SAML / OAuth Inspector
Overview
Capture and inspect SAMLRequest/SAMLResponse and OAuth/OIDC redirects when you click the extension
SAML / OAuth Inspector helps identity and security engineers debug single sign-on directly in the browser. When you click the extension icon, it shows the last captured SAML or OAuth/OIDC data from the page you are on. WHAT IT CAPTURES • SAMLRequest and SAMLResponse (HTTP-POST and URL/redirect style) • OAuth/OIDC redirect parameters: code, state, id_token, access_token, error, and related fields • Decoded SAML details: Issuer, NameID, conditions, audiences, and attributes • Decoded JWT claims from id_token / access_token when present in the browser WHY USE IT • Troubleshoot failed SSO logins • Verify claims and NameID format during federation setup • See whether a flow is SAML or OAuth/OIDC • Inspect authorization errors returned by the identity provider • Work locally without sending data to a third-party service HOW TO USE 1. Install and pin the extension 2. Start a SAML or OAuth/OIDC sign-in 3. When a message is captured, a badge appears (S = SAML, O = OAuth) 4. Click the extension icon to view the summary, attributes/claims, and raw payload 5. Copy or clear the capture as needed NOTES • Designed for IT admins, IAM engineers, and developers • Processing is local in your browser • Does not cryptographically validate SAML signatures or JWT signatures • Authorization code flows often only expose code and state in the browser; tokens may be redeemed server-side Built for real-world Entra ID, AD FS, Okta, and other federation debugging scenarios.
0 out of 5No ratings
Details
- Version1.1.0
- UpdatedAugust 7, 2026
- Offered byKevin.Scattergood
- Size9.54KiB
- LanguagesEnglish (United States)
- Developer
Email
Kevin.Scattergood@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes