OMCP OAuth Lab

PRIVACY

Metadata stays in this browser tab.

Validation is implemented in local JavaScript. The tool does not upload metadata, call the pasted endpoints, store input, or require an account.

What is processed

The browser parses the resource URL and two JSON documents only to generate the visible report. Clearing or closing the tab removes the working input.

Hosting data

Cloudflare processes ordinary request metadata needed to deliver static site files. The validator itself has no scan API, analytics call, or third-party script.

Do not paste client secrets

OAuth metadata documents should be public and should not contain client secrets or access tokens. If one appears in a URL or pasted document, rotate it.