SSO Tracer
Overview
Trace and decode OAuth 2.0, OIDC and SAML 2.0 sign-in flows in a DevTools panel. Local only, nothing leaves the browser.
SSO Tracer is a DevTools panel for debugging single sign-on. It watches OAuth 2.0, OIDC and SAML 2.0 traffic as you authenticate and shows you the decoded flow — not a wall of raw network rows. WHO IT IS FOR Identity engineers, backend developers and security testers who have to answer "why did this login fail?" against a real deployment: an IdP on one domain, an SP on another, and a handshake between them that nobody can see. Chrome's Network tab shows you base64 and query strings. This shows you the flow. WHAT IT CAPTURES • OAuth 2.0 — authorization requests (including PKCE), code and implicit-token callbacks, token exchanges, and RFC 6749 error responses • OIDC — ID tokens with every claim labelled and expiry computed, discovery documents, end-session/logout • SAML 2.0 — AuthnRequest and Response over both the POST and HTTP-Redirect bindings, assertions, attribute statements, conditions and status codes • Token introspection — RFC 7662 requests and their active/scope/exp responses WHO IT IS FOR Identity engineers, backend developers and security testers who have to answer "why did this login fail?" against a real deployment: an IdP on one domain, an SP on another, and a handshake between them that nobody can see. Chrome's Network tab shows you base64 and query strings. This shows you the flow. WHAT IT CAPTURES • OAuth 2.0 — authorization requests (including PKCE), code and implicit-tanges, and RFC 6749 error responses request, code callback and token exchange are linked by the state parameter, so one click surfaces the whole chain instead of you scrolling a network log looking for the other half. • It finds tokens other tools miss. Most tools look for a URL ending in /token returning {access_token, id_token}. Real deployments do not cooperate. SSO Tracer scans JSON response bodies for JWT-shaped values under any key name at any URL, so a custom endpoint answering {"jwt": "eyJ..."} is picked up like any other token response. • Manual decoder — paste a JWT, an OAuth redirect URL, or a SAML message in any binding (raw XML, POST base64, or Redirect deflate) and read it decoded. No captured traffic needed. • Expiry and signature metadata at a glance — alg, kid, and whether the token is valid, expiring or already expired. PRIVACY Everything stays in the browser. The extension makes no network requests of its own: no fetch, no XMLHttpRequest, no WebSocket, no analytics, no account, no backend. Captured events live in memory-backed session storage and are gone when you close the browser. Exports are redacted by default — tokens, authorization codes, assertions and PII claims are replaced before the file is written, and turning that off requires confirming a dialog that spells out what the file will contain. HOW TO USE IT 1. Open DevTools (F12) and select the "SSO Tracer" tab. 2. Open it BEFORE you sign in — request and response bodies are only readan. 3. Perform the login. Events appear live; click one to inspect it.
0 out of 5No ratings
Details
- Version1.0.0
- UpdatedOctober 3, 2026
- Offered byomermertkaya
- Size86.91KiB
- LanguagesEnglish
- Developer
Email
omermertkaya@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
SSO Tracer has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
SSO Tracer handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, visit the developer's support site