Build & lint an OAuth client-assertion JWT

A private_key_jwt / client_secret_jwt client assertion authenticates your client to the token endpoint (RFC 7523). Validate a pasted assertion against the spec, or build a correct one in your browser.

Everything runs in your browser. In builder mode your private key or client secret is used to sign locally and is never uploaded or persisted. In validator mode the assertion is decoded and linted client-side; the signature is not verified (no key is provided). A saved permalink stores only the derived findings — never a key, secret, or claim value.

Load example:

clientassertcheck

Build & lint an OAuth client-assertion JWT (RFC 7523)

by IntegrAuth