Get a server of your own

Create a sandbox and you get your own authorization server URL to configure in your IdP. No email address, no password — a recovery URL you save, or a passkey.

What it's for

The request log
Everything a client sends, verbatim and unredacted — which is why a log is only ever visible to the sandbox that owns the server.
The check trace
Every validation step with the expected and received values side by side. Evaluation continues past a failure, so a request that's wrong in three ways tells you all three at once; the client still gets one normal OAuth error.
The toggles
Flip the server's policy and watch which clients break. Chiefly: whether a private_key_jwt assertion's aud has to be the issuer identifier or the token endpoint URL — the specs disagree, so clients do too.