Browser Extension

Permissions and Privacy

What a dApp can see and do with the Joey browser extension, and when.

Which sites can connect

  • Allowed: https: sites, and http: only on localhost, 127.0.0.1 and [::1].
  • Refused with 4100: file:, data:, blob:, about:, browser and extension pages, and sandboxed frames with an opaque (null) origin.

What a connection grants

  • Per site, per account. A grant is tied to your exact origin (scheme, host and port). The user chooses which accounts to share, and your site can only use those accounts.
  • Embedded frames need their own approval. A cross-origin iframe can't use the top-level page's grant until the user approves it separately.
  • Every signature is approved. Each signing request needs its own approval, which expires after 5 minutes (reported as 4001).

Nothing is revealed before approval

Until the user approves your site:

  • getAccounts() and a silent connect() return an empty list;
  • your site receives no events;
  • your site can't tell whether Joey is locked, because it gets 4001 where a connected site would get 4300, and connect waits for unlock rather than failing quickly.

The extension doesn't read page content and sends nothing about the pages a user visits.

Changes while a request is pending

  • If the user switches network, the request fails with 4901.
  • If your site's access is revoked, the request fails with 4100.

Revoking access

  • By your dApp: call joey.disconnect().
  • By the user: Settings → Connected Sites. Your site receives a disconnect event, and its pending requests are withdrawn.
  • Deleting an account removes it from every grant. A site left with no accounts is disconnected.

Rate limits

Exceeding these limits returns -32005. Back off rather than retrying in a loop.

Limit Value
Requests in flight per frame 8
Pending approvals per site 5
Pending approvals in total 20
Repeated rejections If the user rejects many requests from your site in a short time, Joey blocks your site briefly.