Don't paste the token.
Compare the contract.
Load an OpenAPI JSON document locally, name the operations this client actually calls, and paste scope names—not a token. The tool compares only declared OAuth/OpenID requirements and surfaces missing declarations, missing grant names and possible excess for human review.
Local OpenAPI scope comparer
| Operation | Declared alternatives | Best comparison | Status |
|---|---|---|---|
| No OpenAPI document loaded. | |||
Contract warnings
The paid pack sends selected operation labels and scope names to this service to render Markdown; it never receives the OpenAPI file or any token. Redact labels first if they expose internal design.
Authorization boundary: this tool sees declarations, not enforcement. It cannot verify token signature, issuer, audience, subject, resource, expiration, consent, downstream IAM permissions or actual server behavior. Never paste a token or secret. Treat missing or incorrect OpenAPI security metadata as unassessable, not safe.
$11 Scope Review Pack
Generate a Markdown operation-to-scope workpaper with alternatives, missing/excess candidates, specification checks, server-rejection tests and an owner decision record. The submitted scenario contains labels and scope names only—not the source file or token.
- Operation-level OAuth/OpenID scope alternatives
- Missing-grant and possible-excess review candidates
- Spec version, provider documentation and enforcement tests
- Keep, narrow, split-token, fix-spec or escalate decision record
Authorization standards and platform substitutes
PMF preflight 66/100 · 21 days + 150 qualified visits + paid evidence