⚯ ENTRA / AZURE TOKEN & SCOPE AUDIT
// ENTRA / AZURE TOKEN & SCOPE ANALYZER

Entra / Azure Token & Scope Analyzer

Paste an Azure/Entra access token (JWT), an az account get-access-token JSON, decoded claims JSON, a Microsoft Graph grants export, or a plain scope list. The tool decodes the claims (no signature check), classifies delegated scp vs app-only roles permissions against a Graph abuse KB, flags escalation to Global Administrator, directory roles baked into wids, and public/FOCI clients — with Windows + Linux operator commands, remediation, and a ↓ EDGES export for the Attack Path Chainer. Analyzed locally — nothing leaves your browser.