TruthID
Client Apps

Browser Extension

Credential autofill and a WebAuthn/passkey bridge for the Vault — talks to Mobile and Desktop, never holds write authority itself.

The browser extension (Manifest V3, built with WXT) brings TruthID Vault into your browser: autofilling saved credentials, addresses, and cards into web forms, and acting as a bridge for passkeys saved in the Vault. It supports Chrome-family browsers (including Brave, since it's Chromium-based) and Firefox 109+.

What it does — and doesn't hold

The extension has no Vault data or write authority of its own. Scanning a QR code from the mobile app starts a short-lived session (kept only in chrome.storage.session — never written to disk, cleared if the browser's service worker restarts), and the counterpart device — mobile or desktop — pushes back an encrypted subset of the Vault over whichever transport answers first. The extension relays and autofills; it never independently decides what's in the Vault.

It reaches both mobile and desktop, racing multiple channels in parallel:

  • LAN to mobile, scanning the local network for the same local HTTP server mobile uses to answer other cross-device requests (see Cross-Device & Storage).
  • Dead-drop (IPFS/IPNS) to mobile, the same best-effort fallback described on that page.
  • Desktop's local server, if desktop happens to be running on the same machine — no QR or extra encryption needed, since loopback is already implicitly trusted (see Desktop → The local server).

For passkeys specifically, the extension holds the signing key only for the duration of a browser session and answers navigator.credentials.get() calls directly — this is the "virtual authenticator" side of the Vault's passkey feature described in TruthID Vault.

Brave

Brave's anti-fingerprinting protections zero out the chrome.system.* API entirely, which breaks the automatic LAN-IP discovery the extension normally relies on. This is expected, detected explicitly, and has a permanent fix rather than a workaround: the extension falls back to manual IP entry, and that manual path is the correct, supported way to use LAN discovery on Brave — not a degraded temporary state waiting on a browser fix.

Next steps

  • Mobile — the usual counterpart device for autofill
  • Desktop — the same-machine counterpart, via the local server
  • TruthID Vault — what's actually being autofilled

On this page