Item logo image for SSO Tracer

SSO Tracer

ExtensionDeveloper Tools1 user
Item media 1 (screenshot) for SSO Tracer

Overview

Trace and decode OAuth 2.0, OIDC and SAML 2.0 sign-in flows in a DevTools panel. Local only, nothing leaves the browser.

SSO Tracer is a DevTools panel for debugging single sign-on. It watches OAuth 2.0, OIDC and SAML 2.0 traffic as you authenticate and shows you the decoded flow — not a wall of raw network rows. WHO IT IS FOR Identity engineers, backend developers and security testers who have to answer "why did this login fail?" against a real deployment: an IdP on one domain, an SP on another, and a handshake between them that nobody can see. Chrome's Network tab shows you base64 and query strings. This shows you the flow. WHAT IT CAPTURES • OAuth 2.0 — authorization requests (including PKCE), code and implicit-token callbacks, token exchanges, and RFC 6749 error responses • OIDC — ID tokens with every claim labelled and expiry computed, discovery documents, end-session/logout • SAML 2.0 — AuthnRequest and Response over both the POST and HTTP-Redirect bindings, assertions, attribute statements, conditions and status codes • Token introspection — RFC 7662 requests and their active/scope/exp responses WHO IT IS FOR Identity engineers, backend developers and security testers who have to answer "why did this login fail?" against a real deployment: an IdP on one domain, an SP on another, and a handshake between them that nobody can see. Chrome's Network tab shows you base64 and query strings. This shows you the flow. WHAT IT CAPTURES • OAuth 2.0 — authorization requests (including PKCE), code and implicit-tanges, and RFC 6749 error responses request, code callback and token exchange are linked by the state parameter, so one click surfaces the whole chain instead of you scrolling a network log looking for the other half. • It finds tokens other tools miss. Most tools look for a URL ending in /token returning {access_token, id_token}. Real deployments do not cooperate. SSO Tracer scans JSON response bodies for JWT-shaped values under any key name at any URL, so a custom endpoint answering {"jwt": "eyJ..."} is picked up like any other token response. • Manual decoder — paste a JWT, an OAuth redirect URL, or a SAML message in any binding (raw XML, POST base64, or Redirect deflate) and read it decoded. No captured traffic needed. • Expiry and signature metadata at a glance — alg, kid, and whether the token is valid, expiring or already expired. PRIVACY Everything stays in the browser. The extension makes no network requests of its own: no fetch, no XMLHttpRequest, no WebSocket, no analytics, no account, no backend. Captured events live in memory-backed session storage and are gone when you close the browser. Exports are redacted by default — tokens, authorization codes, assertions and PII claims are replaced before the file is written, and turning that off requires confirming a dialog that spells out what the file will contain. HOW TO USE IT 1. Open DevTools (F12) and select the "SSO Tracer" tab. 2. Open it BEFORE you sign in — request and response bodies are only readan. 3. Perform the login. Events appear live; click one to inspect it.

Details

  • Version
    1.0.0
  • Updated
    October 3, 2026
  • Offered by
    omermertkaya
  • Size
    86.91KiB
  • Languages
    English
  • Developer
    Email
    omermertkaya@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization

SSO Tracer has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.

SSO Tracer handles the following:

Personally identifiable information
Authentication information
Web history
User activity
Website content

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

For help with questions, suggestions, or problems, visit the developer's support site

Google apps