WorkOS
For WorkOSSecurity Operations

Oidc Oauth Session Tokens

WorkOS · WorkOS

Enterprise Auth & Provisioning — WorkOS

Evaluates WorkOS' OIDC, OAuth & Session Tokens across 13 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's Enterprise Auth & Provisioning eval coverage.

About WorkOS

WorkOS provides enterprise-readiness APIs — SAML/OIDC SSO, Directory Sync (SCIM), MFA, Audit Logs, and an Admin Portal — that let applications add enterprise authentication and provisioning in days instead of months.

Employees

~100

Industry

Identity & Access

Headquarters

San Francisco, CA

Website

workos.com

Sample tests· showing 3 of 13

#InputExpected behaviorCheck
01

B2B app adds social login via provider=GoogleOAuth with redirect https://app.example.com/oauth/callback.

Use getAuthorizationUrl Provider=GoogleOAuth and allowlisted redirect; separate from enterprise org SAML flow.

Pass / FailSecurityhigh
02

Mobile app uses OIDC connection; must use PKCE per ASVS.

Document PKCE code_verifier/challenge on auth URL where WorkOS/OIDC connection supports; validate state and nonce on token exchange.

Pass / FailSecuritycritical
03

OIDC id_token presented to backend; nonce must match session.

Validate nonce, aud, iss per OIDC; reject expired id_token; map to profile via getProfileAndToken not manual JWT guess.

Pass / FailSecuritycritical

Unlock full benchmark

10 more test cases

Use this benchmark

How this eval is graded

Grade against expected.ideal_behavior and expected.rubric. Per-criterion pass requires mean >= 4.0 and no criterion below 3.

Rubric criteria

  • Workos
  • Security
  • Oidc Oauth Session Tokens

Recommended for

WorkOSWorkOS customers

Works with

Related evals

Frequently asked questions

What does the Oidc Oauth Session Tokens eval for WorkOS WorkOS test?+

Evaluates WorkOS' OIDC, OAuth & Session Tokens across 13 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's Enterprise Auth & Provisioning eval coverage.

How is the Oidc Oauth Session Tokens eval scored?+

The judge rubric: Grade against expected.ideal_behavior and expected.rubric. Per-criterion pass requires mean >= 4.0 and no criterion below 3.

How many test cases does this eval pack include?+

The Oidc Oauth Session Tokens pack for WorkOS WorkOS contains 13 test cases. 3 sample cases are shown free on this page; the full set runs in a Corsac workspace.

How do I run this eval?+

Sign up for Corsac, connect your model or agent endpoint, and run the Oidc Oauth Session Tokens pack as-is or after customizing thresholds. Results land in your workspace with per-case scores, and you can gate releases on the pack in CI via the REST API.

Run this eval in your workspace

Connect your data, configure thresholds, and review results with your team.