Check exported OpenID Connect discovery metadata, relying-party settings and a published JWKS against an issuer, redirect and key-rotation policy.
This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.
Run the checked-in example
npm run example # examples/clean, exits 0
node bin/oidc-configuration-checker.mjs --root examples/broken; echo $? # 1
node bin/oidc-configuration-checker.mjs --root examples/incomplete; echo $? # 2Read the result
The example key sets hold real public keys, generated once for this repository with their private halves discarded. No fixture anywhere in this package carries a private key, a client secret or any other credential.
Where this check stops
The four documents are consistent with one another: the issuer the client expects is the issuer the metadata declares, every registered redirect URI is in the policy allowlist as an exact string, every declared algorithm is one the policy permits, none appears nowhere, and the key set carries enough identified, permitted, inspectable keys for a rotation to be staged.
Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.
Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.