Permission Checker
Paste a manifest or a list of permissions and see what each one actually allows, grouped by category and by how broad it is. Host permissions are explained separately.
Files are processed locally in your browser and are not uploaded.
Tool
A .json, .crx or .zip file. Read locally.
One per line, or comma separated. Entries containing :// or<all_urls> are treated as host permissions.
Waiting for a manifest or permission list.
API permissions
| Permission | Category | What it allows | Impact |
|---|
Host permissions
| Pattern | Scope | What it allows |
|---|
Optional permissions
| Permission | Category | What it allows | Impact |
|---|
- Grants a small, well-defined capability.
- Grants a meaningful capability on some data or pages.
- Grants access across a large surface area, such as all tabs or all sites.
- Grants a high-impact capability such as reading all browsing data, blocking requests, or attaching a debugger. Many legitimate extensions need these; the permission alone does not indicate a problem.
How to use
- Paste manifest.json into the text area, or load a .json, .crx or .zip file.
- If you only have a list of permissions, switch to the "Permission list" tab and paste them one per line.
- Read the API permissions and host permissions separately — they are different capabilities.
How it works
The manifest is parsed locally, then permissions, host_permissions and optional_permissions are pulled out and kept apart. Host permissions answer a different question from API permissions: not "what can the extension call" but "which pages is it allowed to touch".
Each permission name is looked up in a reference table built from the current Chrome Extensions API reference, and shown with what it grants, why it matters, and a category. Names that are not in the reference are listed separately as unrecognised — usually a platform-specific or enterprise-only permission, or a typo.
Impact describes the breadth of the capability, not the intent of the extension. A permission manager needs to read cookies for the sites you use it on; a password manager needs wide host access to work at all. A high-impact permission is worth understanding, and on its own it says nothing about whether an extension is well built.
The impact wording is deliberately careful: "high-impact permission" and "broad host access", never "malicious". Deciding whether an extension is trustworthy is a judgement about behaviour and source, not about a list of strings.
Important limitations
- The reference table is a snapshot of the Chrome API documentation, not Chrome itself. New permissions appear over time, and an unrecognised name is reported as such rather than guessed at.
- Permissions describe capability, not behaviour. An extension can hold broad permissions and use them well or badly, and nothing in a manifest tells you which.
- Optional permissions are listed separately because they are not granted on install — the extension must ask, and the user can decline.
- A pasted permission list is taken at face value. It cannot be cross-checked against a manifest, so an unknown name in a pasted list may simply be a typo.
Privacy and security
This tool runs entirely in your browser. Manifests and permission lists are read locally and never uploaded. No analytics are installed, so nothing you paste here is recorded.
Frequently asked questions
Does a powerful permission mean an extension is malicious?
No, and this tool will never tell you that. Permissions describe what an extension is able to do, not what it does. Plenty of widely used, reputable extensions hold broad host access because that is the only way to work across the sites they support. The useful question is whether a specific permission makes sense for what the extension claims to do.
What is the difference between permissions and host_permissions?
API permissions let an extension call specific Chrome functions, like reading your history or storing data. Host permissions say which web pages it may read or change, using match patterns such as "https://example.com/*". They are separate lists, and an extension often needs both: storage to keep a setting, and host access to act on a page.
Why does an extension want <all_urls>?
Because it works on every site. Password managers, ad blockers, translators, accessibility tools and page enhancers all need it. It is also the broadest grant available, so it is the one worth checking against what the extension says it does.
What are optional permissions for?
They let an extension ask for extra capability only when a user wants it — for example a reader mode that needs access to a site only when you use it on that site. Chrome shows the user exactly what is being requested, and the answer can be no without uninstalling anything.
My permission is listed as unrecognised. Is that a problem?
Not necessarily. Some permissions only exist on ChromeOS or on Chrome Enterprise-managed devices, and some belong to newer or narrower APIs that this reference table does not cover. If you are not on such a platform, check the spelling in the manifest.
Related tools
Manifest Viewer
Read a manifest.json field by field, formatted and explained.
Runs locallyChrome Extension Inspector
Get a readable summary of what an extension declares and how it runs.
Runs locallyManifest V3 Validator
Check common Manifest V3 configuration problems in a manifest.
Runs locally