Is your Dynamic Client Registration an open-registration risk?

Grade an OAuth/OIDC authorization server's advertised Dynamic Client Registration (RFC 7591) exposure from its published discovery metadata — every finding cited, results shareable by permalink. This is a static, metadata-only check: it never registers a test client or POSTs to the registration endpoint. It grades "DCR is exposed; here's what to verify" — never "your DCR is open."

We resolve `/.well-known/openid-configuration` and/or `/.well-known/oauth-authorization-server` over HTTPS and read only public metadata. We never POST to registration_endpoint. Nothing is stored unless a report is created.

dcrcheck

Is your Dynamic Client Registration an open-registration risk?

by IntegrAuth