Skip to main content

Preconfiguring the app URL

Administrators who manage Chrome for their organization can push the Passwd app URL to the extension through enterprise policy, so employees no longer have to be told the address by hand.

On first run the extension configures itself from the policy and takes the user straight to the Google sign-in screen for that workspace — the app URL screen is skipped, because you already answered it. The user only presses Sign in with Google.

The policy does not sign anyone in, and it never changes an app URL a user already has.

This works in Chromium-based browsers. Firefox ignores extension policy.

How it works​

Read these rules before rolling the policy out to your organization.

  • It applies on a fresh install. The first time the popup is opened, the extension resolves the policy value, configures itself against that workspace, and shows the Google sign-in screen. A loader appears while the workspace is being contacted.
  • An app URL already stored in the extension always wins. The policy is read only while the extension has no app URL configured. Applying or changing a policy never signs an existing user out or moves them to another workspace.
  • Signing out does not re-arm the policy. The app URL is deliberately kept across a sign-out, so a user who signs out stays pointed at their own workspace rather than being asked for an address again. To make the policy apply a second time, clear the extension's storage or reinstall it.
  • The workspace is never a dead end. Switch workspace on the Google sign-in screen leads back to the choice screen, where the default Passwd workspace and manual URL entry both still work. Once a user picks their own workspace, the policy no longer overrides it.
  • An unreachable workspace fails quietly. If the workspace cannot be contacted — offline, or a wrong address — nothing is configured and no error is shown. The user gets the normal choice screen, with the workspace field under Use custom URL prefilled with your policy value so they can retry with one click. The next time the popup is opened, the extension tries again.

Changing the policy while the popup is open takes effect the next time the popup is opened.

What to set​

The policy has a single key.

KeyTypeRequired
customAppUrlstringno

Three value shapes are accepted.

ValueResolves to
companyhttps://company.passwd.team
company.passwd.teamhttps://company.passwd.team
https://passwd.company.comhttps://passwd.company.com

A bare workspace name gets .passwd.team appended. Anything containing a dot, slash, or colon is treated as a host or a full URL and used as given, so custom domains work.

A value that cannot be resolved to a URL — an empty string, or a stray space — is treated as no policy at all, and no error is shown to the user.

Not sure which address to use? Find out here.

Finding your extension ID​

Policy is addressed per extension ID, so you have to configure the ID of the build your users actually have installed.

To read it yourself, open chrome://extensions, enable Developer mode, and read the ID under the Passwd entry. This is always correct, including after a store listing changes.

For reference, the Chrome Web Store build has the ID mnngnbmkiabhobdmeolcnjidongapoba.

Setting the policy​

In the examples below, replace <extension-id> with the ID from the previous section, and company.passwd.team with your own app URL.

Google Admin console​

Go to Devices → Chrome → Apps & extensions → Users & browsers, select the Passwd extension, then under Policy for extensions paste:

{
"customAppUrl": { "Value": "company.passwd.team" }
}

Windows​

Create a string value named customAppUrl under this registry key, either directly or through Group Policy:

HKLM\Software\Policies\Google\Chrome\3rdparty\extensions\<extension-id>\policy

macOS​

Deliver an MDM configuration profile. macOS accepts two shapes and Chrome reads both — pick one.

A preference domain of its own per extension, com.google.Chrome.extensions.<extension-id>, holding the key at the top level:

<key>customAppUrl</key>
<string>company.passwd.team</string>

Or the older nested shape, delivered in a com.google.Chrome profile:

<key>3rdparty</key>
<dict>
<key>extensions</key>
<dict>
<key><extension-id></key>
<dict>
<key>customAppUrl</key>
<string>company.passwd.team</string>
</dict>
</dict>
</dict>

If a profile looks correct but chrome://policy shows nothing under your extension ID, check whether the value went into the other shape's file.

Linux​

Create /etc/opt/chrome/policies/managed/passwd.json:

{
"3rdparty": {
"extensions": {
"<extension-id>": {
"customAppUrl": "company.passwd.team"
}
}
}
}

Verifying​

  1. Open chrome://policy and press Reload policies.
  2. Find the section for your extension ID. customAppUrl should be listed with your value and status OK. A status of not a valid policy means the key name is wrong or the value is not a string.
  3. Open the extension popup. It should show the Google sign-in screen with your workspace hostname under Workspace, without asking for an app URL.

Troubleshooting​

note

The policy is read only while the extension has no app URL configured, and signing out does not clear it. To test the policy, use a fresh browser profile or a freshly installed extension.

Step 2 shows your value, but the popup lands on the choice screen. Either the extension already had an app URL configured, in which case the policy was never read at all — test again in a fresh profile — or the workspace could not be reached. In the second case Use custom URL will have the value prefilled, and pressing Continue shows the underlying error.

The Google sign-in screen appears, but for the wrong workspace. The extension had an app URL configured before the policy was applied. A stored app URL takes precedence, and signing out does not clear it.

Nothing appears under your extension ID at chrome://policy. The ID is probably wrong — confirm it at chrome://extensions with Developer mode enabled. On macOS, also check that the value did not go into the other configuration-profile shape.