Krodium Developers

Documentation

Everything you need to publish an extension, a web app or a desktop app.

Getting started

Publishing on Krodium takes about ten minutes of your time and a short wait for review.

  1. Go to the developer console and sign in with Viremail.
  2. Choose Individual or Organisation, fill in your details, upload your identity document and accept the Developer Agreement.
  3. Organisations then prove they own their domain. The console shows you exactly what to add.
  4. While we verify you, create a listing and save it as a draft. Add your icon, screenshots, descriptions and package.
  5. When your account is verified, send the listing for review. You will see the decision, and a reason if we say no, in the console.

What a listing needs

  • A name (up to 60 characters), a short description (up to 100) and a full description (up to 4,000).
  • One category: Productivity, Business, Developer tools, Creativity, Communication, Privacy and security, Education, Finance, Lifestyle, Utilities, Games.
  • An icon: a PNG, exactly 512 by 512 pixels.
  • One to eight screenshots (PNG, JPEG or WebP).
  • A support address and a privacy policy address, both starting with https://.
  • A price: Free, or Paid in pounds. Paid listings are saved now and sold once payouts open.

Packaging

Extensions

Upload a .krx, .xpi or .zip file. It must be a zip with a manifest.json at the top level. We read it without unpacking it and check the name, version and permissions, then show you the result.

{
  "manifest_version": 3,
  "name": "Example Notes",
  "version": "1.2.0",
  "description": "Quick notes in your sidebar.",
  "permissions": ["storage"],
  "host_permissions": ["https://example.com/*"]
}

A .krx also needs a krodium.json next to the manifest:

{
  "id": "com.example.notes",
  "version": "1.2.0",
  "kind": "extension"
}
  • The id is reverse-domain, lower case, such as com.example.notes. Ids starting com.krodium. or in.svayam. are reserved.
  • Versions are one to four numbers separated by dots, such as 1.2.0. Each upload needs a new version.
  • Packages can be up to 200 MB and must not be encrypted or contain unsafe file paths.
  • Ask only for the permissions you use. Broad permissions such as every website, history, cookies or native messaging are flagged for closer review.

Web apps

Give us the https address of your app and of its web app manifest. The manifest must be on the same website. We fetch it safely, check its name, start address and scope, and keep a copy of those few fields. Nothing is uploaded, and your app updates whenever your site does.

Desktop apps

Upload an installer: .dmg or .pkg for macOS, .exe or .msi for Windows, .AppImage, .deb or .rpm for Linux. Choose the platform and architecture, and give the version. Installers can be up to 500 MB. We check that the file really is what its name says, and record its SHA-256 checksum so people can verify their download. Please sign and notarise your installers with your own developer certificates.

Review guidelines

Every listing and every new version is looked at by a person. Here is what we check.

  • It does what it says. The name, description and screenshots match the product and nothing is hidden.
  • Permissions fit the purpose. If your extension asks for access it does not need, we will ask you to remove it.
  • Data is handled honestly. Your privacy policy says what you collect, where it goes and why. Nothing is sold.
  • The package is clean. No malware, no obfuscated code that hides behaviour, no code loaded from elsewhere to change what the extension does after review.
  • The listing is honest. No fake reviews, no keyword stuffing, and no use of other companies' names to suggest they back you.

We aim to review new listings within two working days. If we reject a listing you will see the reason in the console. Fix it and send it again, or reply to us at the support address in the console if you disagree.

Changing the details of a live listing, such as the description or screenshots, sends it back for review so that the page people see has always been checked. Uploading a new version of a live listing is reviewed too, and the previous approved version stays available until the new one is approved.

Policies

  • No malware, spyware, cryptomining or anything that works against the person using it.
  • No collecting or selling data that you have not clearly told people about.
  • No remote code: everything that runs must be in the package we reviewed.
  • No changing the search engine, home page or new tab page without clear, informed consent.
  • No injecting adverts into pages people did not ask to change.
  • No illegal content, hate, harassment or content that exploits children.
  • Extra care for children's, health and financial data, with a clear privacy policy.
  • Paid listings state their trial and refund terms. A free listing does not become paid without a clear new choice for people who already have it.

Breaking these rules can lead to a listing being suspended or an account being closed. The full terms are in the Developer Agreement.

Your information

Identity documents are encrypted when stored, can be opened only by Krodium reviewers, and are deleted 90 days after we decide on your account. Job applications and their CVs are encrypted in the same way.