The one that looks worst
Every permission
This is the list the Chrome Web Store package asks for at install.
- host access to all sites
- A session can contain any site. Without this the extension could only work on a list fixed at build time.
- declarativeNetRequest
- The core mechanism. It replaces the Cookie header on requests from a managed tab with that session's cookies. Without it there is no product.
- cookies
- Reads cookies so they can be copied into a session, and writes a session's cookies back into its own private store.
- webRequest
- Observes response headers so a cookie set by a site can be folded into the right session rather than the browser's shared store. Observing only; it does not block.
- webNavigation
- Detects when a tab navigates so the correct session rules are live before the first request leaves, which is what prevents a half-finished login.
- scripting
- Injects the small script that keeps localStorage and sessionStorage separate per session, and applies the fingerprint posture you chose.
- tabs
- A session is a property of a tab. The extension needs tab identity to know which session a request belongs to.
- tabGroups
- Colours tabs by session, which is how you can see which account a tab is in without clicking it.
- storage
- Stores your sessions and settings on your machine.
- unlimitedStorage
- A cookie store per session plus the journal exceeds the default five megabyte quota once you have several sessions.
- contextMenus
- Adds a right-click entry to open a link, or move a tab, into a session.
What leaves your machine
We want to be exact here, because the easy version of this claim is not true. Isolating cookies on every site requires access to every site, so the permission list above does grant the capability to reach the network. This is everything the extension uses it for:
- Anonymous usage stats, off by default and sent only if you turn them on: features used, bucketed session and tab counts, days since install, error types, OS, architecture, browser and major version, language, whole-hour time-zone offset, and a random install id.
- Favicon fetches for the sites in your own sessions, sent without cookies.
- Pro only: the licence server, which receives the key, a random device id and a coarse label such as “Windows, Chrome”, and encrypted sync if you turn it on.
The usage stats have two independent switches and both have to be on. The first is your consent, which is off until you turn it on. The second is an endpoint, which is injected at packaging time and exists only in the store build, so a developer running an unpacked copy sends no stats and could not send any if they tried.
What it can carry is bounded by construction rather than by promise. Every field is a version, a bucketed count, a value from a closed enum, a boolean or a fixed slug. There is deliberately no method anywhere in the module that accepts a free-form string, so a URL, a domain, a cookie or an account name has no path into a payload even by mistake. The full list is at what it collects.