OIDC Discovery Auditor avatar

OIDC Discovery Auditor

Pricing

Pay per usage

Go to Apify Store
OIDC Discovery Auditor

OIDC Discovery Auditor

Audit a public OpenID Connect provider's /.well-known/openid-configuration discovery metadata. Check issuer match, required keys, https endpoints, signing algorithms, and PKCE. Returns a score and grade.

Pricing

Pay per usage

Rating

0.0

(0)

Developer

Sanskar Jaiswal

Sanskar Jaiswal

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

a day ago

Last modified

Share

Audit a public OpenID Connect provider's /.well-known/openid-configuration discovery metadata in one API call. Validates the document against the OpenID Connect Discovery 1.0 specification: required metadata keys, issuer match against the fetched URL, https endpoint URLs, ID token signing algorithms, subject types, and PKCE support. Returns a readiness score, letter grade, per-check analysis, and recommendations. Built for identity engineers, SaaS platform teams, security auditors, and QA pipelines.

Use cases

  • Identity engineers - verify discovery metadata before pointing RP/client libraries at a new or upgraded IdP
  • SaaS platform teams - confirm multi-tenant OIDC providers publish correct issuer values per tenant and conformant endpoint URLs
  • Security auditors and pen-testers - check for issuer mismatch (clients MUST reject mismatched metadata), unsigned ID token support (none), missing https endpoints, and weak PKCE (plain)
  • Site migration QA - catch discovery regressions after domain moves, CDN changes, or IdP upgrades
  • CI/CD pipelines - schedule conformance checks and alert on score drops

What it checks

  • Discovery document - served at /.well-known/openid-configuration with HTTP 200 and application/json Content-Type
  • JSON validity - the document body parses as a JSON object
  • Required metadata keys - issuer, authorization_endpoint, jwks_uri, response_types_supported (OIDC Discovery 1.0 section 3)
  • Issuer match - the declared issuer value matches the URL the document was fetched from (OIDC clients MUST reject mismatches); issuer must not contain query or fragment components
  • Endpoint URLs - every documented endpoint (authorization_endpoint, token_endpoint, userinfo_endpoint, jwks_uri, registration_endpoint, end_session_endpoint, revocation_endpoint, introspection_endpoint, pushed_authorization_request_endpoint, device_authorization_endpoint, and more) is a parseable https URL; off-issuer-origin endpoints are flagged as a warning (common on shared IdP platforms)
  • ID token signing algorithms - id_token_signing_alg_values_supported contains recognized JWS algorithms and does not include none (prohibited for ID tokens)
  • PKCE support - code_challenge_methods_supported advertises S256; plain is flagged per RFC 7636
  • Recommended keys - token_endpoint, id_token_signing_alg_values_supported, subject_types_supported presence; subject_types_supported values limited to public/pairwise

Endpoint URLs found inside the metadata are never fetched - only the discovery document on the provided issuer host is read.

Input

FieldTypeRequiredDefaultDescription
startUrlstringyes-Issuer URL of the OIDC provider (root domain, no path)
timeoutSecondsintegerno10Per-request timeout (3-30 seconds)

Example input

{
"issuer": "https://accounts.google.com",
"timeoutSeconds": 10
}

Output

A single dataset item with the full audit:

FieldTypeDescription
inputIssuerstringThe issuer URL provided as input
discoveryUrlstringThe /.well-known/openid-configuration URL that was fetched
finalUrlstringFinal URL after redirects
httpsbooleanWhether the discovery document was served over HTTPS
statusintegerFinal HTTP status code
documentFoundbooleanWhether a 200 discovery document was served
jsonValidbooleanWhether the document body is valid JSON
parseErrorstring | nullJSON parse error message, or null
issuerstring | nullDeclared issuer value in the metadata
issuerMatchesFinalUrlbooleanWhether the declared issuer matches the fetched URL
requiredKeysarrayRequired metadata keys present
missingRequiredKeysarrayRequired metadata keys missing
missingRecommendedKeysarrayRecommended metadata keys missing
metadataKeyCountintegerTotal metadata keys in the document
endpointsarrayPer-endpoint analysis (key, url, https, parseable, issuerHost, issues)
responseTypesarray | nullresponse_types_supported values
subjectTypesarray | nullsubject_types_supported values
signingAlgsarray | nullid_token_signing_alg_values_supported values
codeChallengeMethodsarray | nullcode_challenge_methods_supported values (PKCE)
tokenAuthMethodsarray | nulltoken_endpoint_auth_methods_supported values
scopesarray | nullscopes_supported values
grantTypesarray | nullgrant_types_supported values
pkceSupportedbooleanWhether PKCE code challenge methods are advertised
checksarrayPer-check analysis (name, status, note, weight, recommendation)
issuesarrayAggregated issue descriptions
scoreintegerOIDC discovery readiness score (0-100)
gradestringLetter grade (A+, A, B, C, D, E, F)
checkedAtstringISO 8601 timestamp
recommendationsarrayActionable recommendations

Example output (abridged)

{
"inputIssuer": "https://accounts.google.com",
"discoveryUrl": "https://accounts.google.com/.well-known/openid-configuration",
"documentFound": true,
"jsonValid": true,
"issuer": "https://accounts.google.com",
"issuerMatchesFinalUrl": true,
"missingRequiredKeys": [],
"signingAlgs": ["RS256"],
"codeChallengeMethods": ["S256", "plain"],
"pkceSupported": true,
"score": 92,
"grade": "A",
"checks": [
{
"name": "Issuer match",
"check": "issuer",
"status": "good",
"note": "issuer 'https://accounts.google.com' matches the discovery document URL.",
"weight": 20,
"recommendation": null
}
],
"recommendations": []
}

Security

  • Public HTTP/HTTPS only; rejects URL credentials, private IP literals (IPv4 and IPv6), private DNS resolutions, and revalidates redirects before following.
  • Fetches only the discovery document on the provided issuer host; endpoint URLs found inside the metadata are never fetched.
  • Bounded body read (2 MB cap); no login, no JavaScript execution, no cookies, no stored page content.

Pricing

Pay-per-event: one scored audit per run (~$0.015/run).

EventPrice
Actor start$0.005
Per issuer audited$0.01

FAQ

Does this fetch the JWKS or test the authorization endpoint? No. Only the discovery document is fetched. Endpoint URLs and jwks_uri are validated as metadata strings so the actor cannot be used to probe arbitrary URLs.

Why does issuer mismatch matter? OIDC Discovery 1.0 section 3 requires the issuer value to be identical to the issuer identifier used to construct the discovery URL. RFC 8414-conformant clients MUST reject metadata where they differ - a mismatch silently breaks client discovery.

Can I audit an OAuth 2.0 authorization server without OIDC? This actor audits the OIDC discovery document. OAuth AS metadata (/.well-known/oauth-authorization-server) overlaps heavily but is a separate RFC 8414 layout; only use this actor for OpenID Connect providers.

Local development

npm install
npm test # node --test suite (parsers, SSRF, scoring, live smoke)
npm run lint # node --check
python3 ../scripts/audit_actor.py . # portfolio security audit (run from actors/ dir)