Auth Inspector (SAML & OIDC)

DevTools panel to inspect SAML Requests/Responses and OIDC tokens locally.

As of May 2026, Auth Inspector (SAML & OIDC) has 1,000 users and a 5.00/5 rating from 2 reviews in the Developer Tools category.

Usersno change0%
1.0K
1,000
Ratingno change0%
5.00
2 reviews
Reviewsno change0%
2
Version
1.0.0
Manifest V3

History

2 snapshots

Tracking since Apr 21, 2026.

1.0K1.0K988.4Apr 21, 2026May 31, 2026
View as table
DateUsersRatingReviewsVersion
Apr 21, 20261.0K5.0021.0.0
May 6, 20261.0K5.0021.0.0
Now1.0K5.0021.0.0

Permissions & access

Permissions
storage
Host access
None declared

Screenshots

Auth Inspector (SAML & OIDC) screenshot 1Auth Inspector (SAML & OIDC) screenshot 2Auth Inspector (SAML & OIDC) screenshot 3

About

Auth Inspector adds a dedicated panel to Chrome DevTools that captures and explains your authentication traffic in real time. It watches SAML (Redirect & POST bindings) and OIDC (authorize, token, userinfo, introspect, revoke, end_session, JWKS) so you can see exactly what’s being sent and received—without digging through raw network payloads.

Built for identity engineers, SREs, and developers who debug login flows across multiple IdPs and apps (Keycloak broker, Okta, Azure AD, Ping, custom IdPs, etc.).

What it does
- SAML made readable: Pretty-prints XML and shows a human-friendly summary (Issuer, Destination, InResponseTo, Status, Assertions, Subject, Conditions, Audience, AuthnContext, and Attributes).
- OIDC decoded: Parses /authorize params (scopes, PKCE, response mode/type) and decodes JWT header/payload for ID and access tokens (issuer, subject, aud, azp, nonce, acr, amr, auth_time, exp/iat, realm/client roles, groups, organization, locale, and other user attributes).
- Tabs for Parsed / Decoded / Raw: Start with a clean summary, switch to decoded details, and drop to raw when you need wire-level data.
- Safe by default: Raw bearer tokens and large secrets are redacted. Parsed/Decoded views show fields you need for debugging—but never the original token string.
- Fast filtering: Filter by protocol (SAML/OIDC), host, and free-text. Quick toggle to show only the current site.
- Export: One-click copy of the current session’s events (with sensitive fields still redacted).

How to use
1. Open Chrome DevTools (F12) → Auth Inspector tab.
2. Run your SAML/OIDC flow in the page.
3. Watch events appear as cards. Click Parsed, Decoded, or Raw tabs for detail.
4. Use host/text filters or pause to focus on what matters.
5. Copy what you need into tickets or notes—safely.

Permissions
- DevTools only. The extension runs inside the DevTools panel and reads the Network log for the inspected tab.
- No host permissions and no remote requests from the extension.
- Optional clipboard use for copy buttons.

Privacy
- No data collection. No telemetry. No cloud.
- All parsing and redaction happen locally in your browser.
- Exports happen only when you explicitly copy.

Technical

Version
1.0.0
Manifest
V3
Size
40.13KiB
Min Chrome
88
Languages
1
Featured
No

Metadata

ID
hlfgmkebaohkdiedbicinfghpppmkpgk
Developer ID
u34a2d324b98861cb3533dbff005d5c29
Developer Email
[email protected]
Created
Aug 14, 2025
Last Updated (Store)
Aug 14, 2025
Last Scraped
May 31, 2026
Website
Support URL

Similar extensions

Alternatives to Auth Inspector (SAML & OIDC), ranked by description similarity.

Data sourced from the Chrome Web Store · last verified May 31, 2026.