recordist

Extension pairing

The Chrome extension is a client of the local API. It records nothing; it tells the desktop app when a browser meeting is live and what it is called. This page covers the mechanics. The user guide is at Chrome extension.

Why pairing exists

Every request to the local API needs the bearer token from api_token, and a browser extension cannot read files on disk. Pairing hands the token to the extension once, through a short-lived code, so that nothing else in the browser can talk to Recordist by pretending to be the extension.

The flow

  1. In Recordist, open Settings → Extension. The app shows a 6-digit code. (The extension’s Pair with Recordist button opens the same screen through the recordist://pair URL scheme.)
  2. The user types the code into the extension popup.
  3. The extension posts { "code": "…" } to POST /v1/pair and receives { "token": "…" }.
  4. The token is stored in chrome.storage.local, in the user’s browser profile, and sent only to http://127.0.0.1:47321.

Codes expire after two minutes and are single-use. Options → Forget pairing in the extension deletes the token; the app can also revoke it, after which the extension asks to pair again.

What the extension calls

Endpoint When
GET /v1/health Polled every 30–60 seconds from the service worker to mirror recording state on the toolbar badge
POST /v1/recording/prompt When a meeting page becomes active with the microphone on: { source_app, title, url, attendees }
POST /v1/recording/marker When the user drops a marker from the toolbar
GET /v1/events To keep the badge in sync while recording

The prompt endpoint only asks; the desktop app shows its confirm-to-record card and the person decides. The extension cannot start a recording on its own.

Permissions

Permission Why
Host access to the meeting sites (Google Meet, Microsoft Teams on the web, Zoom web client, Webex, Slack huddles) To read the meeting title and the participant names as displayed
Host access to http://127.0.0.1:47321/* To talk to the desktop app on your own machine
storage To keep the pairing token and settings
alarms To wake the service worker for the health poll
activeTab, tabs To know which tab a meeting update came from and to notice when a meeting tab closes

No remote code, no analytics, no requests to anything but loopback. It does not use any media API and never reads audio, video or screen content.

Building it yourself

The extension is a Manifest V3 extension built with a single npm run build in its package. Loading it unpacked requires Chrome 120 or later. It is being prepared for the Chrome Web Store; the user guide says how to get it in the meantime.