Skip to main content

OIDC Authorization URL & PKCE Generator

Build /authorize URLs with S256 PKCE — Okta, Auth0, Entra ID, Keycloak, any OIDC IdP

Provider & client

PKCE values

Send this as code_verifier in your token request.

Authorization URL

https://your-org.okta.com/oauth2/default/v1/authorize?response_type=code&client_id=0oa1abc2def3ghi4jkl5&redirect_uri=http%3A%2F%2Flocalhost%3A5173%2Fcallback&scope=openid+profile+email

Then exchange the code at https://your-org.okta.com/oauth2/default/v1/token:

grant_type=authorization_code&client_id=0oa1abc2def3ghi4jkl5&code_verifier=qsfCl-OcxmWzQiKqsHx-WNtfNaCw4Vw08ma4XGxmIrsiiJJm7lApoJJwKR1nI8YFRzPW-cjhxWFPbij27rltNQ&redirect_uri=http%3A%2F%2Flocalhost%3A5173%2Fcallback

Need this on-premise or behind your firewall?

We ship a self-hosted enterprise edition of our identity tools (SAML, OIDC, JWT) — air-gapped, auditable, no data leaves your network. Contact us for details.

Get the on-prem version

About the OIDC URL Builder

Almost every OAuth 2.0 / OpenID Connect bug in a new app traces back to the authorization request: a missing scope, a wrong redirect_uri, or a PKCE verifier that does not match the challenge sent in the authorize URL. Assembling that URL by hand invites typos in exactly the parameters the identity provider compares strictly.

This builder assembles the full /authorize URL with state, nonce, and an S256 PKCE pair generated with your browser’s secure random generator. The code_verifier stays on your machine and is never transmitted - copy it into your token request when the authorization code comes back. Works with Okta, Auth0, Microsoft Entra ID, Keycloak, Google, and any standards-compliant OIDC provider.

How to use

  1. Enter your issuer URL (e.g. https://your-org.okta.com/oauth2/default) and client ID.
  2. Set the redirect URI and scopes exactly as registered with your provider.
  3. Leave PKCE on for SPAs and mobile apps - the S256 challenge is computed via Web Crypto.
  4. Copy the authorization URL, complete the login, then exchange the code with the shown token request and code_verifier.

Frequently Asked Questions

What is PKCE and when do I need it? ▾

PKCE (Proof Key for Code Exchange) binds the authorization code to a verifier secret so intercepted codes cannot be exchanged. It is required for public clients (SPAs, mobile apps) and recommended for all OAuth 2.1 flows. This builder generates the verifier and computes the S256 code challenge with Web Crypto.

Does this work with Okta, Auth0, Entra ID, and Keycloak? ▾

Yes. The /authorize endpoint parameters are standardized by OpenID Connect, so the generated URL works with any compliant provider - fill in the authorization endpoint URL from your provider app settings.

Are the state, nonce, and verifier safe to generate here? ▾

They are generated with your browser crypto.getRandomValues and never leave the page - nothing is transmitted or logged. For production apps, generate them in your own code; use this tool to understand and debug the flow.

What is PKCE and do I need it? ▾

PKCE (proof of key for code exchange) binds the authorization request to a verifier only your app knows, preventing intercepted authorization codes from being used. It is required for public clients (SPAs, mobile) and recommended everywhere — this builder generates the challenge pair for you.

Which parameters are required in an OIDC authorization URL? ▾

response_type, client_id, and redirect_uri at minimum; state (CSRF protection) and nonce (replay protection for ID tokens) should always be included. scope=openid is what makes it OIDC rather than plain OAuth2.

Why must redirect_uri match exactly? ▾

Identity providers compare it byte-for-byte against the registered value — a trailing slash or http/https difference is rejected. Copy the exact registered URI when building requests.