OAuth & Identity Labs
Authorization Code Flow Trainer
Set up and troubleshoot a full OAuth 2.0 flow.
Client Credentials Flow Lab
Learn service-to-service authentication.
PKCE Challenge
Secure mobile & SPA authentication with PKCE.
JWT Playground
Generate, decode, and verify JWTs.
SAML vs OAuth Showdown
Compare and contrast identity federation protocols.
Implicit Flow Lab
Explore the legacy flow and its security risks.
OAuth Token Exchange
Simulate token handling between different parties.
OAuth Threat Modeling
Analyze and mitigate common OAuth vulnerabilities.
OAuth with FIDO2/WebAuthn
Combine OAuth with passwordless authentication.
OAuth Consent & Scopes Lab
Understand scopes, permissions, and user consent flows.