OAuth flows.
Configurable.
Engagement-ready.
ShroudCloud is purpose-built OAuth attack infrastructure for authorized red team operations. It is in private development now. Join the waitlist to be notified as access opens.
Join the waitlist.
Access is opening in stages to pentest firms, in-house red teams, and independent researchers. Leave your details and we will be in touch.
By submitting you agree to our Privacy Policy and Terms of Service.
FlawedToken is an open-source, deliberately vulnerable OAuth client with toggleable flaws, running in one Docker command. Use it to follow along with the walkthroughs on cctbp.com and build hands-on familiarity with real auth misconfigurations.
View on GitHub →Built by someone
who runs these engagements.
ShroudCloud was built by a CISSP practitioner who specializes in authentication and session security in modern web applications and identity providers. Most red team platforms are port-scanners with a GUI. This one is different.
The platform came out of frustration with the same problem on every auth engagement: the right OAuth components do not exist off the shelf. You end up building a custom IdP or RP from scratch every time, then throwing it away. ShroudCloud makes that setup reusable and engagement-ready.
Currently in private development. Join the waitlist to be notified as access opens.
Join the waitlist.
ShroudCloud is in private development. Access is opening in stages to pentest firms, in-house red teams, and independent researchers. Leave your details and we will be in touch as spots open.
By submitting you agree to our Privacy Policy and Terms of Service. © 2026 ShroudCloud. All rights reserved.