Files
bookmarks-api/docs/signing.md
T

2.6 KiB

Signing for Firefox Release

Firefox Release and Beta will only keep an add-on that Mozilla has signed. Temporary add-ons from about:debugging die on restart. Developer Edition / Nightly can load unsigned builds if xpinstall.signatures.required is false — do not rely on that for this workstation.

Mozilla signs through addons.mozilla.org even when the add-on is not listed in the store.

1. AMO developer account

  1. Register at addons.mozilla.org (Mozilla account).
  2. Open API credentials.
  3. Generate a JWT issuer (user:…) and secret.
  4. Store both in Vaultwarden. Never commit them. Env names WEB_EXT_API_KEY / WEB_EXT_API_SECRET (or AMO_JWT_ISSUER / AMO_JWT_SECRET if you prefer wrappers).

2. Choose a channel

Channel What you get
unlisted Signed .xpi for self-install. Not on the AMO store. Enough to survive Firefox restarts. Start here.
listed Public AMO listing, automatic updates via Firefox. Needs listing metadata, review, and Add-on Policy compliance. Do this when you want strangers to find it.

Unlisted submissions can still be pulled for manual review. Native messaging is allowed; be ready to explain that the HTTP listener is the native host, bind is loopback-only, and the extension does not accept onMessageExternal.

3. Sign (unlisted)

From this repo, with Node + web-ext 8+:

npm install -g web-ext
cd extension
web-ext sign --channel=unlisted --api-key $env:WEB_EXT_API_KEY --api-secret $env:WEB_EXT_API_SECRET

The gecko id in manifest.json (firefox-agent-bridge@easygoingaming.com) must stay stable. Bump version for every new sign.

web-ext writes a signed .xpi under web-ext-artifacts/. Install it in Firefox: the .xpi file, or about:addons → gear → Install Add-on From File.

Keep the native host registered (tools/install-native-host.ps1). Signing replaces only the extension; the host is unchanged.

4. Updates

Bump version, sign again on the same channel and id. For unlisted self-distribution, updates need an update_url in browser_specific_settings.gecko if you want Firefox to auto-fetch. Until that exists, drop in a new .xpi by hand.

5. Listed (later)

web-ext sign --channel=listed plus an AMO metadata JSON (name, summary, license MIT). Expect listing copy that says: local scripts only, loopback HTTP, bearer token, bookmarks allowlist. Do not claim it is a general Firefox remote-control tool.