OAuth URL Builder
Build OAuth 2.0 and OIDC authorization URLs
Grant Type
Note: Client Credentials and Device Code flows don't use the authorization endpoint - they go directly to the token endpoint.
Endpoints
Client Configuration
Scopes
Security Parameters
Use the PKCE Generator tool to create code_verifier and code_challenge
Optional Parameters
Authorization URL
Fill in the parameters and click "Build URL"
Learn More
About OAuth 2.0 Authorization
- •OAuth 2.0 authorization endpoint initiates the authentication flow
- •PKCE (
code_challenge) is required for public clients - •
stateparameter prevents CSRF attacks - •
nonceis required for OIDC to prevent replay attacks
OAuth URL in IAM
- •Authorization Code + PKCE – Recommended flow for all client types
- •State Validation – Verify state on callback to prevent CSRF
- •Silent Auth – Use prompt=none for session checks
- •Scopes – Request only the permissions your app needs