What is a CRX file?
A CRX is the container Chrome uses to install an extension: a small binary header wrapped around an ordinary ZIP. Here is what is inside it and why you cannot just unzip one.
The short answer
A .crx file is the package format Chrome installs from. It is a ZIP archive with a binary header in front of it. That header is why your archive tool says the file is corrupt, and it is also what ties the package to a publisher.
What is inside
Every CRX contains three things, in order:
- A magic number. The first four bytes are always
Cr24. Nothing else starts a file this way, which is how tools tell a CRX from a ZIP instantly. - A header. This differs by format version. A CRX2 header declares the length of a public key and the length of a signature, and stores both before the archive. A CRX3 header declares one length for a block of metadata containing signed proof-of-ownership information, which is also stored before the archive.
- The ZIP archive. This is the actual extension:
manifest.json, the JavaScript, the HTML, the icons, the stylesheets. Its internal structure is nothing special — it is a normal ZIP with a rootmanifest.json.
Why a plain unzip fails
Archive tools expect a ZIP local file header, PK\x03\x04, at byte zero. A CRX hasCr24 there instead, followed by the header, and only then the real ZIP. The archive tool sees a signature it does not recognise and reports a bad file. Nothing is actually corrupt — the ZIP is intact, just not at offset zero.
This is exactly what the CRX to ZIP converter fixes. It reads the header to find where the archive begins, then slices those bytes out. It does not rebuild the archive, so the ZIP you get back is byte-for-byte the one that was inside.
What the signature is for
The header carries a signature produced with a publisher key. Its purpose is to let Chrome tell "this package is the one the publisher signed" apart from "this is a copy someone edited after the fact". That distinction matters for auto-updates: Chrome will only update an installed extension if the new package carries a valid signature from the same key.
Important limit. Converting a CRX to a ZIP removes the signature along with the header. It does not verify it first. The converter on this site reads the container; it makes no claim that a package is authentic or untampered, and it cannot tell you who published it.
What a CRX is not
- Not a browser, not an installer. A CRX is just a file. It does nothing on its own, and no web page can install one for you.
- Not necessarily safe. The signature says a publisher signed it, not that it is harmless. Reading the manifest is a separate step, and this site has tools for that.
- Not the same thing as the Chrome Web Store listing. The store serves CRX packages from its own endpoint; the file you get is a snapshot of one published version, not a live view of the listing.
Working with one
The usual sequence, and the one this site is built around:
- Obtain the CRX — see the Chrome Extension Downloader.
- Convert it to a ZIP locally — see the CRX to ZIP converter. Nothing is uploaded.
- Read the
manifest.json— see the Manifest Viewer. - Check what it asks for — see thePermission Checker.
- Decide for yourself whether you want it loaded. That decision, and the act of loading it, are yours through Chrome's own developer mode.
Related formats
If you are choosing between formats, CRX vs ZIP covers what actually changes when you convert, andhow to find a Chrome extension ID covers getting the identifier you need to fetch a package in the first place.
Tools for this
CRX to ZIP Converter
Remove the CRX header and get the underlying ZIP package, in your browser.
Runs locallyChrome Extension Downloader
Turn a Chrome Web Store link or extension ID into a CRX download request.
Manifest Viewer
Read a manifest.json field by field, formatted and explained.
Runs locally