Extension pairing
The Chrome extension is a client of the local API. It records nothing; it tells the desktop app when a browser meeting is live and what it is called. This page covers the mechanics. The user guide is at Chrome extension.
Why pairing exists
Every request to the local API needs the bearer token from api_token, and a browser extension cannot read files on disk. Pairing hands the token to the extension once, through a short-lived code, so that nothing else in the browser can talk to Recordist by pretending to be the extension.
The flow
- In Recordist, open Settings → Extension. The app shows a 6-digit code. (The extension’s Pair with Recordist button opens the same screen through the
recordist://pairURL scheme.) - The user types the code into the extension popup.
- The extension posts
{ "code": "…" }toPOST /v1/pairand receives{ "token": "…" }. - The token is stored in
chrome.storage.local, in the user’s browser profile, and sent only tohttp://127.0.0.1:47321.
Codes expire after two minutes and are single-use. Options → Forget pairing in the extension deletes the token; the app can also revoke it, after which the extension asks to pair again.
What the extension calls
| Endpoint | When |
|---|---|
GET /v1/health |
Polled every 30–60 seconds from the service worker to mirror recording state on the toolbar badge |
POST /v1/recording/prompt |
When a meeting page becomes active with the microphone on: { source_app, title, url, attendees } |
POST /v1/recording/marker |
When the user drops a marker from the toolbar |
GET /v1/events |
To keep the badge in sync while recording |
The prompt endpoint only asks; the desktop app shows its confirm-to-record card and the person decides. The extension cannot start a recording on its own.
Permissions
| Permission | Why |
|---|---|
| Host access to the meeting sites (Google Meet, Microsoft Teams on the web, Zoom web client, Webex, Slack huddles) | To read the meeting title and the participant names as displayed |
Host access to http://127.0.0.1:47321/* |
To talk to the desktop app on your own machine |
storage |
To keep the pairing token and settings |
alarms |
To wake the service worker for the health poll |
activeTab, tabs |
To know which tab a meeting update came from and to notice when a meeting tab closes |
No remote code, no analytics, no requests to anything but loopback. It does not use any media API and never reads audio, video or screen content.
Building it yourself
The extension is a Manifest V3 extension built with a single npm run build in its package. Loading it unpacked requires Chrome 120 or later. It is being prepared for the Chrome Web Store; the user guide says how to get it in the meantime.