๐Ÿ” SAML & OIDC inspector

Paste the federation artefact you are debugging and see what is weak about it, in plain English.

๐Ÿ”’ Decoded and checked in your browser. Nothing you paste, including assertions and certificates, leaves this page.

Why this matters

Federation is where single sign-on gets its strength and where it quietly breaks: an assertion valid for eight hours, a service provider that never checks the audience, a SHA-1 signature, a certificate nobody remembers until sign-ins fail on a Monday morning.

On the OAuth side, wildcard redirect URIs, implicit grant and the password grant are still common, and each turns a small mistake into stolen tokens.