OAuth challenges collector

A place to catch requests a lab sends on your behalf, so you don't need your own server.

  1. Pick an unguessable token, e.g. sol-7f3a9c2e.
  2. Point the lab at https://collector.ipt-ctf.naef.lu/c/<token>.
  3. Watch what arrives at /view/<token>.

You can also host a document the lab will fetch (e.g. a JWKS): POST /host/<token> with the body, and it is served back at GET /host/<token> as JSON.

Captures and hosted documents are kept in memory only and disappear when the collector restarts. Anyone with your token can read them, so keep it to yourself.