Skip to content
Owais Khan Software Reviews

Manifest V3 Permission Checker

Paste a Chrome extension manifest.json to see the exact warnings users will be asked to accept, find every Manifest V3 error before the Web Store does, and convert a V2 manifest to V3.

Everything runs locally: your manifest never leaves your browser.

Check a Chrome extension manifest

Add “PR Helper”?

It can:

  • Read and change your data on all github.com sites and gitlab.com
  • Read your browsing history
  • Read and change your bookmarks

The install dialog’s warning list, worded and merged the way Chrome does it.

Problems

  • error permissions: "https://api.github.com/*" is a host pattern: in Manifest V3 it belongs in host_permissions, not permissions.
  • error optional_permissions: "debugger" cannot be optional; Chrome rejects it in optional_permissions. Move it to permissions.
  • info permissions: "tabs" is only needed to read url, title and favIconUrl of tabs you have no host access to. If you act on the tab the user clicked, activeTab does it with no install warning.

Permissions

PermissionWarning on its ownIn this manifest
storage—No warning
tabsRead your browsing historyShown
bookmarksRead and change your bookmarksShown

Auto-fixed Manifest V3

  • 1 host pattern moved from permissions to host_permissions

Reading the example

The example asks for https://*.github.com/* twice — once in host_permissions, once as a content script match — and for gitlab.com, so Chrome shows one host warning: “Read and change your data on all github.com sites and gitlab.com”. tabs adds “Read your browsing history”. https://api.github.com/* is in the wrong array: in Manifest V3 a host pattern in permissions grants nothing, so the auto-fix moves it to host_permissions. And debugger cannot be optional at all.

A Chrome extension permissions auditor that matches Chrome

Most lists of extension permissions give each one a warning in isolation, which is not what users see. Chrome merges warnings: all-sites access absorbs tabs, webNavigation and declarativeNetRequest; history absorbs tabs and topSites; hosts that differ only by country domain are listed once. This Chrome extension permissions auditor applies the same rules in the same order, so the list above is the list in the install dialog — and the one users see again, with the extension disabled, when an update adds a warning.

Chrome extension Manifest V3 validator

As a Chrome extension Manifest V3 validator it checks what the Web Store rejects or delays: V2 keys left in a V3 manifest, host patterns in the wrong array, webRequestBlocking, remote code or 'unsafe-eval' in the content security policy, invalid match patterns, a bad version string, and permissions that cannot be optional.

Convert Manifest V2 to V3

To convert Manifest V2 to V3, paste the V2 file and copy the auto-fixed version: browser_action becomes action, background scripts become a service worker, host patterns move to host_permissions, and web_accessible_resources and the CSP take their object form. The manifest is only part of a migration, so anything that needs code changes is listed under the output instead of being silently dropped.

Where these rules come from

The warning text and the rules for merging warnings are taken from Chromium’s source — its permission message rules and string resources — and checked against Chromium’s own unit tests, rather than from the permissions documentation, which is out of date in places. The Manifest V3 changes follow Chrome’s migration guide.

Frequently asked questions

What host permissions changed between Manifest V2 and Manifest V3?
In Manifest V2, match patterns such as https://example.com/* sat in the permissions array next to API names. Manifest V3 moves them to their own host_permissions key, and optional ones to optional_host_permissions. A match pattern left in permissions in a V3 manifest does not grant anything — Chrome reports it as an unknown permission. Content script matches still live under content_scripts and still count toward the install warning.
How do I fix the broad host permissions warning in Chrome Web Store submission?
Patterns that match every site — <all_urls>, *://*/*, https://*/* — are broad host access, and the Web Store sends extensions that request them to in-depth review. Chrome itself treats a wildcard over a whole domain ending, such as *.com, the same way: it shows the all-websites warning. If your extension acts on the page the user clicks, activeTab grants that access with no install warning at all. Otherwise list the specific sites you need, or move broad patterns to optional_host_permissions and request them with chrome.permissions.request() when the feature is first used.
Which background script settings are deprecated in Manifest V3?
background.scripts, background.page and background.persistent are Manifest V2 only. Chrome’s Manifest V3 takes one background.service_worker file, optionally with "type": "module". The worker has no DOM and stops when idle, so DOM work moves to an offscreen document and state moves to chrome.storage. The converter above rewrites the key and lists the code changes it cannot make for you.
How do optional permissions work in Manifest V3?
Permissions in optional_permissions and hosts in optional_host_permissions show no warning at install. Your extension asks for them at runtime with chrome.permissions.request(), which must be called from a user gesture, and Chrome shows the warning then. Some permissions cannot be optional — debugger, declarativeNetRequest, proxy, geolocation, unlimitedStorage and a few others — and Chrome rejects them in optional_permissions.
Why does "tabs" show no warning in some extensions?
Chrome merges overlapping warnings. "Read and change all your data on all websites" already covers what tabs reveals, so tabs adds nothing when the extension has all-sites access; "history" absorbs tabs, topSites and webNavigation the same way. This checker applies those rules in Chrome’s own order, which is why a permission can be listed as "Covered by a broader warning".
Is my manifest.json uploaded anywhere?
No. The checker runs entirely as a small script inside this page; your manifest never leaves your browser, and there is no upload, no API call and no analytics here. That is enforced rather than promised: this site’s test suite scans the shipped HTML for every browser API capable of sending data off the page and fails the build if it finds one.