Use in your browser

Check your OpenID configuration

Point either tool at a public issuer or .well-known URL: one for a check, two for a comparison. Both read only public documents, validate them against OIDC Discovery 1.0, RFC 8414, and RFC 9728, then parse the JWKS and probe the endpoints those documents reference.

Guest includes 50 lifetime app requests. Create a free account for 100 app requests each calendar month. One allowance across every app, in your browser and your agent.One allowance across every app, in your browser and your agent. Manage usage

Auth Discovery Check

Connect agent

Guest access is available after setup. Full account linking verified by PowMCP: Claude only.

Issuer check

Validate one issuer's discovery document, its JWKS, and the endpoints it references.

Usually finishes within 30 seconds.

An issuer origin, a full .well-known metadata URL, or a remote MCP server base URL

27 of 2048

Leave this unset to detect the family from the URL and the document itself

Clear this to list the referenced endpoints without checking whether they respond

Add Auth Discovery Check to your agent

Connect this app on its own. Add other PowMCP apps whenever your agent needs another job done.

Open the apps workspace A glowing app tile clicking into a slot on a dark agent device, with the PowMCP app box behind it

Connect directly

Choose your agent. Each button opens a new tab with only this app's endpoint ready to add.

Use another agent

Copy one ready-to-send prompt for any agent that supports remote MCP connections.

Manual endpoint, JSON, and terminal commands

For clients that require manual configuration, use this app-only endpoint, its JSON entry, or one terminal command.

ChatGPT: enable Developer mode in Settings → Security and login, then add this MCP endpoint from the Plugins page. Availability depends on your account and workspace policy. PowMCP has not yet verified ChatGPT account linking. OpenAI setup guide

https://powmcp.com/auth-discovery-check/mcp
{
  "mcpServers": {
    "powmcp-auth-discovery-check": {
      "type": "http",
      "url": "https://powmcp.com/auth-discovery-check/mcp"
    }
  }
}

Terminal agents add this app with one command:

Claude Code
claude mcp add --transport http powmcp-auth-discovery-check https://powmcp.com/auth-discovery-check/mcp
Codex CLI
codex mcp add powmcp-auth-discovery-check --url https://powmcp.com/auth-discovery-check/mcp
Gemini CLI
gemini mcp add --transport http powmcp-auth-discovery-check https://powmcp.com/auth-discovery-check/mcp

Manage, disable, or remove this connection in your agent's own MCP settings. PowMCP does not label an external connection as installed without confirmation from that client.

Proof

What it does

Check an OIDC/OAuth issuer's discovery documents in chat

Validate a public OIDC/OAuth issuer or remote MCP server's discovery-document family, the openid-configuration (OIDC Discovery 1.0), oauth-authorization-server (RFC 8414), and oauth-protected-resource (RFC 9728) well-known documents, against a pinned spec profile, then live-traverse the JWKS, endpoint reachability, and RFC 9728 authorization_servers[] it references, or compare two issuers under identical limits.

Category
Developer Tools

Request cost1 completed result

Guests get 50 lifetime app requests. Free accounts get 100 each calendar month.

Tools in this app

01

Auth Discovery Check

discovery_check

Validate one public OIDC/OAuth issuer, a full .well-known metadata URL, or a remote MCP server base URL. Auto-detects the discovery-document family (OIDC Discovery 1.0 openid-configuration, RFC 8414 authorization-server metadata, or RFC 9728 protected-resource metadata), validates required and recommended fields against a pinned dated spec profile, then live-traverses what the document references: parses the jwks_uri key set, probes reachability of the authorization/token/userinfo/registration endpoints, and for a protected-resource document cross-fetches each authorization_servers[] issuer's own metadata, and verifies the issuer-exact-match rule (a templated issuer such as Microsoft's /common {tenantid} is reported as a known non-fatal case, not a false failure). It fetches only PUBLIC metadata and the public URLs it references (never client secrets, private keys, tokens, or accounts) and never performs a live auth flow, issues or verifies tokens, does dynamic client registration, or judges that the server is secure. Each call live-fetches the metadata plus several referenced endpoints and can take up to 110 seconds.

02

Auth Discovery Compare

discovery_compare

Compare exactly two public OIDC/OAuth issuers or metadata URLs under identical bounded checks: two IdPs, or one issuer before and after a config change (staging vs production). Runs the same discovery_check on each (family auto-detection, required/recommended-field conformance, issuer-exact-match, JWKS parse, endpoint reachability, and RFC 9728 authorization_servers[] cross-fetch), then reports each document's pass state, a comparability note (the pair is comparable only when both resolve to the same document family), a difference table of conformance findings introduced or resolved between the two, and a ranking by pass state then fewer required-field failures, only when the measured findings support one. It never infers that one issuer is more secure or better configured than the other, and never performs a live auth flow. Use discovery_check for a single issuer. Each comparison fetches both issuers' documents and referenced endpoints and can take up to 110 seconds.

Auth Discovery Check questions

Scope and boundaries for Auth Discovery Check.

01What can I check with Auth Discovery Check?

Check https://accounts.google.com with endpoint probing enabled, or compare it with https://appleid.apple.com as two OpenID Connect issuers. A full .well-known URL can be supplied when the document family is already known.

02How should I read the result?

Start with familyState, metadataState, and pass, then read the most severe issues. OIDC and authorization-server profiles test required structure, issuer matching, JWKS, and probed endpoints; protected-resource metadata uses its own structural and reachability checks. Fix required-field, issuer, JWKS, and endpoint problems, and treat an undetected family, truncation, unprobed endpoints, or the absence of a credentialed flow as inconclusive.

03What are its limits?

Only public discovery metadata, key sets, and referenced endpoints are inspected. The app never runs an authentication flow, issues or verifies tokens, registers a client, handles secrets, or determines whether an issuer is secure; disabling probes leaves endpoint reachability untested.