Skip to main content

Browser extension permissions

Each permission the Keepiq extension asks for, and why. The store listings use these lines as the justification for review.

PermissionWhy the extension needs it
storageKeeps the connected accounts (server, user, app password, label, idle delay) and, for at most five minutes, which one-time code to fill on the next login step.
activeTabFills the login you pick into the tab you are on.
tabsReads the address of the current tab to show matching logins, and sends the fill to that tab only.
clipboardWriteCopies a one-time code so you can paste it, and clears it again after 30 seconds.
idleLocks the vault when your computer locks or after the idle delay you picked.
windowsOpens the small window that asks before a passkey is used, and the window for fingerprint or face unlock. Firefox needs no permission for this.
Access to all http and https sitesFinds login, one-time code and passkey fields on the sites you use. The extension fills only after you pick a login in its popup, or a one-time code on the step right after a login fill on the same site.

A test checks that every permission in browser-extension/manifest.json has a call site in the extension code (tests/extension/storeRelease.spec.js), so an unused permission fails the build.