Manifest V3 Permission Checker
Paste a Chrome extension manifest.json to see the exact warnings users will be
asked to accept, find every Manifest V3 error before the Web Store does, and convert a V2
manifest to V3.
Everything runs locally: your manifest never leaves your browser.
Check a Chrome extension manifest
Add “PR Helper”?
It can:
- Read and change your data on all github.com sites and gitlab.com
- Read your browsing history
- Read and change your bookmarks
The install dialog’s warning list, worded and merged the way Chrome does it.
Problems
- error
permissions: "https://api.github.com/*" is a host pattern: in Manifest V3 it belongs in host_permissions, not permissions. - error
optional_permissions: "debugger" cannot be optional; Chrome rejects it in optional_permissions. Move it to permissions. - info
permissions: "tabs" is only needed to read url, title and favIconUrl of tabs you have no host access to. If you act on the tab the user clicked, activeTab does it with no install warning.
Permissions
| Permission | Warning on its own | In this manifest |
|---|---|---|
| storage | — | No warning |
| tabs | Read your browsing history | Shown |
| bookmarks | Read and change your bookmarks | Shown |
Auto-fixed Manifest V3
- 1 host pattern moved from permissions to host_permissions
Reading the example
The example asks for https://*.github.com/* twice — once in
host_permissions, once as a content script match — and for
gitlab.com, so Chrome shows one host warning: “Read and change your data on all
github.com sites and gitlab.com”. tabs adds “Read your browsing history”.
https://api.github.com/* is in the wrong array: in Manifest V3 a host pattern in
permissions grants nothing, so the auto-fix moves it to
host_permissions. And debugger cannot be optional at all.
A Chrome extension permissions auditor that matches Chrome
Most lists of extension permissions give each one a warning in isolation, which is not what
users see. Chrome merges warnings: all-sites access absorbs tabs,
webNavigation and declarativeNetRequest; history
absorbs tabs and topSites; hosts that differ only by country
domain are listed once. This Chrome extension permissions auditor applies
the same rules in the same order, so the list above is the list in the install dialog — and
the one users see again, with the extension disabled, when an update adds a warning.
Chrome extension Manifest V3 validator
As a Chrome extension Manifest V3 validator it checks what the Web Store
rejects or delays: V2 keys left in a V3 manifest, host patterns in the wrong array,
webRequestBlocking, remote code or 'unsafe-eval' in the content
security policy, invalid match patterns, a bad version string, and permissions that cannot be
optional.
Convert Manifest V2 to V3
To convert Manifest V2 to V3, paste the V2 file and copy the auto-fixed
version: browser_action becomes action, background scripts become a
service worker, host patterns move to host_permissions, and
web_accessible_resources and the CSP take their object form. The manifest is
only part of a migration, so anything that needs code changes is listed under the output
instead of being silently dropped.
Where these rules come from
The warning text and the rules for merging warnings are taken from Chromium’s source — its permission message rules and string resources — and checked against Chromium’s own unit tests, rather than from the permissions documentation, which is out of date in places. The Manifest V3 changes follow Chrome’s migration guide.