KeyBridge

Recipe format

A recipe tells KeyBridge where your own key lives on a site, how to check it, and which apps it may be handed to. Recipes are plain JSON with no code, so the library can grow without shipping new extension versions, and the Chrome Web Store's "no remote code" rule still holds.

Example

{
  "id": "example",
  "version": 1,
  "name": "Example service",
  "keyLabel": "API key",
  "description": "What the key is and what it's used for.",
  "site": "https://example.com/",
  "matches": ["https://example.com/*", "https://*.example.com/*"],
  "instructions": "Shown in the popup: what to do on the site before pressing Grab.",
  "strategies": [
    { "type": "resource", "pattern": "api\\.example\\.com/v1/([A-Za-z0-9_-]{20,})/" },
    { "type": "request", "urls": ["https://api.example.com/*"], "header": "authorization", "pattern": "^Bearer (.+)$" },
    { "type": "localStorage", "key": "^auth$", "path": "token" }
  ],
  "keyPattern": "^[A-Za-z0-9_-]{20,64}$",
  "validate": { "url": "https://api.example.com/v1/{key}/ping", "okStatus": [200, 204] },
  "targets": [{ "name": "My app", "url": "https://app.example.net/#key={key}", "qr": true }]
}

Fields

FieldRequiredMeaning
idyesLowercase id. A custom recipe with a built-in id overrides the built-in one.
versionInteger. The library offers an Update when it has a higher version.
name, keyLabel, description, instructionsnameText shown to the user.
siteWhere Open site goes.
matchesyesChrome match patterns for pages where Grab runs. Broad patterns like https://*/* are rejected.
strategiesyesTried in order. Every candidate found is validated, and the first valid one wins.
keyPatternRegex a key must match.
validateurl (https, contains {key}) is fetched without cookies. Statuses in okStatus (default [200]) mean the key is valid.
targetsyesWhere the key can go: name, url (https, contains {key}), and qr: true to offer a QR code for phones. Use the URL fragment (#…) so the key never reaches a server.

Strategies

Each strategy can take a pattern (regex). The first capture group, or the whole match, is the key.

typeReadsExtra fields
resourceURLs of requests the page has already made (Performance API), newest firstpattern
requestLive requests seen by the background worker. Needs Live capture turned on for the recipeurls (match patterns), pattern on the URL, or header (e.g. authorization) plus pattern
localStorage / sessionStorageStorage entrieskey (regex on the entry name), path (JSON path into the value)
indexedDBAll rows of one object store (read-only; never creates databases)db, store, path
cookieCookies visible to the page (not HttpOnly)name
globalA page JavaScript variable (runs in the page's own context)path, e.g. window.__APP__.apiKey
domPage elementsselector, optional attribute

See the safety model for how recipes are checked before they're added.