Skip to content

OAuth Playground

Build an OAuth 2.0 authorization code URL with a random state value, or a token exchange cURL command for the code you get back.

OAuth Playground

Output

Working…

Updated . Provided as is. Check the output before you rely on it in production.

How to use OAuth Playground

  1. 1

    Choose the step

    Pick Authorization URL to start the flow, or Token cURL to exchange the returned code.

  2. 2

    Fill in the endpoint and client

    Enter the provider's authorize or token endpoint and your client ID.

  3. 3

    Add the redirect or code

    Enter the redirect URL for the authorization step, or the code you received for the token step.

  4. 4

    Use the result

    Open the authorization URL to sign in, or run the token cURL. Store the generated state value and verify it on the callback.

Questions and answers

What is the state parameter for?
The state parameter protects the OAuth redirect against cross-site request forgery: generate a random value per request, store it, and reject callbacks whose state differs. This playground adds a random 24-character state to every authorization URL it builds.
Why must the redirect URI match exactly?
Providers compare the redirect_uri in the token request with the one from the authorization request; any difference fails the exchange.

Use it as an API

OAuth Playground is also callable as a free HTTP JSON API at https://aidevhub.io/api/oauth-playground/ — GET with query parameters or POST with a JSON body, no authentication, CORS enabled, fair use (abusive traffic is throttled at the edge; there is no per-request quota header). Responses return { ok, tool, result, meta }.

curl -s "https://aidevhub.io/api/oauth-playground/?endpoint=https%3A%2F%2Fauth.example.com%2Fauthorize&client_id=client_123&redirect_url=https%3A%2F%2Fapp.example.com%2Fcallback&mode=authorization-url"

Machine-readable contract: /api/tool/oauth-playground.json All API endpoints: /agents/ LLM site index: /llms.txt

For AI agents: how to call this tool

Machine-readable contract, endpoints and examples. Humans can ignore this section.

Best Path For Builders

Dedicated API endpoint

Deterministic outputs, machine-safe contracts, and production-ready examples.

Dedicated API

https://aidevhub.io/api/oauth-playground/

OpenAPI: https://aidevhub.io/api/openapi.yaml

GET /api/oauth-playground/ GET oauth-playground
POST /api/oauth-playground/ POST oauth-playground

Unified Runtime API

https://aidevhub.io/api/tools/run/?toolId=oauth-playground&a=https%3A%2F%2Fprovider.example.com%2Foauth%2Fauthorize

GET and POST are supported at /api/tools/run/ with identical validation and limits.

Limit: 30 req / 60s, input max 256 KB.