keepr
ENRU
Log inGet started
Help centerApps & extensionsBrowser extension permissions: what Keepr asks for and why

Browser extension permissions: what Keepr asks for and why

Updated Oct 6, 2026
6 min read

In short

The Keepr extension looks at two things in your browser: the address and the title of a tab. From them it recognises a Jira, GitLab or GitHub issue and offers it to the timer. It does not read your browsing history, keeps nothing of its own running inside the pages you visit, and reads no page content except, in one case described below, the issue's title.

Some browser prompts sound broader than that, because the browser describes everything a permission could allow, not what the extension does with it. Below is each permission in turn: what it lets the extension do, what Keepr actually reads with it, when you are asked, and how to take it back.

Granted when you install

Storage (“storage”), no prompt. Keeps your personal API token and the workspace you chose in this browser, so you are not asked for them after every restart. Nothing is synced to your other devices, and Disconnect, in the popup's account menu, clears both.

Access to api.keepr.ru, which Chrome words as “Read and change your data on api.keepr.ru”. This is the Keepr API, the only place the extension sends anything: it starts and stops your timers and lists your projects, tasks and tags. There are no analytics and no third parties.

Active tab (“activeTab”), no prompt. When you click the Keepr icon, the browser lets the extension read the tab the popup opened over, until you leave that page or close the tab. Keepr reads its address and title to offer the issue. Your other tabs stay out of reach.

Scripting (“scripting”), no prompt. Lets the extension run its single title script, described below, in a tab it already has access to. On its own it grants access to no site at all.

Side panel (“sidePanel”, Chrome only), no prompt. Lets you pin the timer to the browser's side panel with the pin in the popup's header. The panel opens only when you pin it, and shows the same timer as the popup.

Asked for in the pinned side panel

The popup closes as soon as you click away, so the active tab grant is all it needs. The pinned panel stays open while you switch tabs and never receives that grant, so it has to ask before it can follow the issue you have open. Nothing in this section is granted at install, and nothing is asked until you pin the panel.

Tab access (“tabs”), optional. Chrome words it as “Read your browsing history”; the panel offers it first, as “Let Keepr see the tab you're on”. With it, the panel reads the address and title of the active tab in its window each time you switch tabs, which lets it follow you to an issue on any tracker, your company's own included. Keepr does not read your history, keeps no record of the tabs you visit, and sends nothing about a page that is not an issue.

One tracker site at a time (“https://*/*”), optional. If you choose “Not now”, the panel instead offers the tracker site you last opened the popup on, for example “Let Keepr see issues on gitlab.com”, and Chrome asks for that site alone: “Read and change your data on gitlab.com”. Keepr reads the same address and title, on that site's tabs only. You can allow more sites, such as your company's own GitLab or Jira, on the extension's Options page. The pattern covers every HTTPS site only because company trackers cannot be listed in advance; each site is still granted separately, by you.

The panel asks for a site in one more case: when an issue is open in a board drawer and the panel may not run the title script there, it asks for that site, for example “Let Keepr read issue titles on gitlab.com”. It is the same one-site grant, and you can refuse it; the card then shows the issue's key without its title.

The one script, and when it runs

The extension declares no content script: nothing of Keepr's is loaded into the pages you visit or stays running there. There is a single exception. An issue opened in a board or list drawer leaves the board's name in the tab title rather than the issue's. Only then, when you open the popup or the panel follows you there, does the extension run one short function in that tab.

The function asks the tracker for that one issue's title, with the session you are already signed in with: Jira's or GitLab's own API on the same site, or GitHub's public API for github.com. Failing that, it reads the issue's heading on the page. It returns the title and finishes; it reads nothing else on the page and asks no other site for anything.

It runs only on a recognised issue page, and only in a tab the extension may already access: the one you opened the popup on, or a tracker site you allowed for the panel.

What reaches Keepr

When the popup or the panel recognises an issue, the extension asks Keepr whether one of your tasks already carries that issue's key, and which project tasks from the same tracker project went into, so the card can name the right task or project. That lookup sends Keepr the issue's key and the tracker project's address, and saves nothing.

The issue's title reaches Keepr only when you act on it. “Use” fills the timer description with the issue's key and title; “Start timer” saves that description with the time entry and, if no task matches yet, creates one named after the issue's title, with the key and the issue's address stored beside it.

Nothing else about your browsing leaves the browser: not the other pages you visit, not your other tabs, and not the page's content. Your API token stays in this browser and goes nowhere but api.keepr.ru.

Taking a permission back

Open the extension's Options page: Settings at the bottom of the popup, or right-click the Keepr icon and choose Options. “Tab addresses for the side panel” shows whether tab access is allowed, with a button to revoke it; the panel then asks again next time. “Issue pages in the side panel” lists every site you allowed, each with a button to stop reading it.

Chrome shows the same sites under : open Keepr's Details and look under Site access. Removing a site there has the same effect as removing it on the Options page.

Storage, active tab, scripting and the side panel have no switch of their own; they go when you remove the extension. To cut the extension off from your account, choose Disconnect in the popup's account menu, or revoke its token on the API tokens page, which works for every browser the token was pasted into.

In Firefox

Firefox installs Keepr from its Add-ons listing. At install it asks for access to your data on api.keepr.ru and lists the data the extension needs to work, which Firefox requires it to declare up front. That data is your authentication info (the API token), personally identifying info (the name and email of your Keepr account, shown in the popup) and website content (an issue's key, title and address) — the same items this article describes.

There is no side panel permission: the panel is Firefox's own sidebar, opened with the same pin in the popup. Firefox words tab access as “Access browser tabs” and a single site as access to your data on that site; what Keepr reads with them is unchanged.

Firefox lets you switch off access to api.keepr.ru at any time, on the extension's permissions tab in . The extension cannot work without it, so the popup offers to allow it again. The same tab lists the optional grants, which you can remove there as well as on the Options page.