permissions

Enables extensions to request extra permissions at runtime, after they have been installed.

Extensions need permissions to access more powerful WebExtension APIs. They can request permissions at install time by including them in the permissions manifest.json key. The main advantages of asking for permissions at install time are:

  • The extension asks the user only once, so it's less disruptive for them, and a simpler decision.
  • The extension can rely on the access to the APIs it needs, as it knows the permissions are granted.

In most major browsers, users can see if installed extensions request advanced permissions through the browser's extensions manager.

Using the permissions API, an extension can request additional permissions at runtime. The extension must list these permissions in

The main advantages of requesting permissions at runtime are:

  • The extension can run with a smaller set of permissions, except when it needs them.
  • The extension can gracefully handle permission denial, instead of presenting the user with a global "all or nothing" choice at install time. For example, a user can get a lot out of that map extension without giving it access to their location.
  • The extension may need host permissions, but not know at install time which host permissions it needs. For example, the list of hosts may be a user setting. In this scenario, requesting a more specific range of hosts at runtime can be an alternative to asking for "<all_urls>" at install time.

Note that some permissions are not allowed in optional_permissions.

To use the permissions API, decide which permissions your extension can request at runtime, and list them in optional_permissions and browser_specific_settings.gecko.data_collection_permissions.optional. After this, you can request any permissions included in optional_permissions or browser_specific_settings.gecko.data_collection_permissions.optional. The extension can only make these requests in the handler for a user action (for example, a click handler).

Starting with Firefox 84, users can manage optional permissions of installed extensions from the Add-ons Manager. Extensions that use optional permissions should listen for browser.permissions.onAdded and browser.permissions.onRemoved API events to know when a user grants or revokes these permissions.

For advice on designing your request for runtime permissions, to maximize the likelihood that users grant them, see Request permissions at runtime.

Types

permissions.Permissions

Represents a set of permissions.

Methods

permissions.contains()

Checks whether the extension has specific permissions.

permissions.getAll()

Retrieves all the permissions currently granted to the extension.

permissions.remove()

Gives up a set of permissions.

permissions.request()

Asks for a set of permissions.

Event handlers

permissions.onAdded

Fires when a user grants new permissions.

permissions.onRemoved

Fires when a user revokes a permission.

Example extensions

Browser compatibility

desktop mobile
Chrome
Edge
Firefox
Opera
Safari
Firefox for Android
Safari on iOS
permissions
Chrome – Full support
Chrome 16 (Release date: 2011-12-13)
footnote Full support
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote Full support
Firefox – Full support
Firefox 55 (Release date: 2017-08-08)
footnote Full support
Opera – Full support
Opera 15 (Release date: 2013-07-02)
footnote Full support
Safari – Full support
Safari 14 (Release date: 2020-09-16)
footnote Full support
Firefox for Android – Full support
Firefox for Android 79 (Release date: 2020-07-28)
footnote Full support
Safari on iOS – Full support
Safari on iOS 15 (Release date: 2021-09-20)
footnote Full support
Permissions
Chrome – Full support
Chrome 16 (Release date: 2011-12-13)
footnote Full support
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote Full support
Firefox – Full support
Firefox 55 (Release date: 2017-08-08)
footnote Full support
Opera – Full support
Opera 15 (Release date: 2013-07-02)
footnote Full support
Safari – Full support
Safari 14 (Release date: 2020-09-16)
footnote Full support
Firefox for Android – Full support
Firefox for Android 79 (Release date: 2020-07-28)
footnote Full support
Safari on iOS – Full support
Safari on iOS 15 (Release date: 2021-09-20)
footnote Full support
Permissions.data_collection
Chrome – No support
Chrome
footnote No support
Edge – No support
Edge
footnote No support
Firefox – Full support
Firefox 140 (Release date: 2025-06-24)
footnote Full support
Opera – No support
Opera
footnote No support
Safari – No support
Safari
footnote No support
Firefox for Android – Full support
Firefox for Android 142 (Release date: 2025-08-19)
footnote Full support
Safari on iOS – No support
Safari on iOS
footnote No support
contains
Chrome – Full support
Chrome 16 (Release date: 2011-12-13)
footnote Full support
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote Full support
Firefox – Full support
Firefox 55 (Release date: 2017-08-08)
footnote Full support
Opera – Full support
Opera 15 (Release date: 2013-07-02)
footnote Full support
Safari – Full support
Safari 14 (Release date: 2020-09-16)
footnote Full support
Firefox for Android – Full support
Firefox for Android 79 (Release date: 2020-07-28)
footnote Full support
Safari on iOS – Full support
Safari on iOS 15 (Release date: 2021-09-20)
footnote Full support
getAll
Chrome – Full support
Chrome 16 (Release date: 2011-12-13)
footnote Full support
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote Full support
Firefox – Full support
Firefox 55 (Release date: 2017-08-08)
footnote Full support
Opera – Full support
Opera 15 (Release date: 2013-07-02)
footnote Full support
Safari – Full support
Safari 14 (Release date: 2020-09-16)
footnote Full support
Firefox for Android – Full support
Firefox for Android 79 (Release date: 2020-07-28)
footnote Full support
Safari on iOS – Full support
Safari on iOS 15 (Release date: 2021-09-20)
footnote Full support
onAdded
Chrome – Full support
Chrome 16 (Release date: 2011-12-13)
footnote Full support
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote Full support
Firefox – Full support
Firefox 77 (Release date: 2020-06-02)
footnote Full support
Opera – Full support
Opera 15 (Release date: 2013-07-02)
footnote Full support
Safari – Full support
Safari 14 (Release date: 2020-09-16)
footnote Full support
Firefox for Android – Full support
Firefox for Android 79 (Release date: 2020-07-28)
footnote Full support
Safari on iOS – Full support
Safari on iOS 15 (Release date: 2021-09-20)
footnote Full support
onRemoved
Chrome – Full support
Chrome 16 (Release date: 2011-12-13)
footnote Full support
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote Full support
Firefox – Full support
Firefox 77 (Release date: 2020-06-02)
footnote Full support
Opera – Full support
Opera 15 (Release date: 2013-07-02)
footnote Full support
Safari – Full support
Safari 14 (Release date: 2020-09-16)
footnote Full support
Firefox for Android – Full support
Firefox for Android 79 (Release date: 2020-07-28)
footnote Full support
Safari on iOS – Full support
Safari on iOS 15 (Release date: 2021-09-20)
footnote Full support
remove
Chrome – Full support
Chrome 16 (Release date: 2011-12-13)
footnote Full support
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote Full support
Firefox – Full support
Firefox 55 (Release date: 2017-08-08)
footnote Full support
Opera – Full support
Opera 15 (Release date: 2013-07-02)
footnote Full support
Safari – Full support
Safari 14 (Release date: 2020-09-16)
footnote
footnote Removing <all_urls> or *://*/* origins will remove previously granted permission to request specific origin patterns and will stop automatically prompting the user for access to any visited website via the extension's access popover in the toolbar.
Firefox for Android – Full support
Firefox for Android 79 (Release date: 2020-07-28)
footnote Full support
Safari on iOS – Full support
Safari on iOS 15 (Release date: 2021-09-20)
footnote
footnote Removing <all_urls> or *://*/* origins will remove previously granted permission to request specific origin patterns and will stop automatically prompting the user for access to any visited website via the extension's access popover in the toolbar.
request
Chrome – Full support
Chrome 16 (Release date: 2011-12-13)
footnote Full support
Edge – Full support
Edge 79 (Release date: 2020-01-15)
footnote Full support
Firefox – Full support
Firefox 55 (Release date: 2017-08-08)
footnote
footnote It's not possible to request permissions from within DevTools (bug 1796933).
footnote Before version 101, permissions cannot be requested from a sidebar document (bug 1493396).
footnote Before version 75, permissions cannot be requested from popup panels (see bug 1432083).
footnote Before version 61, permissions cannot be requested from options pages embedded in about:addons (see bug 1382953).
Opera – Full support
Opera 15 (Release date: 2013-07-02)
footnote Full support
Safari – Full support
Safari 14 (Release date: 2020-09-16)
footnote
footnote Requesting <all_urls> or *://*/* origins will grant permission to request specific origin patterns and automatically prompt the user for access to any visited website via the extension's access popover in the toolbar.
footnote The user will be prompted again for permissions that have been previously granted and then removed.
footnote Supported permissions will be granted without prompting the user. Only specific origin patterns will prompt the user.
Firefox for Android – Full support
Firefox for Android 120 (Release date: 2023-11-21)
footnote Full support
Safari on iOS – Full support
Safari on iOS 15 (Release date: 2021-09-20)
footnote
footnote Requesting <all_urls> or *://*/* origins will grant permission to request specific origin patterns and automatically prompt the user for access to any visited website via the extension's banner.
footnote The user will be prompted again for permissions that have been previously granted and then removed.
footnote Supported permissions will be granted without prompting the user. Only specific origin patterns will prompt the user.

Legend

Tip: you can click/tap on a cell for more information.

Full support
Full support
No support
No support
See implementation notes.

See also

Note: This API is based on Chromium's chrome.permissions API.