Manifest Viewer

Paste a manifest.json or drop in a .crx or .zip package and read the extension's name, version, permissions, background, content scripts and icons field by field. Parsed in your browser.

Files are processed locally in your browser and are not uploaded.

Tool

A .json, .crx or .zip file. Nothing is uploaded.

Paste the manifest, or load a file above — loading a file replaces the text below.

Waiting for a manifest.

How to use

  1. Paste manifest.json into the text area, or choose a .json, .crx or .zip file. Dropping a packaged extension works too — the manifest.json is read out of the archive.
  2. Every field is listed below the input with a plain-language note about what it means.
  3. Use "Copy JSON" to take the formatted manifest with you, or "Reset" to start over.

How it works

The manifest is parsed with JSON.parse, which reads JSON as data and never runs anything inside it. A manifest full of HTML or JavaScript in its fields is displayed as those literal characters.

For a .crx or .zip file, the CRX header is skipped first, then the ZIP archive is read in memory and only manifest.json is decompressed. The rest of the archive is listed but not loaded.

Display is grouped by what a field is for: identity, permissions, execution, resources, and everything else. Values are inserted into the page as text, so nothing from a manifest can become markup or run.

JSON.parse does not modify object prototypes, and the three keys that could be used to confuse downstream code — __proto__, constructor and prototype — are dropped before anything else touches the object.

Important limitations

  • The viewer describes what a manifest declares. It cannot tell you what the extension actually does at runtime, and a clean manifest is not evidence of a safe extension.
  • Fields that are not part of the extension manifest format are still shown, so you can see exactly what a package contains rather than only what Chrome recognises.
  • A manifest is not the whole extension. Behaviour lives in the JavaScript files, which this tool does not read or execute.
  • Very large manifests are refused. Real manifests are a few kilobytes.

Privacy and security

This tool runs entirely in your browser and has no upload path. Text you paste and files you choose are read with the File API and held in memory only while the page is open. Nothing is stored, and nothing is sent to a server.

Frequently asked questions

Where do I find manifest.json?

In an unpacked extension folder it is the manifest.json at the root. In a .crx or .zip package it sits at the root of the archive. Either works here — drop the file in and it is found for you.

Can this run anything inside a manifest?

No. A manifest is JSON: data, not code. It is parsed with JSON.parse and every value is written into the page as text. If a manifest declares a name of "<img src=x onerror=alert(1)>", you will see those characters, not a broken image.

Why does my pasted JSON fail to parse?

Most often it is a trailing comma, which JSON does not allow, or a comment, which JSON also does not allow even though some editors add them. The error message gives you the line and column where parsing stopped.

What is the difference between the viewer and the validator?

The viewer describes. The Manifest V3 Validator judges — it checks the manifest against documented Manifest V3 rules and reports errors and warnings you can act on.