Browser Extension
Permissions and Privacy
What a dApp can see and do with the Joey browser extension, and when.
Which sites can connect
- Allowed:
https:sites, andhttp:only onlocalhost,127.0.0.1and[::1]. - Refused with
4100:file:,data:,blob:,about:, browser and extension pages, and sandboxed frames with an opaque (null) origin.
What a connection grants
- Per site, per account. A grant is tied to your exact origin (scheme, host and port). The user chooses which accounts to share, and your site can only use those accounts.
- Embedded frames need their own approval. A cross-origin iframe can't use the top-level page's grant until the user approves it separately.
- Every signature is approved. Each signing request needs its own approval, which expires after 5 minutes (reported as
4001).
Nothing is revealed before approval
Until the user approves your site:
getAccounts()and a silentconnect()return an empty list;- your site receives no events;
- your site can't tell whether Joey is locked, because it gets
4001where a connected site would get4300, andconnectwaits for unlock rather than failing quickly.
The extension doesn't read page content and sends nothing about the pages a user visits.
Changes while a request is pending
- If the user switches network, the request fails with
4901. - If your site's access is revoked, the request fails with
4100.
Revoking access
- By your dApp: call
joey.disconnect(). - By the user: Settings → Connected Sites. Your site receives a
disconnectevent, and its pending requests are withdrawn. - Deleting an account removes it from every grant. A site left with no accounts is disconnected.
Rate limits
Exceeding these limits returns -32005. Back off rather than retrying in a loop.
| Limit | Value |
|---|---|
| Requests in flight per frame | 8 |
| Pending approvals per site | 5 |
| Pending approvals in total | 20 |
| Repeated rejections | If the user rejects many requests from your site in a short time, Joey blocks your site briefly. |