1 item
Trace and inspect OAuth 2.0, SAML, and OIDC authentication flows in the browser. IAM Tracer is a developer and security engineer's companion for debugging authentication flows in the browser. It passively observes OAuth 2.0, OpenID Connect (OIDC), and SAML 2.0 traffic as it happens and presents a structured, real-time timeline in the DevTools panel — no proxy to configure, no certificates to install, no traffic modification. WHAT IT CAPTURES • OAuth 2.0 — authorization code grants, implicit token flows, PKCE parameters, state values, and error responses • OIDC — token endpoint calls, discovery document fetches (.well-known/openid-configuration), and logout flows (end_session_endpoint) • SAML 2.0 — SAMLRequest and SAMLResponse POST bindings, decoded XML assertions, subject NameID, attributes, and status codes • JWT decoding — id_token and access_token claims decoded inline (header + payload) HOW IT WORKS IAM Tracer hooks into browser navigation events and network request completions using standard Chrome extension APIs. SAML POST bodies are extracted from form submissions in the page DOM. All parsing happens locally in your browser. NO DATA LEAVES YOUR BROWSER All captured events are stored in chrome.storage.session — they exist only for the current browser session and are automatically cleared when you close the browser. Nothing is sent to any remote server. WHO IT'S FOR • Frontend and backend developers integrating OAuth / OIDC / SAML • Identity engineers debugging SSO flows • Security engineers auditing authentication protocol implementations • QA engineers testing authentication edge cases
Aug 28, 2026
rating_count is the Chrome Web Store ratings count, not a written-review count.
Media assets
Screenshots and videos on the listing.
Has promo video
Whether the listing includes at least one video.
Languages
Declared language locales.
Developer website
Listing exposes a developer website URL.
Contact email
Listing exposes a contact email.
Keyword in name
Case-insensitive substring match in the name.
Keyword in description
Case-insensitive substring match in the description.
Keyword occurrences in description
Count of case-insensitive occurrences in the description.
Category user-count percentile
Share of same-category extensions with fewer users (null if unknown).
These are transparent listing completeness / keyword signals, not a prediction of Chrome Web Store search ranking.