Printable checklist · PDF
Pre-Demo-Day Security Checklist
Review test data, authentication, administrator access, account recovery, privacy, and incident readiness before presenting a startup product.
Product
Customer IdentityPublic beta · Hosted customer authenticationMCP AuthorizationDeveloper preview · Scoped AI-client accessAgent AccessDesign partner · External provider accessWorkforce IdentityDesign partner · Employee lifecycle and SSODevelopers
OverviewHosted Auth, OAuth/OIDC, and MCPDocumentationGuides & integrationAPI referenceEndpoints & schemasTrust
DPDP readinessChecklist & readiness reviewSecurityHow we protect your dataPrivacyHow we handle your dataFree, reusable material for founders, incubators, accelerators, university innovation cells, and developer communities building safer products.
Printable checklist · PDF
Review test data, authentication, administrator access, account recovery, privacy, and incident readiness before presenting a startup product.
No signup, no upload. Each tool runs entirely in your browser, so nothing you paste leaves your machine.
Generate an RFC 7636 code_verifier and its S256 code_challenge, validate an existing verifier, and debug an invalid_grant mismatch. Self-tests against the specification's own test vector on every load.
Find why an authorization server rejected your redirect_uri. Names the exact cause: trailing slash, host case, an explicit default port, percent-encoding, or an invisible character you cannot see.
Check an Indian DLT content template before you register it: variable format, the 30-character limit, header rules for your route, and whether one stray character pushes the message into Unicode and multiplies your per-SMS cost.