Chrome Extension
Surface Phylax trust signals while browsing packages, repositories, and artifacts on the web.
-
Install from the Chrome Web Store
Phylax: Software Trust SignalsAdd to ChromeVerify with confidence. Trust signals surfaced by Phylax.
Works in any Chromium browser: Chrome, Edge, Brave and Arc.
-
Sign in
Open the extension and click Sign in. Choose either:
- A Phylax API token, pasted into the extension.
- An active Phylax CLI session, if you have already run
phylax auth login.
The extension reuses the CLI session where it can, so most people never paste a token.
-
What the extension shows
Package insights See version, publisher, and provenance at a glance.Attestation badge Verify artifacts with signed attestations and policies.Policy hints Understand policy status and what to do next. -
Supported pages
GitHub Repositories and pull requests.npm Packages and versions.PyPI Packages and releases.OCI registries Images and tags.On an unsupported page the extension stays dormant and adds nothing to the DOM.
-
Permissions
Permission Why it is needed Read your browsing history Detect supported pages and show the Phylax panel. Storage Store your preferences and auth session securely. Access to github.com,npmjs.com,pypi.org, registry domainsFetch metadata and attestations to surface trust signals. Notifications (optional) Alert you to policy violations or trust updates.
What the extension never sends
Phylax looks up artifacts by their public coordinates: registry, name and version. Page contents, form input and private repository source are never transmitted. On a private repository the extension can only tell you what your own token already entitles you to see.
Pin the extension to your toolbar so the panel is one click away instead of behind the
puzzle-piece menu. On a supported page the icon changes to reflect the current verdict, so a
BLOCK is visible before you run the install command sitting on the page.
Related guides
For the same verdicts in your editor, see the VS Code Extension. For the terminal, see the Phylax CLI.