Skip to main content
Last updated: 25 Sep 2026

govuk-browser-extension: Releasing the extension

  1. Install jq. For example, on mac, you can do it using brew 'brew install jq'
  2. Update the version in manifest_base.json
  3. Run npm run build
  4. Create a Pull Request with the new package committed
  5. Once the Pull Request is merged, the latest version is released via the Release workflow

How the secrets are managed

Ths secrets for both platforms are stored in the repo, and managed as follows:

Firefox

Extension API keys managed via the shared account in the Firefox developer hub:

  • FIREFOX_JWT_ISSUER
  • FIREFOX_JWT_SECRET

Account details are in the AWS Secrets Manager. See the documentation in Retrieve a credential from Secrets Manager

Chrome

For Chrome, there are several keys:

  • CHROME_CLIENT_ID
  • CHROME_CLIENT_SECRET
  • CHROME_PUBLISHER_ID
  • CHROME_REFRESH_TOKEN

The client ID and client secret are generated by:

  • Visiting the chrome-webstore-upload project in Google Cloud (which is accessible by everyone in the google-chrome-developers@digital.cabinet-office.gov.uk group).
  • Navigating to the OAuth 2.0 Client IDs screen
  • Clicking on the "Chrome Webstore Upload" project
  • From there, you can see the Client ID.
  • You can also generate a new Client Secret. You'll need to copy the secret before navigating away from the page. Remember to delete the old secret if you're switching to a new one.

You then need to generate the CHROME_REFRESH_TOKEN by:

  • Following the instructions in the chrome-webstore-upload-keys README.
  • You can ignore the first few steps - start following from npx chrome-webstore-upload-keys (around step 17).

The CHROME_PUBLISHER_ID is 06b3913d-07a7-479e-94aa-05bb5b3cd44d. (This is not sensitive info - it's public like the extension ID itself, which is dclfaikcemljbaoagjnedmlppnbiljen).

In order for the credentials to work, you must be a member of the Government Digital Service 'publisher':

  • Visit https://chrome.google.com/webstore/devconsole/06b3913d-07a7-479e-94aa-05bb5b3cd44d/settings. You should be on the list.
  • Any other admin member can invite you to the publisher account. If in doubt, ask someone in the google-chrome-developer group - we try to keep the two lists in sync.
  • NB: You do NOT need to pay $5 for a developer account. (Paying for a developer account gives you the ability to create an additional Publisher account - but you won't want to do that. It's also a hassle, requiring raising a CO service desk ticket and arranging a call with them so they can temporarily give you permission to pay a Google bill, and then revoke that permission.)
  • You technically don't even need to be in the google-chrome-developer group. Any Google-based email address can be added to the Publisher account.

If whoever generated the credentials above leaves GDS, the automated publishing will stop working and someone else will need to regenerate the credentials and put them into GitHub's repository secrets.

Note

Firefox and chrome currently disagree on few things with respect to V3 of manifest.json, so inorder to accommodate for both the browser, we would need a separate build for each browser with their manifest.json catering to each of them. To do this, we have created two manifest.json for each browser and have updated build script to generate separate manifest.json for each of them during the build.