For reviewers, not buyers
Second Bookmark Bar for IT & security teams
This page is written for the person who has to decide whether to approve this extension on a managed device, not the person asking them to. Every claim below is checkable against the extension's own manifest and source — nothing here is a summary you have to trust on my word. If an employee sent you a link to this page after requesting Second Bookmark Bar through the Chrome Web Store, this is everything you need to evaluate that request.
Exact permissions
This is the complete permissions, optional_permissions, host_permissions, and content-script block from the shipped manifest — nothing omitted.
| Permission | Grants | What it's for |
|---|---|---|
| activeTab | The active tab's URL, only after the user interacts with the extension | Save-current-page, adaptive domain rules, excluded-site checks. Not standing background access — Chrome grants this per user gesture, revoked between interactions. |
| bookmarks | Read/write access to the entire Chrome bookmark tree | The core function. There's no version of this extension that works without it — every folder, slot, sort, and recovery operation is a bookmarks API call. |
| storage | Local and synced extension storage on the user's device | Settings, folder-slot config, usage ranks, restore-point snapshots. Never bookmark content shipped off-device through this permission. |
| favicon | Chrome's built-in favicon API | Renders site icons next to bookmarks without the extension fetching icons from third-party servers itself. |
| identity | Chrome's OAuth helper (launchWebAuthFlow) | The Google sign-in handshake for optional cloud sync. Not used unless the user opts into the paid cloud tier. |
| alarms | Scheduled background timers in the service worker | Cloud-sync retry polling, checkout-completion checks, and expired-token cleanup. None of these run unless cloud sync is turned on. |
| tabGroups (optional) | Create and label Chrome tab groups | Requested at runtime only, only if the user clicks "open this folder as a tab group" — never requested at install. |
| Host permission — ughpzmmhthrcnwtpfkzr.supabase.co | Network access to exactly one domain | The cloud-sync, auth, and billing backend. Not <all_urls>. Traffic only goes there if the user signs in for cloud sync, or on a detected license-tamper event (see below). |
| Content script — http://*/*, https://*/*, document_start | Runs on every page the user visits, before the page finishes loading | This is what actually produces the "Read and change all your data on the websites you visit" install warning — not the host permission above. It draws the bar and search UI in-page, and reads specific elements only when the user drags a bookmark or video onto it. |
What leaves the device, and under whose action
The entire extension makes exactly three outbound network requests in its source code — verified by grepping the shipped source for every fetch() call site, not estimated:
- Cloud sync / auth / billing — to the Supabase host permission above. Fires only after the user explicitly signs in with Google and enables the paid cloud tier. Carries bookmark roots, settings, and account/billing state.
- A single anonymous security alert — fires even for signed-out users, but only if the extension detects tampering with its own local license/entitlement data or install integrity. Sends an event type and severity value only — no bookmark or browsing data — to flag abuse of the paid tier. Does not run during normal use.
- Thumbnail verification for non-YouTube videos — when a user drags a video from a non-YouTube site into a video folder, the extension fetches a short list of thumbnail-image URLs already present on that source page to confirm one resolves to an image. The request goes to the page's own host, not to Second Bookmark Bar's backend, and carries no bookmark or account data. YouTube thumbnails are built from the video ID alone and never trigger this.
Everything else — the bookmark bar itself, search, folder switching, sorting, recovery, adaptive rules — is entirely local. No analytics SDK, no ad network, no third-party tracking script, anywhere in the codebase.
The free tier has effectively zero network egress
Without signing in, Second Bookmark Bar makes no outbound requests except the two narrow exceptions above (the tamper-detection alert and the non-YouTube thumbnail check, neither of which carries bookmark or account data). No account is created. Bookmarks stay in Chrome's own bookmark tree — the same data Chrome already syncs through your existing Chrome/Google Workspace policies, not a separate copy this extension creates. Uninstalling removes the extension's local and synced storage the same way Chrome removes any extension's storage; it does not touch or remove the underlying Chrome bookmarks, which were never the extension's data to hold in the first place. An optional, skippable feedback page opens on uninstall — no data is transmitted to open it.
Manifest V3, no remote code
Ships as Manifest V3 — Chrome's current, more restrictive extension platform, which structurally disallows fetching and executing arbitrary JavaScript from a server at runtime. Every line of code that runs is in the reviewable package Chrome Web Store hosts; there is no server-side logic injection path for this extension to quietly change behavior after your review.
Managed policy support
Second Bookmark Bar declares a storage.managed_schema in its manifest, so an admin who
deploys it via Chrome Enterprise policy (ExtensionSettings with a
policy_for_extension block, or the equivalent ADMX/plist path) can set three policies
centrally, rather than relying on each user to configure them individually:
DisableCloudSync(boolean) — blocks sign-in for the optional cloud tier at every entry point, and stops the sync loop on a device that was already signed in when the policy applies. Local bookmark and settings data is never touched by this policy.DisableOnboardingSurvey(boolean) — skips the one-time onboarding profile survey (age range / occupation / opt-in email) entirely, for every new install under the policy.PresetExcludedDomains(array of strings) — a set of domains the bar is hidden on by default. This is additive to whatever the user's own excluded-sites list already contains, and it cannot be overridden by a user's own per-site or whitelist-mode settings.
Two honest limitations as of this writing, not hidden because they're inconvenient: on a domain an admin policy excludes, the bar can still flash briefly visible for a moment before the policy takes effect (a first-paint timing gap, not a bypass), and the popup's own per-site toggle doesn't yet explain when a site is excluded by policy rather than by the user's own choice. Both are cosmetic, neither leaks data or lets a user override the policy, and both are on the list to close.
Request-to-install, for your Admin console
If your organization uses the standard Chrome Web Store request workflow, an employee who hits "blocked by organization" can click Request instead of Add to Chrome, and it lands in your Google Admin console for approval. Paste this into the request note or your own review ticket:
Extension: Second Bookmark Bar
Chrome Web Store ID: cbpekbmkijoehmojdcfnchhgpmkcgmif
Manifest version: 3
Permissions: activeTab, bookmarks, storage, favicon, identity, alarms
Optional permissions: tabGroups (runtime-requested only)
Host permissions: one domain (ughpzmmhthrcnwtpfkzr.supabase.co), used only if the
user signs in for the optional paid cloud tier
Remote code: none
Outbound network requests in source: 3 (cloud sync/auth, anonymous tamper alert,
non-YouTube thumbnail check — see https://secondbookmarkbar.com/enterprise/ for detail)
Free-tier network egress: effectively zero
Managed policy support: DisableCloudSync, DisableOnboardingSurvey,
PresetExcludedDomains (see https://secondbookmarkbar.com/enterprise/ for the schema)
Review reference: https://secondbookmarkbar.com/enterprise/ The honest gaps
This is a solo-built product, not an enterprise vendor, and pretending otherwise would make the rest of this page worth less. Being direct about what's missing is what should make the rest of it credible:
- No SOC 2 report, no ISO 27001 certification, and no formal third-party security audit exists today.
- No Data Processing Agreement (DPA) template is currently available for enterprise procurement.
- The managed-storage policy schema above is new and has not been used by a real deployment yet — it's been built and tested against its own logic, not battle-tested against a live company rollout. If you hit something it doesn't handle, that's useful to know about, not a sign it wasn't taken seriously.
- Billing is individual Stripe subscriptions only (€4.99/month or €47.90/year per person, 20% off annual) — there is no volume licensing, seat management, or centralized invoicing today.
- Support is a single developer, not a support team with an SLA.
None of these are secrets being managed around — they're the actual current state, and the reason this page leads with permissions and network behavior rather than a sales pitch. If your organization needs any of the above before it can approve a tool company-wide, that's a reasonable bar this extension doesn't clear yet.
Further reading
For the full permission-by-permission walkthrough written for an end user rather than a reviewer, see Is Second Bookmark Bar safe?. For what to do if you're the employee on the other side of a blocked-extension dialog, see what a blocked-extension request actually looks like. Full data handling is in the privacy policy.
Questions this page doesn't answer — info@secondbookmarkbar.com.