Last updated 15 September 2026

Extension permissions

Chrome shows a list of permissions when you install Hushgate. Here is what each one is for, in plain words.

proxy

Routes Chrome's traffic through the Hushgate server you choose, and restores your normal connection when you disconnect.

webRequest and webRequestAuthProvider

Answers the sign-in challenge from our own proxy server with your short-lived session credentials. Hushgate ignores challenges from any other server.

declarativeNetRequest

Powers the kill switch, which blocks Chrome from loading pages if the tunnel drops, and Threat Protection, which blocks known malware, ad and tracker domains using lists packaged inside the extension. Chrome does the matching on your device; nothing about the pages you visit is sent to us.

privacy

Turns on WebRTC leak protection while you are connected so web apps cannot discover your real IP address.

scripting

Adds small scripts to pages only while location matching is on, so sites that ask for your location or time zone see your server's city instead of yours.

storage

Saves your settings and your current sign-in on your device.

alarms

Checks the connection every minute, renews your session before it expires and ends a pause on time.

notifications

Tells you when protection drops, recovers or needs you to sign in again. You can turn these off in Settings.

Access to all sites (<all_urls>)

Required for the proxy and kill switch to apply to every website. Hushgate does not read page content or browsing history.