Rectangle 27 0

google chrome extension How to remove the permission warning "Read and change all your data on the websites you visit"?


  • Communicate with cooperating websites

If your extension doesn't need to run on the website, but only needs to be able to send HTTP requests to your website (e.g. via an API), then you could add CORS headers to the website to allow the extension to make requests.

Since you are in full control of the website and the extension, you could use externally_connectable to enhance your website. This manifest key allows code on your website to initiate and maintain a communication channel between the website and your extension. Then you can implement the platform-independent parts (e.g. UI with HTML & CSS) in your website, delegate the Chrome-specific parts to the extension, and use the messaging API to communicate between the page and extension.

The warning that users receive will be less scary:

You could also use optional permissions to support new sites via content scripts. With this method, Chrome doesn't show any warnings upon installation. A disadvantage of this method is that your users have to approve another permission request before they can use your extension on your website.

Note
Rectangle 27 0

google chrome extension How to remove the permission warning "Read and change all your data on the websites you visit"?


  • Communicate with cooperating websites

If your extension doesn't need to run on the website, but only needs to be able to send HTTP requests to your website (e.g. via an API), then you could add CORS headers to the website to allow the extension to make requests.

Since you are in full control of the website and the extension, you could use externally_connectable to enhance your website. This manifest key allows code on your website to initiate and maintain a communication channel between the website and your extension. Then you can implement the platform-independent parts (e.g. UI with HTML & CSS) in your website, delegate the Chrome-specific parts to the extension, and use the messaging API to communicate between the page and extension.

The warning that users receive will be less scary:

You could also use optional permissions to support new sites via content scripts. With this method, Chrome doesn't show any warnings upon installation. A disadvantage of this method is that your users have to approve another permission request before they can use your extension on your website.

Note
Rectangle 27 0

google chrome extension How to remove the permission warning "Read and change all your data on the websites you visit"?


  • A "content_scripts" field with a "matches" entry that matches all hosts
  • A match pattern in the "permissions" field that matches all hosts

Domain names are the only way to specify a specific site. If you don't know the domain yet, then optional permissions are your best bet.

Don't miss that tabCapture permission also causes this warning.

Usually, it is a wildcard match pattern in permissions, e.g. http://*/*. If you have a browser action or page action, then you can use Active Tab permission to be able to access the page content without requesting permission to the specific site.

Note
Rectangle 27 0

google chrome extension How to remove the permission warning "Read and change all your data on the websites you visit"?


  • A "content_scripts" field with a "matches" entry that matches all hosts
  • A match pattern in the "permissions" field that matches all hosts

Sign up for our newsletter and get our top new questions delivered to your inbox (see an example).

Domain names are the only way to specify a specific site. If you don't know the domain yet, then optional permissions are your best bet.

Don't miss that tabCapture permission also causes this warning.

Usually, it is a wildcard match pattern in permissions, e.g. http://*/*. If you have a browser action or page action, then you can use Active Tab permission to be able to access the page content without requesting permission to the specific site.

Note