Terminology Index
Glossary
2953 terms
N6
O26
OAuth and OIDC Client Testing
OAuth and OIDC client testing verifies how an application initiates, binds, validates, stores, and ends authorization and authentication transactions with an authorized identity provider.
It covers redirect URIs, state, nonce where applicable, PKCE, issuer, audience, token exposure, scopes, logout, and safe local account mapping without testing an out-of-scope provider.
Introduced in: Web Application Penetration Testing
Examples
- Verify the client rejects a response for another transaction
- Check that issuer and subject drive account binding
No related terms linked yet.
