Effective July 20, 2026

Privacy Policy

Enterprise Authentication Flow Inspector is designed to analyze browser-visible authentication traffic locally in Chrome DevTools. It does not operate a developer-controlled collection service.

Data processing

While Chrome DevTools is open for the active inspected tab, the extension processes request and response information exposed by the Chrome DevTools APIs. This can include URLs, headers, cookies, bodies, SAML messages, OAuth/OIDC tokens, authentication challenges, timing and imported HAR data.

Processing is performed locally inside the extension for display, filtering, decoding and flow analysis.

Data collection and transmission

The extension does not transmit captured traffic, credentials, cookies, tokens, SAML messages, certificate data, imported files or assessment results to the developer or third parties.

The extension does not include analytics, advertising, tracking, telemetry or remote code.

User-controlled import and export

Users may explicitly import HAR or JSON files and export traffic or Markdown assessment reports. These actions are initiated by the user. Exported files are written through the browser's download behavior and are not uploaded by the extension.

Sanitized exports reduce sensitive values for collaboration. Full-diagnostic exports intentionally preserve evidence that may be needed to correlate server-side logs.

Sensitive data notice

Authentication traces can contain credentials, session cookies, bearer tokens, identity attributes, internal hostnames and correlation identifiers. Users are responsible for storing and sharing captured or exported data according to their organization's security requirements.

Remote code

All JavaScript, HTML, CSS, icons and processing logic required by the extension are packaged with it. The extension does not download or execute remote code.

Contact

Privacy questions and project issues can be submitted through GitHub Issues or by email to ksudhir@gmail.com.