Recipe format
A recipe tells KeyBridge where your own key lives on a site, how to check it, and which apps it may be handed to. Recipes are plain JSON with no code, so the library can grow without shipping new extension versions, and the Chrome Web Store's "no remote code" rule still holds.
Example
{
"id": "example",
"version": 1,
"name": "Example service",
"keyLabel": "API key",
"description": "What the key is and what it's used for.",
"site": "https://example.com/",
"matches": ["https://example.com/*", "https://*.example.com/*"],
"instructions": "Shown in the popup: what to do on the site before pressing Grab.",
"strategies": [
{ "type": "resource", "pattern": "api\\.example\\.com/v1/([A-Za-z0-9_-]{20,})/" },
{ "type": "request", "urls": ["https://api.example.com/*"], "header": "authorization", "pattern": "^Bearer (.+)$" },
{ "type": "localStorage", "key": "^auth$", "path": "token" }
],
"keyPattern": "^[A-Za-z0-9_-]{20,64}$",
"validate": { "url": "https://api.example.com/v1/{key}/ping", "okStatus": [200, 204] },
"targets": [{ "name": "My app", "url": "https://app.example.net/#key={key}", "qr": true }]
}
Fields
| Field | Required | Meaning |
|---|---|---|
id | yes | Lowercase id. A custom recipe with a built-in id overrides the built-in one. |
version | Integer. The library offers an Update when it has a higher version. | |
name, keyLabel, description, instructions | name | Text shown to the user. |
site | Where Open site goes. | |
matches | yes | Chrome match patterns for pages where Grab runs. Broad patterns like https://*/* are rejected. |
strategies | yes | Tried in order. Every candidate found is validated, and the first valid one wins. |
keyPattern | Regex a key must match. | |
validate | url (https, contains {key}) is fetched without cookies. Statuses in okStatus (default [200]) mean the key is valid. | |
targets | yes | Where the key can go: name, url (https, contains {key}), and qr: true to offer a QR code for phones. Use the URL fragment (#…) so the key never reaches a server. |
Strategies
Each strategy can take a pattern (regex). The first capture group, or the whole match, is the key.
type | Reads | Extra fields |
|---|---|---|
resource | URLs of requests the page has already made (Performance API), newest first | pattern |
request | Live requests seen by the background worker. Needs Live capture turned on for the recipe | urls (match patterns), pattern on the URL, or header (e.g. authorization) plus pattern |
localStorage / sessionStorage | Storage entries | key (regex on the entry name), path (JSON path into the value) |
indexedDB | All rows of one object store (read-only; never creates databases) | db, store, path |
cookie | Cookies visible to the page (not HttpOnly) | name |
global | A page JavaScript variable (runs in the page's own context) | path, e.g. window.__APP__.apiKey |
dom | Page elements | selector, optional attribute |
See the safety model for how recipes are checked before they're added.