Does your logout actually revoke anything?

Grade an OIDC issuer's logout and revocation metadata against RP-Initiated / Back-Channel / Front-Channel Logout 1.0 and RFC 7009 token revocation — every finding cited, results shareable by permalink. RP-Initiated Logout ends the browser session; it does not revoke tokens. This tool makes that distinction legible.

We resolve `/.well-known/openid-configuration` over HTTPS and read only public metadata. Nothing is stored unless a report is created.

logoutcheck

Does your logout actually revoke anything?

by IntegrAuth