What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Build a Manifest V3 extension around one clearly defined user task: choose the interface and execution components that task needs, declare only the required permissions, keep executable code in the extension package, and test the finished experience before publishing. The starting point is a root-level manifest.json with manifest_version set to 3; background work, page access, and data handling should each be designed for the feature rather than added by default.

1. Define the task and choose the extension’s interface

Write down the user action the extension will support and when the user needs to take it. That decision helps determine whether the extension should use a toolbar popup, a side panel, a context menu, a content script, or a combination of components. Chrome presents these as building blocks, not as a requirement to include every surface. Chrome extension development overview

  • Use a popup for a short interaction launched from the toolbar.
  • Consider a side panel for an experience users need to keep open alongside a page.
  • Use a context menu when the action belongs to a selected item or a page interaction.
  • Use a content script when the feature needs to read or change a web page’s DOM.

Keep the interaction focused. A feature that only runs after a user invokes the extension may need less access and less background machinery than one that continuously responds to browser events.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Create the root manifest

The extension’s manifest.json belongs in the extension’s root directory and declares its identity, capabilities, and resources. Chrome lists manifest_version, name, and version as required keys. For the manifest key, Chrome’s Manifest file format states: “The only supported value is 3.”

This minimal example shows the shape of a Manifest V3 extension, not a universal starter configuration:

{
  "manifest_version": 3,
  "name": "Example extension",
  "version": "1.0",
  "description": "A short, accurate description of the extension",
  "permissions": ["storage"],
  "background": {
    "service_worker": "service-worker.js"
  },
  "action": {
    "default_popup": "popup.html"
  }
}

The example includes a storage permission, service worker, and popup only to illustrate common manifest structure. Each is optional: omit any component the extension does not use. A popup-only extension may not need a background worker, and a content script or host permission belongs in the manifest only when the feature requires it. See the manifest reference for supported keys and their details.

3. Put each job in the right execution context

Service worker: background events and coordination

In Manifest V3, background event handling belongs in an extension service worker. It can coordinate work and communicate with content scripts or extension pages through messaging, but it does not have DOM access. Design background behavior around events rather than assuming the worker remains continuously active; worker lifecycle constraints also mean that important state should not depend on a permanently running process. Chrome extension development overview

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Content script: interaction with a web page

A content script runs in a web page and can read or modify that page’s DOM. Use it for the page-specific part of a feature, then communicate with the service worker or extension pages when coordination is needed. Avoid adding a content script to pages where the feature does not need to run.

Offscreen document: DOM APIs without a visible window

If background functionality needs DOM APIs that the service worker cannot access, consider an offscreen document rather than trying to use page DOM APIs from the worker. This is a specific architectural option for DOM-dependent background work, not a default requirement. Chrome extension development overview

4. Ask for the narrowest permissions that work

Permissions determine what extension capabilities and site access the extension asks users to grant. Request only what the current feature needs. A permission declaration is not, by itself, a privacy guarantee or a promise of Chrome Web Store approval; the extension’s actual collection, use, and disclosure of data must be accurate and policy-compliant. Declare permissions

Use temporary access for user-invoked page actions

For some actions triggered by the user on the current page, activeTab can grant temporary access to the active tab without requesting broader persistent site access. That access ends when the user navigates away from or closes the tab. Whether it fits depends on what the feature does and when it needs to run. The activeTab permission

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use optional permissions for features users enable separately

If an access request is not essential to the extension’s basic function, consider making it optional and requesting it when the user chooses the related feature. Explain why access is needed at that moment, in terms that match the action the user is taking. Declare permissions

Choose access according to the feature

  • Prefer temporary activeTab access where a user-invoked action can work with the current tab.
  • Use host permissions when the feature genuinely needs access to specified sites; use optional host permissions when that access can be enabled separately.
  • Do not request broad site access in anticipation of features that do not exist yet.

5. Keep code packaged and select network APIs by behavior

Manifest V3 disallows remotely hosted executable code. Include the extension’s executable code in the package that is reviewed, rather than fetching code at runtime. Migrate to Manifest V3: remote hosted code

For network features that previously relied on blocking webRequest listeners, assess whether declarativeNetRequest supports the needed request rules. The right API depends on the actual network behavior; do not assume that one approach covers every request-related use case. Migrate to Manifest V3: blocking web requests

6. Minimize and protect user data

Collect only data the feature needs, and be explicit about how it is handled. Chrome’s extension privacy guidance warns that extension storage is not encrypted, so it should not be treated as a secure vault for sensitive data. For data that must be transmitted, use HTTPS; sensitive data that needs remote storage requires an appropriately secure server-side design. Chrome extension user privacy

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Consider incognito behavior deliberately. Avoid retaining browsing history from incognito windows, and ensure the extension’s behavior and disclosures accurately reflect any data it does handle. Detailed store requirements can change, so check the current Chrome Web Store policies before release rather than relying on older privacy guidance alone. Chrome Web Store program policies

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

7. Test the whole user journey before publishing

Test the extension end to end, from installation and permission prompts through the task the user came to perform. Chrome’s best-practices guidance recommends manual coverage across browser versions, operating systems, and network conditions, as well as accurate privacy disclosures, policy compliance, and a listing that sets clear expectations. Improve extension quality

  • Check the core workflow, including expected behavior when a permission is denied or unavailable.
  • Test page interactions on the kinds of pages the extension supports, including navigation cases relevant to its design.
  • Exercise background events and messaging rather than assuming the service worker stays active.
  • Check behavior under different network conditions if the feature depends on remote services.
  • Review the store description and privacy disclosures against the extension’s actual data collection and behavior.

Store requirements and platform behavior can change. Verify the applicable API documentation and Chrome Web Store policies for the release you are preparing.

8. Migrate an existing Manifest V2 extension systematically

Migration is not a single manifest-version edit. The changes depend on the starting extension, so work through Chrome’s Manifest V2 to Manifest V3 migration guide and checklist. Areas to assess include:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Updating manifest structure and host-permission declarations.
  • Moving background behavior to an extension service worker and accounting for its lifecycle.
  • Replacing APIs or patterns that are not supported in Manifest V3, including evaluating network-request behavior.
  • Removing remotely hosted executable code and packaging the code the extension needs.
  • Planning testing and release steps around the extension’s actual functionality.

Do not assume that a migration checklist implies every change applies to every extension; map each item to the existing implementation and verify the relevant current documentation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.