Watch what your Cross App Access client actually does
A Resource Authorization Server that records every request a client makes to it — headers, body, both JWTs decoded — and shows the outcome of every validation check, not just the first one that failed.
Get a server of your own
Create a sandbox and you get your own authorization server URL to configure in your IdP. No email address, no password — a recovery URL you save, or a passkey.
What it's for
- The request log
- Everything a client sends, verbatim and unredacted — which is why a log is only ever visible to the sandbox that owns the server.
- The check trace
- Every validation step with the expected and received values side by side. Evaluation continues past a failure, so a request that's wrong in three ways tells you all three at once; the client still gets one normal OAuth error.
- The toggles
-
Flip the server's policy and watch which clients break. Chiefly: whether a
private_key_jwtassertion'saudhas to be the issuer identifier or the token endpoint URL — the specs disagree, so clients do too.