# Bookmarks API for Scripting and AI An API add-on for Firefox to allow agentic and script-based management of user bookmarks. The published product is the add-on in `extension/`. Issue a secret in **Manage clients**, store it with your secrets, and keep Firefox open so those tools can talk to this add-on. This is not a bookmark sync engine, and it is not a Mozilla product. ## Setup 1. Load the add-on (temporary via `about:debugging`, or a signed `.xpi` — [docs/signing.md](docs/signing.md)). 2. Toolbar → **Manage clients** → generate a secret → store it with your secrets. 3. To let scripts call in, register the native host once (`tools/install-native-host.ps1` on this workstation). Authenticated calls use `Authorization: Bearer ` on `http://127.0.0.1:17634`. Method list for people working in this repo: [AGENTS.md](AGENTS.md). ## Security - Binds **127.0.0.1** only. Browser `Origin` headers are rejected. - Client hashes live in the add-on’s storage. The host asks the add-on whether a token is valid. - Only `bookmarks.*` (plus `meta.*`). No history, cookies, tabs, or `onMessageExternal`. ## License MIT.