jsonValid | boolean | Whether the document body is valid JSON |
parseError | string | null | JSON parse error message, or null |
issuer | string | null | Declared issuer value in the metadata |
issuerMatchesFinalUrl | boolean | Whether the declared issuer matches the fetched URL |
requiredKeys | array | Required metadata keys present |
missingRequiredKeys | array | Required metadata keys missing |
missingRecommendedKeys | array | Recommended metadata keys missing |
metadataKeyCount | integer | Total metadata keys in the document |
endpoints | array | Per-endpoint analysis (key, url, https, parseable, issuerHost, issues) |
responseTypes | array | null | response_types_supported values |
subjectTypes | array | null | subject_types_supported values |
signingAlgs | array | null | id_token_signing_alg_values_supported values |
codeChallengeMethods | array | null | code_challenge_methods_supported values (PKCE) |
tokenAuthMethods | array | null | token_endpoint_auth_methods_supported values |
scopes | array | null | scopes_supported values |
grantTypes | array | null | grant_types_supported values |
pkceSupported | boolean | Whether PKCE code challenge methods are advertised |
checks | array | Per-check analysis (name, status, note, weight, recommendation) |
issues | array | Aggregated issue descriptions |
score | integer | OIDC discovery readiness score (0-100) |
grade | string | Letter grade (A+, A, B, C, D, E, F) |
checkedAt | string | ISO 8601 timestamp |
recommendations | array | Actionable recommendations |
Example output (abridged)
{"inputIssuer": "https://accounts.google.com","discoveryUrl": "https://accounts.google.com/.well-known/openid-configuration","documentFound": true,"jsonValid": true,"issuer": "https://accounts.google.com","issuerMatchesFinalUrl": true,"missingRequiredKeys": [],"signingAlgs": ["RS256"],"codeChallengeMethods": ["S256", "plain"],"pkceSupported": true,"score": 92,"grade": "A","checks": [{"name": "Issuer match","check": "issuer","status": "good","note": "issuer 'https://accounts.google.com' matches the discovery document URL.","weight": 20,"recommendation": null}],"recommendations": []}
Security
- Public HTTP/HTTPS only; rejects URL credentials, private IP literals (IPv4 and IPv6), private DNS resolutions, and revalidates redirects before following.
- Fetches only the discovery document on the provided issuer host; endpoint URLs found inside the metadata are never fetched.
- Bounded body read (2 MB cap); no login, no JavaScript execution, no cookies, no stored page content.
Pricing
Pay-per-event: one scored audit per run (~$0.015/run).
| Event | Price |
|---|---|
| Actor start | $0.005 |
| Per issuer audited | $0.01 |
FAQ
Does this fetch the JWKS or test the authorization endpoint?
No. Only the discovery document is fetched. Endpoint URLs and jwks_uri are validated as metadata strings so the actor cannot be used to probe arbitrary URLs.
Why does issuer mismatch matter?
OIDC Discovery 1.0 section 3 requires the issuer value to be identical to the issuer identifier used to construct the discovery URL. RFC 8414-conformant clients MUST reject metadata where they differ - a mismatch silently breaks client discovery.
Can I audit an OAuth 2.0 authorization server without OIDC?
This actor audits the OIDC discovery document. OAuth AS metadata (/.well-known/oauth-authorization-server) overlaps heavily but is a separate RFC 8414 layout; only use this actor for OpenID Connect providers.
Local development
npm installnpm test # node --test suite (parsers, SSRF, scoring, live smoke)npm run lint # node --checkpython3 ../scripts/audit_actor.py . # portfolio security audit (run from actors/ dir)