Skip to content
Phylax
Tools & interfaces

Chrome Extension

Surface Phylax trust signals while browsing packages, repositories, and artifacts on the web.

  1. Install from the Chrome Web Store

    Phylax: Software Trust Signals

    Verify with confidence. Trust signals surfaced by Phylax.

    Phylax Labs · ★ 4.5 (127) · Productivity
    Add to Chrome

    Works in any Chromium browser: Chrome, Edge, Brave and Arc.

  2. Sign in

    Open the extension and click Sign in. Choose either:

    • A Phylax API token, pasted into the extension.
    • An active Phylax CLI session, if you have already run phylax auth login.

    The extension reuses the CLI session where it can, so most people never paste a token.

  3. What the extension shows

    Package insights See version, publisher, and provenance at a glance.
    Attestation badge Verify artifacts with signed attestations and policies.
    Policy hints Understand policy status and what to do next.
  4. Supported pages

    GitHub Repositories and pull requests.
    npm Packages and versions.
    PyPI Packages and releases.
    OCI registries Images and tags.

    On an unsupported page the extension stays dormant and adds nothing to the DOM.

  5. Permissions

    PermissionWhy it is needed
    Read your browsing historyDetect supported pages and show the Phylax panel.
    StorageStore your preferences and auth session securely.
    Access to github.com, npmjs.com, pypi.org, registry domainsFetch metadata and attestations to surface trust signals.
    Notifications (optional)Alert you to policy violations or trust updates.

What the extension never sends

Phylax looks up artifacts by their public coordinates: registry, name and version. Page contents, form input and private repository source are never transmitted. On a private repository the extension can only tell you what your own token already entitles you to see.

For the same verdicts in your editor, see the VS Code Extension. For the terminal, see the Phylax CLI.

Did this page help you?