Test your MCP server's compliance with RFC 9728, RFC 8414, RFC 7591, OAuth 2.1, and MCP 2025-11-25
Supports MCP spec version 2025-11-25 and previous versions
Bypass client registration
Bypass OAuth 2.1 authorization flow, PKCE, and token validation tests
Enable browser-based user authentication with PKCE (S256 for MCP 2025-11-25)
Priority #1: Use existing client credentials (bypasses Client ID Metadata and DCR)
Priority #2: Use HTTPS URL as client_id (falls back to DCR if unavailable)
Enable authenticated HTTP connections to non-localhost MCP servers (localhost always allowed - HTTPS recommended for production)
Capture and display request/response data for debugging
Running compliance tests... This may take up to 30 seconds.
Summary of whether each section provides sufficient information for a compliant client to complete OAuth authentication.