Item logo image for Enterprise Authentication Flow Inspector

Enterprise Authentication Flow Inspector

5.0(

1 rating

)
ExtensionDeveloper Tools16 users
Item media 6 (screenshot) for Enterprise Authentication Flow Inspector
Item video thumbnail
Item media 2 (screenshot) for Enterprise Authentication Flow Inspector
Item media 3 (screenshot) for Enterprise Authentication Flow Inspector
Item media 4 (screenshot) for Enterprise Authentication Flow Inspector
Item media 5 (screenshot) for Enterprise Authentication Flow Inspector
Item media 6 (screenshot) for Enterprise Authentication Flow Inspector
Item video thumbnail
Item video thumbnail
Item media 2 (screenshot) for Enterprise Authentication Flow Inspector
Item media 3 (screenshot) for Enterprise Authentication Flow Inspector
Item media 4 (screenshot) for Enterprise Authentication Flow Inspector
Item media 5 (screenshot) for Enterprise Authentication Flow Inspector
Item media 6 (screenshot) for Enterprise Authentication Flow Inspector

Overview

Troubleshoot and correlate authentication flows across SAML, OAuth/OIDC, OAM/WebGate, Kerberos/WNA, NTLM, X.509, Okta, and Entra ID.

Enterprise Authentication Flow Inspector adds a focused authentication troubleshooting panel to Chrome DevTools. It helps identity, middleware, application, and support engineers understand what happened between the browser, WebGate, Oracle Access Manager, identity providers, service providers, authorization servers, and protected applications. ### One panel for the complete browser-visible authentication flow - Capture requests and responses from the active inspected tab. - Start or stop processing without clearing the existing trace. - Follow redirects across hosts while preserving host-specific URL colors. - Receive prioritized next actions tied to the exact browser-visible evidence when a flow fails or requires review. - See HTTP method, status meaning, duration, response size, and slow-request emphasis. - Search request and response content and filter SAML, OAM/WebGate, or static-resource traffic. - Import browser HAR files or panel JSON exports for offline analysis. - Export captured sessions as JSON for repeatable troubleshooting. - Export sanitized or full-diagnostic Markdown assessment reports with evidence, prioritized next actions, timelines, correlation keys, and protocol-specific log guidance. ### Oracle OAM and WebGate - Identify OAM, WebGate, and FED traffic using URLs, headers, bodies, and cookies. - Recognize `/oam/server`, `/fed/sp`, `/fed/idp`, `obrar.cgi`, `obreq.cgi`, `obrareq.cgi`, and credential-collection endpoints. - Highlight `OAM_ID`, `OAMAuthnCookie`, `ObSSOCookie`, `ORA_OSFS_SESSION`, and related authentication artifacts. - Correlate the browser-visible OAM/WebGate flow in Flow Analysis, with expandable OAM Details for request IDs, cookie transitions, redirect loops, failures, and the final application return. - Switch between a request-focused Traffic Inspector and a full-width Flow Analysis workspace for correlated session assessment. - Flag ECID and RID values on failing requests when Oracle correlation headers are visible, with guidance to use the ECID for further OAM, WebGate, OHS, WebLogic, identity-domain, and server-log troubleshooting. ### SAML federation - Detect SAMLRequest and SAMLResponse values in URLs, forms, bodies, and redirect headers. - Decode HTTP-POST and HTTP-Redirect binding messages when browser support permits. - Format and color decoded SAML XML for faster inspection. - Summarize issuer, destination, bindings, NameID policy, conditions, audience, subject, session, attributes, status, signatures, and assertion details. - Extract embedded X.509 certificate subject, issuer, serial number, validity dates, and thumbprints. ### OAuth and OpenID Connect - Extract OAuth/OIDC parameters and Bearer tokens from URLs, fragments, headers, forms, and JSON bodies. - Decode JWT headers and claims, including issuer, subject, audience, scopes, timestamps, and token identifiers. - Highlight active, expiring, expired, and not-yet-valid token states. - Correlate OIDC authorization, callback, token, UserInfo, discovery, and JWKS traffic using state when available. - Check browser-visible state, nonce, PKCE, audience, issuer, and token lifetime signals. - Clearly distinguish decoded token content from cryptographic signature validation. ### Okta and Microsoft Entra ID - Recognize Okta and Microsoft Entra ID using confidence-based combinations of official authority domains, provider endpoints, headers, issuer metadata, cookies, and error formats. - Extract Okta organization, authorization-server ID, provider errors, and `X-Okta-Request-Id` when browser-visible. - Extract Microsoft Entra tenant information, `AADSTS` errors, trace ID, correlation ID, and provider request ID when browser-visible. - Direct troubleshooting toward the Okta System Log or Microsoft Entra sign-in logs using the captured provider correlation evidence. ### Windows Native Authentication and X.509 - Identify browser-visible `WWW-Authenticate`, `Authorization`, and `Proxy-Authenticate` challenges. - Recognize Negotiate/SPNEGO, Kerberos, and NTLM schemes. - Highlight NTLM prominently when a flow falls back from expected Kerberos/WNA behavior. - Tag `/oam/CredCollectServlet/WNA` and `/oam/CredCollectServlet/X509` requests. - Display forwarded client-certificate headers and parse certificate material when available. - Correlate the protected-resource request, WNA challenge, browser response, protocol selection, repeated 401s, final authorization, and session-cookie outcome in Flow Analysis with expandable WNA Details. ### Privacy by design All analysis runs locally inside the extension. Captured traffic, cookies, tokens, SAML messages, authentication headers, and imported HAR data are not sent to the developer or to third parties. Users remain responsible for protecting exported traces because authentication data can be sensitive. ### Important scope The extension analyzes traffic visible to Chrome DevTools. Server-to-server exchanges, domain-controller traffic, Kerberos ticket caches, private signing keys, and backend logs are outside that browser-visible scope. JWT and certificate information is decoded and summarized; cryptographic trust validation is not performed. GETTING STARTED AND DOCUMENTATION Step-by-step guide: https://ksudhir.github.io/oracle-sso-devtools/getting-started/ Reference documentation: https://ksudhir.github.io/oracle-sso-devtools/docs/ Source code and issue tracking: https://github.com/ksudhir/oracle-sso-devtools Open source: https://github.com/ksudhir/oracle-sso-devtools Created by Sudhir Kulkarni

Details

  • Version
    2.0.0
  • Updated
    July 27, 2026
  • Offered by
    sudhir.kulkarni
  • Size
    111KiB
  • Languages
    English (United States)
  • Developer
    Email
    ksudhir@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, visit the developer's support site

Google apps