DocsSecurity

Browser extension

ShareShield 4.0 closed a hole in how the browser extension got its API key. Here is what changed, what it means for an extension you already use, and what replaces it.

Removed in
4.0
Affects
/extension/auth key handoff
Existing installs
Keep their key, on API v1
Replacement
OAuth sign-in, later release
On this page
  1. In short
  2. What changed in 4.0
  3. Why it was removed
  4. Existing installs
  5. Sign-in with OAuth

In short

  • The 3.x API-key handoff page for the extension, /extension/auth, was removed in 4.0 as a security fix.
  • An extension that is already connected keeps working with the key it holds, for now (see below).
  • A new install, or reconnecting an existing one, can't get a key until the extension signs in with an interactive OAuth flow, which is coming in a later release.

What changed in 4.0

In 3.x the extension connected to your account through a handoff page in the app: the extension opened /extension/auth, and the app created a new API key and passed it back to the extension. 4.0 removes that page and the handoff entirely. It is not deprecated or hidden; it is gone.

Why it was removed

So an extension that wasn't ShareShield's, including one written to look like it, could ask for a key and get one, and then use the API as you. An API key is a long-lived credential, and it should never go to a caller the app can't identify.

That hole is closed: 4.0 issues no keys to extensions at all. Its replacement is meant to fix the underlying design rather than patch it: with OAuth, you sign in to ShareShield yourself, interactively, instead of a key being handed to whoever asks.

Existing installs

A key an extension already holds is an ordinary API key. It keeps working until it expires or is revoked, with two things to know:

  • When 3.x keys were migrated to 4.0 they were given every scope and bound to your oldest organisation. Like every key, it stops working if you leave that organisation.
  • Existing installs call the deprecated v1 API. Their keys work through v1 only until v1 is removed, which is planned 60 days after the 4.0 release.

You can see and revoke your keys under Dashboard → Profile → API keys, and organisation admins can revoke any key in the organisation. If you don't recognise a key, or connected an extension you aren't sure about, revoke it.

Sign-in with OAuth

The extension's sign-in is moving to an interactive OAuth flow, in a later release than 4.0. You'll sign in to ShareShield yourself, rather than the app handing a key to whichever extension asks for one. Until then there is nothing to set up.

To build your own integration in the meantime, use an API key you create yourself, with only the scopes it needs. See Integrations and the API reference.