SSO Tracer — Privacy Policy

Last updated: 1 October 2026

SSO Tracer is a Chrome extension that decodes OAuth 2.0, OIDC and SAML 2.0 sign-in traffic inside your own browser. This policy describes exactly what it touches and where that data goes.

The short version

Nothing leaves your browser. SSO Tracer has no backend, no analytics, no telemetry and no account. It never transmits anything anywhere. The only data that ever leaves the extension is a file you explicitly ask it to export, written to your own disk.

What the extension reads

To show you an authentication flow, SSO Tracer observes the browser traffic that carries that flow:

DataWhere it comes fromWhy
Request URLs, methods, status codeswebRequest, webNavigationTo detect authorization requests, callbacks, token endpoints and discovery documents
SAMLRequest / SAMLResponse form fieldsThe submitted form, read by the content scriptThe only place a SAML POST-binding message is readable before it is sent
Request and response bodies of auth-related requestsChrome DevTools network API, only while the SSO Tracer DevTools panel is openToken endpoints return access_token / id_token in the response body; nothing else can read it

Captured material can include authorization codes, access tokens, ID tokens, refresh tokens, SAML assertions, and the identity claims inside them (such as your email address, name or user ID). That is the point of the tool: these are the values you are trying to debug.

Where it is stored

Captured events are held in chrome.storage.session, which is held in memory and discarded when you close the browser. They are not written to storage.local, storage.sync, disk, IndexedDB, cookies, or anywhere else. The store is capped at the 500 most recent events, and “Clear” in the panel or popup empties it immediately.

Where it is not sent

The extension makes no network requests of its own. There is no fetch, XMLHttpRequest, WebSocket or sendBeacon call anywhere in its code, and its Content Security Policy (script-src 'self') blocks loading or executing remotely hosted code. The extension ships uncompiled and unminified, so what is published is what runs.

Export

The “Export JSON” and “Copy Flow” actions write a trace to a file you choose, or to your clipboard. Redact is enabled by default: tokens, authorization codes, SAML assertions, sensitive request headers and PII claims are replaced with [REDACTED] / [REDACTED-PII] before anything is written. Turning redaction off requires confirming a dialog that lists what the unredacted file will contain. Once exported, the file is yours — handle it like any other file containing credentials.

Permissions, and why each one exists

Data sold or shared

None. No data is sold, shared, or transferred to any third party, and none is used for anything other than showing it to you in the DevTools panel. This is consistent with the Chrome Web Store Limited Use requirements.

Children

SSO Tracer is a developer tool and is not directed at children.

Changes

Material changes to this policy will be published on this page and reflected in the Chrome Web Store listing.

Contact

Ömer Mert Kaya — omermertkaya@gmail.com