
Analyze and track OAuth 2.0, OIDC, and Microsoft Entra ID tokens from Burp, mitmproxy, or Chrome DevTools captures. Visualize token lifecycles, detect risky scopes, and export tokens for replay via an interactive dashboard.
Track OAuth 2.0, OIDC, and Microsoft Entra ID tokens across captured network traffic. Ingests Burp Suite XML exports, mitmproxy flow files, or live Chrome DevTools Protocol streams into a single SQLite database, then serves an interactive web dashboard for filtering tokens, walking exchanges, spotting risky scopes, exporting tokens for replay, and visualising token lifecycles as Mermaid graphs.
Status: TATS is stable for personal / engagement use. Optimised for the Microsoft 365 / Entra ecosystem (FOCI, BroCI/NAA, ESTSAUTH session cookies, entrascopes.com enrichment) but works against any standard-ish OAuth/OIDC traffic.
When you proxy a long Microsoft 365 or Azure session through Burp / mitmproxy the resulting capture is enormous and most tools either:
This tool extracts every observed access / refresh / id token, fingerprints them so it can correlate the same token across sources, decodes JWT claims, resolves Microsoft client / resource GUIDs against entrascopes.com, and renders the whole picture as a single dashboard — including a refresh-token chain view that follows FOCI cross-app exchanges and BroCI nested-app token issuance.
This project is intended primarily for research and education purposes but provides options such as command preview and token export features that can support some offensive tooling.
ingest — Burp Suite "Save items" XML exportmitm — mitmproxy .mitm flow file (HTTP and WebSocket frames)cdp — live attach to Chrome / Edge via DevTools Protocol
(real-time, captures TLS-decrypted HTTP and WebSocket frames
without a proxy CA; tracks every existing tab AND every tab opened
during the run via browser-level auto-attach)--append to merge into an existing database; tokens
are upserted (uses count + observed lifetime accumulate), events and
exchanges are appended, and the row's source_tag records every pass
that has seen the token.pip install mitmproxy).access_token, refresh_token, id_token) and
cookie-name heuristics drive the token type.ESTSAUTH, ESTSAUTHPERSISTENT,
ESTSAUTHLIGHT, SignInStateCookie) are explicitly recognised as
refresh-equivalent tokens (they would otherwise be misclassified by the
generic "auth" cookie hint).foci field
in token-endpoint responses.brk_client_id, brk_redirect_uri, and brk-<guid>:// redirect schemes
in the request body.--enrich flag fetches firstpartyscopes.json and
resources.json from https://entrascopes.com/ and resolves appid /
azp / aud GUIDs into friendly names with clickable links.upn / preferred_username /
unique_name / email / name, falling back to sub@iss or oid,
and surfacing app-only and unknown-identity buckets separately. Each
identity row shows a captures badge when the user appears in
≥2 source_tags (cross-capture survival, the headline --append
research signal) plus a first_seen → last_seen span and a
timeline button that highlights every token for that user on
the Sequence-diagram tab.appid / azp / form-body
client_id / brk_client_id / brk_nested_id) that's appeared in
exchanges, with FOCI / brokerable / broker / nested badges.aud claim observed, resolved to entrascopes
resource names where possible.tid values with token / user / app counts.scp / scope /
roles against a curated watchlist of high-impact Microsoft Graph
permissions and Azure resource scopes.(token, host) pair where
the token was used at a host that disagrees with its aud claim
(suggests credential leak or misuse).amr) — pwd / mfa / pop / smartcard
distribution.xms_cc=CP1),
proof-of-possession binding (cnf claim, with shared-kid detection
across audiences), step-up auth requirements (acrs), and the acr
authentication-context level. Each row is clickable and filters the
Tokens tab to only the tokens that carry that marker.⚠ priv badge — the
FOCI / BroCI-style privilege-expansion research signal.source_tag token counts so you can see how many
rows came from each ingest pass.roadtx describe,
roadtx auth, curl, Python requests, and PowerShell
Invoke-RestMethod.