ScreenshotNeo

BlogGuides

SingleFile Extension Permissions Explained: Why Does It Access All Websites?

SingleFile’s broad site access lets it process pages across tabs. Here’s what that permission allows, what the project says it does, and how to narrow access in Chrome.

By the ScreenshotNeo team4 October 20267 min read

SingleFile requests access to all websites because it is designed to save complete pages from across the web. Its FAQ says the tabs and all_urls permissions let it inject the code needed to process pages in any tab; saving several tabs in one click is one example. The permission is a broad capability grant. It does not, by itself, show that the extension sends page data to anyone.

SingleFile’s FAQ says page processing happens in the browser and that it does not upload data to third-party servers. That is the project’s stated handling, not an independent audit. Saving a page can still make network requests to download resources that are present on the page but not already displayed or cached, such as images, CSS, frames, and fonts. SingleFile FAQ

1. Why SingleFile asks for access to all websites

SingleFile’s purpose is to save a page as a self-contained HTML file, including its styling and resources. It also supports saving selected content, frames, links, and multiple tabs. To process a page, the extension needs to run code in that page’s context. Since a user may ask it to save a page on any site, its host access needs to cover sites beyond one fixed domain.

The project explains that tabs together with all_urls permits injecting the processing code into pages in any tab. The FAQ gives saving several tabs in one click as an example. This explains why broad access is relevant to the feature set; it does not mean every feature requires access to every site at every moment.

2. What the permission can allow

Mozilla describes “Access your data for all websites” as permission that could let an extension read webpage content and information entered on pages, including usernames and passwords. Treat that as a description of the capability granted by the browser. It is not evidence that a particular extension routinely reads or transmits those values. Mozilla’s explanation of Firefox permission requests

Keep two questions separate when evaluating an extension:

  • Capability: What could the browser permission enable on sites where access is granted?
  • Handling: What does the project say it does with the data it can access?

For SingleFile, the project FAQ says it performs its work in the browser and does not upload data to third-party servers. The broad permission still matters because it grants the technical ability to process page data on sites where access is allowed.

3. What the other SingleFile permissions are for

SingleFile’s FAQ maps its requested permissions to features. Browser prompts and permission categories can vary by browser and release, so check the listing and permissions for the version you installed.

Permission Purpose described by the project
identity Connect SingleFile to a Google Drive account.
storage Keep extension settings.
menus / contextMenus Add an entry to webpage context menus.
tabs and all_urls Inject code to process pages in tabs, including multi-tab saving.
downloads Save pages using the browser’s download mechanism.
clipboardWrite Copy page content to the clipboard instead of saving it.
nativeMessaging Use SingleFile Companion to save pages.

Mozilla explains that download permission can let an extension save files through the browser’s download manager and access or update download details. Access to browser tabs can expose tab details such as its URL, title, and icon. These general permission descriptions are not proof that SingleFile uses each permission for every possible purpose. Chrome Web Store’s permissions guide

4. Can you limit SingleFile to selected sites in Chrome?

Yes. Chrome lets you choose when an extension may access sites. Depending on the Chrome version, the choices are to run it when you select it, allow it on the current site, or allow it on all sites. You can also add or remove specific allowed sites in the extension’s details. Chrome Help: Install and manage extensions

  1. Open Chrome’s Extensions page and find SingleFile.
  2. Open the extension’s details.
  3. Change its site access to the narrowest option that supports your workflow.
  4. If needed, manage individual sites in the site-access controls.
  5. When using click-to-run access, select the extension on the page you want it to process.

With click-to-run access, Chrome permits access to the current site after you select the extension; closing the tab or window means you must select it again to grant access there. Current-site access allows automatic access on that site. All-sites access allows it automatically across sites. Exact menu wording can change between Chrome versions.

A narrower setting gives you more control over when the extension can access a page. It can also mean extra clicks, and workflows involving automatic access across sites or several tabs may need broader access or more user interaction. That trade-off follows from Chrome’s site-access controls and SingleFile’s documented multi-tab workflow.

5. Privacy questions: what the permission does and does not tell you

Does the permission mean SingleFile is reading everything I do online?

No conclusion about routine behavior follows from the permission prompt alone. It tells you what the browser may allow when site access is granted. The SingleFile FAQ says the extension processes pages in the browser and does not upload data to third-party servers. Consider that a statement from the project, and distinguish it from the browser’s description of the permission’s potential capability.

Does SingleFile upload pages I save?

The project FAQ says it does not upload data to third-party servers. It also explains that saving may download page resources that are present but not already displayed or cached. Downloading resources from a website to your browser is a network request, but it is different from uploading the saved page to a third-party server.

Is a browser-store recommendation proof that an extension is risk-free?

No. A store label is useful context, but it is not a guarantee that an extension is risk-free or an independent verification of every behavior in every installation. Review the permissions, the developer’s published explanations, and the site access you grant.

6. Troubleshooting site access

Symptom Likely cause What to do
SingleFile does not save the current page. Chrome has not granted site access for that page, or access is set to require an explicit click. Use the extension on the page to grant click-to-run access, or allow access on the current site in its details.
Saving across several tabs needs repeated interaction. Access is limited to selected sites or to click-to-run. Grant access to the relevant sites, or choose all-sites access if that convenience is needed.
A permission prompt differs from instructions you found. Browser labels and permission categories differ, and can change by browser or release. Check the installed version’s extension details and the current browser listing.
A saved page is missing a resource. The resource may not have been available to download, or the page may not have exposed it as expected at save time. Try loading the page fully before saving. Remember that SingleFile may download resources present but not already displayed or cached; site restrictions can also affect availability.

7. When you need a screenshot instead of a saved HTML page

SingleFile is for preserving a page as HTML. If your task is to capture a clean screenshot or PDF, ScreenshotNeo is an alternative to try first: it removes cookie and consent banners, newsletter popups, and chat widgets before capture, and only clean shots are billed. Its API can return PNG, JPEG, WebP, or PDF; the parameter names used by other screenshot APIs also work. The code examples and options are in the ScreenshotNeo documentation.

Or skip the browser setup

One GET request can capture a URL. Replace YOUR_API_KEY with your key:

curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
    timeout=90,
)
open("shot.webp", "wb").write(r.content)
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
  • Cookie banners, popups, and chat widgets are removed before the shot; each cleanup step can be turned off.
  • Bot checks, blank pages, timeouts, failed loads, and cache hits cost nothing. Responses identify the page verdict and billing status in headers.
  • An MCP server gives AI agents tools for screenshots, page information, and PDF capture.
  • 1,000 screenshots a month are free with no card; paid plans start at $5 for 3,000 screenshots.

Start with 1,000 free screenshots a month—no card required.

8. Frequently asked questions

Can I grant access only when I save a page?

In Chrome, choose the option to run the extension when you select it. You may need to grant access again when you use it on another page or after closing the tab or window.

Does limiting site access remove SingleFile’s permissions permanently?

Chrome’s site-access setting controls where the extension can use its host permissions. You can change the setting and manage allowed sites in the extension details.

Where can I see SingleFile’s explanation for its permissions?

See the project FAQ and the extension listing for your browser. Firefox’s listing is at Firefox Add-ons.