OAuth State/Nonce Debugger
Generate, parse, and validate OAuth state and nonce parameters
State Configuration
Generated State
Click Generate to create a state value
Generated Nonce
Click Generate to create a nonce value
Learn More
About State & Nonce
- •
stateprevents CSRF attacks in OAuth flows - •
nonceprevents replay attacks in OIDC id_tokens - •Both should be cryptographically random and stored securely
- •State can optionally encode additional data (return URL, tenant ID)
State/Nonce in IAM
- •CSRF Protection – Bind auth request to session
- •Replay Prevention – Ensure id_token freshness
- •Deep Linking – Return user to original page
- •Multi-tenant – Pass tenant context through flow