Validate your Shared Signals & CAEP setup

Check an SSF transmitter’s .well-known/ssf-configuration against SSF 1.0, or decode a CAEP Security Event Token against RFC 8417 — every finding cited. SETs are decoded entirely in your browser and never uploaded; their signature is not verified (no key set is provided).

A URL is fetched server-side over HTTPS (SSRF-guarded); nothing is stored unless a report is created. Pasted JSON (starting with {) is validated in your browser.

ssfcheck

Validate your Shared Signals / CAEP setup

by IntegrAuth