Use the browser.webRequest API to observe and analyze traffic and to intercept, block, or modify requests in-flight.

Permissions: webRequest

Not allowed in: Content scripts, Devtools pages

_BlockingResponseAuthCredentials
_CertificateInfoFingerprint
_CertificateInfoSubjectPublicKeyInfoDigest
_CertificateInfoValidity
_GetSecurityInfoOptions
_HttpHeaders
_OnAuthRequiredDetails
_OnAuthRequiredDetailsChallenger
_OnBeforeRedirectDetails
_OnBeforeRequestDetails
_OnBeforeRequestDetailsRequestBody
_OnBeforeSendHeadersDetails
_OnCompletedDetails
_OnErrorOccurredDetails
_OnHeadersReceivedDetails
_OnResponseStartedDetails
_OnSendHeadersDetails
_StreamFilterOndataEvent
_WebRequestOnAuthRequiredEvent
_WebRequestOnBeforeRedirectEvent
_WebRequestOnBeforeRequestEvent
_WebRequestOnBeforeSendHeadersEvent
_WebRequestOnCompletedEvent
_WebRequestOnErrorOccurredEvent
_WebRequestOnHeadersReceivedEvent
_WebRequestOnResponseStartedEvent
_WebRequestOnSendHeadersEvent
BlockingResponse
CertificateInfo
RequestFilter
SecurityInfo
StreamFilter
UploadData
UrlClassification
_SecurityInfoOverridableErrorCategory
_SecurityInfoProtocolVersion
_SecurityInfoState
_StreamFilterStatus
CertificateTransparencyStatus
HttpHeaders
OnAuthRequiredOptions
OnBeforeRedirectOptions
OnBeforeRequestOptions
OnBeforeSendHeadersOptions
OnCompletedOptions
OnHeadersReceivedOptions
OnResponseStartedOptions
OnSendHeadersOptions
ResourceType
TransportWeaknessReasons
UrlClassificationFlags
UrlClassificationParty
MAX_HANDLER_BEHAVIOR_CHANGED_CALLS_PER_10_MINUTES
onAuthRequired
onBeforeRedirect
onBeforeRequest
onBeforeSendHeaders
onCompleted
onErrorOccurred
onHeadersReceived
onResponseStarted
onSendHeaders
filterResponseData
getSecurityInfo
handlerBehaviorChanged
_SecurityInfoOverridableErrorCategory:
    | "trust_error"
    | "domain_mismatch"
    | "expired_or_not_yet_valid"

The type of certificate error that was overridden for this connection, if any.

_SecurityInfoProtocolVersion:
    | "TLSv1"
    | "TLSv1.1"
    | "TLSv1.2"
    | "TLSv1.3"
    | "unknown"

Protocol version if state is "secure"

_SecurityInfoState: "insecure" | "weak" | "broken" | "secure"
_StreamFilterStatus:
    | "uninitialized"
    | "transferringdata"
    | "finishedtransferringdata"
    | "suspended"
    | "closed"
    | "disconnected"
    | "failed"

Describes the current status of the stream.

CertificateTransparencyStatus:
    | "not_applicable"
    | "policy_compliant"
    | "policy_not_enough_scts"
    | "policy_not_diverse_scts"
HttpHeaders: _HttpHeaders[]

An array of HTTP headers. Each header is represented as a dictionary containing the keys name and either value or binaryValue.

OnAuthRequiredOptions: "responseHeaders" | "blocking" | "asyncBlocking"
OnBeforeRedirectOptions: "responseHeaders"
OnBeforeRequestOptions: "blocking" | "requestBody"
OnBeforeSendHeadersOptions: "requestHeaders" | "blocking"
OnCompletedOptions: "responseHeaders"
OnHeadersReceivedOptions: "blocking" | "responseHeaders"
OnResponseStartedOptions: "responseHeaders"
OnSendHeadersOptions: "requestHeaders"
ResourceType:
    | "main_frame"
    | "sub_frame"
    | "stylesheet"
    | "script"
    | "image"
    | "object"
    | "object_subrequest"
    | "xmlhttprequest"
    | "xslt"
    | "ping"
    | "beacon"
    | "xml_dtd"
    | "font"
    | "media"
    | "websocket"
    | "csp_report"
    | "imageset"
    | "web_manifest"
    | "speculative"
    | "other"
TransportWeaknessReasons: "cipher"
UrlClassificationFlags:
    | "fingerprinting"
    | "fingerprinting_content"
    | "cryptomining"
    | "cryptomining_content"
    | "emailtracking"
    | "emailtracking_content"
    | "tracking"
    | "tracking_ad"
    | "tracking_analytics"
    | "tracking_social"
    | "tracking_content"
    | "any_basic_tracking"
    | "any_strict_tracking"
    | "any_social_tracking"

Tracking flags that match our internal tracking classification

UrlClassificationParty: UrlClassificationFlags[]

If the request has been classified this is an array of UrlClassificationFlags.

MAX_HANDLER_BEHAVIOR_CHANGED_CALLS_PER_10_MINUTES: number

The maximum number of times that handlerBehaviorChanged can be called per 10 minute sustained interval. handlerBehaviorChanged is an expensive function call that shouldn't be called often.

Fired when an authentication failure is received. The listener has three options: it can provide authentication credentials, it can cancel the request and display the error page, or it can take no action on the challenge. If bad user credentials are provided, this may be called multiple times for the same request.

If "blocking" is specified in the "extraInfoSpec" parameter, the event listener should return an object of this type.

Fired when a server-initiated redirect is about to occur.

Fired when a request is about to occur.

If "blocking" is specified in the "extraInfoSpec" parameter, the event listener should return an object of this type.

Fired before sending an HTTP request, once the request headers are available. This may occur after a TCP connection is made to the server, but before any HTTP data is sent.

If "blocking" is specified in the "extraInfoSpec" parameter, the event listener should return an object of this type.

Fired when a request is completed.

Fired when an error occurs.

Fired when HTTP response headers of a request have been received.

If "blocking" is specified in the "extraInfoSpec" parameter, the event listener should return an object of this type.

Fired when the first byte of the response body is received. For HTTP requests, this means that the status line and response headers are available.

Fired just before a request is going to be sent to the server (modifications of previous onBeforeSendHeaders callbacks are visible by the time onSendHeaders is fired).

  • ...

    Parameters

    • requestId: string

    Returns StreamFilter

  • Retrieves the security information for the request. Returns a promise that will resolve to a SecurityInfo object.

    Parameters

    Returns Promise<SecurityInfo>

  • Needs to be called when the behavior of the webRequest handlers has changed to prevent incorrect handling due to caching. This function call is expensive. Don't call it often.

    Returns Promise<void>