Auth Inspector (SAML & OIDC)
DevTools panel to inspect SAML Requests/Responses and OIDC tokens locally.
As of May 2026, Auth Inspector (SAML & OIDC) has 1,000 users and a 5.00/5 rating from 2 reviews in the Developer Tools category.
Usersno change0%
1.0K
1,000
Ratingno change0%
5.00
2 reviews
Reviewsno change0%
2
Version
1.0.0
Manifest V3
History
2 snapshotsTracking since Apr 21, 2026.
View as table
| Date | Users | Rating | Reviews | Version |
|---|---|---|---|---|
| Apr 21, 2026 | 1.0K | 5.00 | 2 | 1.0.0 |
| May 6, 2026 | 1.0K | 5.00 | 2 | 1.0.0 |
| Now | 1.0K | 5.00 | 2 | 1.0.0 |
Permissions & access
- Permissions
- storage
- Host access
- None declared
Screenshots
About
Auth Inspector adds a dedicated panel to Chrome DevTools that captures and explains your authentication traffic in real time. It watches SAML (Redirect & POST bindings) and OIDC (authorize, token, userinfo, introspect, revoke, end_session, JWKS) so you can see exactly what’s being sent and received—without digging through raw network payloads. Built for identity engineers, SREs, and developers who debug login flows across multiple IdPs and apps (Keycloak broker, Okta, Azure AD, Ping, custom IdPs, etc.). What it does - SAML made readable: Pretty-prints XML and shows a human-friendly summary (Issuer, Destination, InResponseTo, Status, Assertions, Subject, Conditions, Audience, AuthnContext, and Attributes). - OIDC decoded: Parses /authorize params (scopes, PKCE, response mode/type) and decodes JWT header/payload for ID and access tokens (issuer, subject, aud, azp, nonce, acr, amr, auth_time, exp/iat, realm/client roles, groups, organization, locale, and other user attributes). - Tabs for Parsed / Decoded / Raw: Start with a clean summary, switch to decoded details, and drop to raw when you need wire-level data. - Safe by default: Raw bearer tokens and large secrets are redacted. Parsed/Decoded views show fields you need for debugging—but never the original token string. - Fast filtering: Filter by protocol (SAML/OIDC), host, and free-text. Quick toggle to show only the current site. - Export: One-click copy of the current session’s events (with sensitive fields still redacted). How to use 1. Open Chrome DevTools (F12) → Auth Inspector tab. 2. Run your SAML/OIDC flow in the page. 3. Watch events appear as cards. Click Parsed, Decoded, or Raw tabs for detail. 4. Use host/text filters or pause to focus on what matters. 5. Copy what you need into tickets or notes—safely. Permissions - DevTools only. The extension runs inside the DevTools panel and reads the Network log for the inspected tab. - No host permissions and no remote requests from the extension. - Optional clipboard use for copy buttons. Privacy - No data collection. No telemetry. No cloud. - All parsing and redaction happen locally in your browser. - Exports happen only when you explicitly copy.
Technical
- Version
- 1.0.0
- Manifest
- V3
- Size
- 40.13KiB
- Min Chrome
- 88
- Languages
- 1
- Featured
- No
Metadata
- ID
- hlfgmkebaohkdiedbicinfghpppmkpgk
- Developer ID
- u34a2d324b98861cb3533dbff005d5c29
- Developer Email
- [email protected]
- Created
- Aug 14, 2025
- Last Updated (Store)
- Aug 14, 2025
- Last Scraped
- May 31, 2026
- Website
- —
- Support URL
- —
Similar extensions
Alternatives to Auth Inspector (SAML & OIDC), ranked by description similarity.
AppSec Inspector
Professional security inspection tool. Scan headers, detect secrets, audit auth - all locally, no data collection.
6
DevInspect - Inspector & Accessibility Checker
Frontend inspection tool with performance metrics, accessibility checks, and CSS selector extraction in real time.
11
★ 4.0
Analytics Auditor
Professional QA & Debugging tool for digital analytics. Real-time validation, smart alerts and multi-tab support.
40
★ 5.0
Bloomreach Engagement Inspector
Your friendly companion for monitoring and debugging Bloomreach analytics
44
★ 5.0
SigInspector - Statsig Event Log & Inspector
View and inspect Statsig event logs, gate evaluations, and experiment exposures directly in Chrome DevTools.
33
★ 5.0
Rest API Inspector
Inspect, filter and export REST API calls from any web app. View headers, payloads, timing and status. Export as HAR or JSON.
1.0K
★ 4.3
JWT Token Decode
With JWT Token Decode: automatically inspect JWTs from web requests & manually decode JSON tokens. Quick, easy online token decoder.
248
★ 5.0
Interceptor
Focused HTTP and API inspection inside Chrome DevTools, with intercept, forward, replay, and passive review for authorized testing.
2
★ 5.0
Data sourced from the Chrome Web Store · last verified May 31, 2026.