From 0281b3d93460d5f9b87c90a969ade0d75d52d1e8 Mon Sep 17 00:00:00 2001
From: akxue <18199652+akxue@users.noreply.github.com>
Date: Wed, 7 Oct 2026 17:43:20 +0000
Subject: [PATCH 1/5] Document DeveloperToolsAvailability for enterprise policy
extensions
---
browsers/chrome-policies.mdx | 34 ++++++++++++++++++++++++++++++++++
browsers/extensions.mdx | 4 ++++
2 files changed, 38 insertions(+)
diff --git a/browsers/chrome-policies.mdx b/browsers/chrome-policies.mdx
index 8bee12ca..e3582eae 100644
--- a/browsers/chrome-policies.mdx
+++ b/browsers/chrome-policies.mdx
@@ -272,6 +272,40 @@ const browser = await kernel.browsers.create({
```
+### Inspect enterprise policy extensions with DevTools
+
+[Extensions that require enterprise policies](/browsers/extensions#extensions-requiring-enterprise-policies), such as ones using `webRequestBlocking`, are force-installed by Chrome. Chrome blocks DevTools and CDP on force-installed extensions by default, so you can't open DevTools on the extension or attach to its service worker. Set `DeveloperToolsAvailability` to `1` to allow it:
+
+
+```python Python
+from kernel import Kernel
+
+kernel = Kernel()
+
+browser = kernel.browsers.create(
+ extensions=[{"name": "request-signer"}],
+ chrome_policy={
+ "DeveloperToolsAvailability": 1,
+ },
+)
+```
+
+```typescript Typescript/Javascript
+import Kernel from '@onkernel/sdk';
+
+const kernel = new Kernel();
+
+const browser = await kernel.browsers.create({
+ extensions: [{ name: 'request-signer' }],
+ chrome_policy: {
+ DeveloperToolsAvailability: 1,
+ },
+});
+```
+
+
+This applies to every force-installed extension in the browser. Anyone with access to the browser, including live view users, can then inspect the extension's code and storage. Kernel only accepts `0` (Chrome's default) and `1`, because `2` turns off DevTools everywhere, which also disconnects CDP.
+
### Restrict navigation to specific URLs
To lock a browser to an approved set of URLs, block everything with `URLBlocklist` and then allow back only the URLs you want with `URLAllowlist`. Entries match a whole domain (`chatgpt.com`) or a specific path (`en.wikipedia.org/wiki/Cat`), and more specific entries take precedence. This gates top-level navigation, so any other URL returns `ERR_BLOCKED_BY_ADMINISTRATOR`; it does not block resources or API calls a permitted page loads from other origins.
diff --git a/browsers/extensions.mdx b/browsers/extensions.mdx
index db419a0f..1c8b94d3 100644
--- a/browsers/extensions.mdx
+++ b/browsers/extensions.mdx
@@ -184,3 +184,7 @@ Once you successfully upload an enterprise policy extension, Kernel handles the
5. **Installation** - Chrome installs the extension via enterprise policy when the browser starts
No additional HTTP server or manual policy configuration is needed. The extension works seamlessly in any browser session that it's uploaded to.
+
+### Debugging with DevTools
+
+Chrome blocks DevTools and CDP on extensions installed through enterprise policy. To inspect your extension, set `DeveloperToolsAvailability` to `1` in `chrome_policy`. See [Inspect enterprise policy extensions with DevTools](/browsers/chrome-policies#inspect-enterprise-policy-extensions-with-devtools).
From 8f3c737ba72f219e8b5b4b28f6510746a50ca329 Mon Sep 17 00:00:00 2001
From: akxue <18199652+akxue@users.noreply.github.com>
Date: Thu, 8 Oct 2026 20:56:08 +0000
Subject: [PATCH 2/5] Move extension DevTools docs into a debugging section
---
browsers/chrome-policies.mdx | 34 ++---------------------------
browsers/extensions.mdx | 42 ++++++++++++++++++++++++++++++++----
2 files changed, 40 insertions(+), 36 deletions(-)
diff --git a/browsers/chrome-policies.mdx b/browsers/chrome-policies.mdx
index e3582eae..9d118530 100644
--- a/browsers/chrome-policies.mdx
+++ b/browsers/chrome-policies.mdx
@@ -272,39 +272,9 @@ const browser = await kernel.browsers.create({
```
-### Inspect enterprise policy extensions with DevTools
+### Debug extensions that use `webRequestBlocking`
-[Extensions that require enterprise policies](/browsers/extensions#extensions-requiring-enterprise-policies), such as ones using `webRequestBlocking`, are force-installed by Chrome. Chrome blocks DevTools and CDP on force-installed extensions by default, so you can't open DevTools on the extension or attach to its service worker. Set `DeveloperToolsAvailability` to `1` to allow it:
-
-
-```python Python
-from kernel import Kernel
-
-kernel = Kernel()
-
-browser = kernel.browsers.create(
- extensions=[{"name": "request-signer"}],
- chrome_policy={
- "DeveloperToolsAvailability": 1,
- },
-)
-```
-
-```typescript Typescript/Javascript
-import Kernel from '@onkernel/sdk';
-
-const kernel = new Kernel();
-
-const browser = await kernel.browsers.create({
- extensions: [{ name: 'request-signer' }],
- chrome_policy: {
- DeveloperToolsAvailability: 1,
- },
-});
-```
-
-
-This applies to every force-installed extension in the browser. Anyone with access to the browser, including live view users, can then inspect the extension's code and storage. Kernel only accepts `0` (Chrome's default) and `1`, because `2` turns off DevTools everywhere, which also disconnects CDP.
+Chrome blocks DevTools on extensions that use `webRequestBlocking`. Set `DeveloperToolsAvailability` to `1` to allow it. See [Debugging your extensions](/browsers/extensions#debugging-your-extensions).
### Restrict navigation to specific URLs
diff --git a/browsers/extensions.mdx b/browsers/extensions.mdx
index 1c8b94d3..e0e49ef7 100644
--- a/browsers/extensions.mdx
+++ b/browsers/extensions.mdx
@@ -134,6 +134,44 @@ kernel browsers extensions upload ./my-extension
Loading an extension triggers a Chromium restart, which takes several seconds and may disrupt active CDP connections.
+## Debugging your extensions
+
+You can open DevTools on your extension or attach to its service worker over CDP to read its console, set breakpoints, and inspect its storage. This works by default for most extensions.
+
+### Extensions that use `webRequestBlocking`
+
+Chrome only grants `webRequestBlocking` to extensions installed through enterprise policy, so Kernel [installs these extensions that way](#extensions-requiring-enterprise-policies). Chrome blocks DevTools on those extensions by default. To allow it, set `DeveloperToolsAvailability` to `1` in [`chrome_policy`](/browsers/chrome-policies) when you create the browser or pool:
+
+
+```python Python
+from kernel import Kernel
+
+kernel = Kernel()
+
+browser = kernel.browsers.create(
+ extensions=[{"name": "request-signer"}],
+ chrome_policy={
+ "DeveloperToolsAvailability": 1,
+ },
+)
+```
+
+```typescript Typescript/Javascript
+import Kernel from '@onkernel/sdk';
+
+const kernel = new Kernel();
+
+const browser = await kernel.browsers.create({
+ extensions: [{ name: 'request-signer' }],
+ chrome_policy: {
+ DeveloperToolsAvailability: 1,
+ },
+});
+```
+
+
+This applies to every extension Kernel installed this way in that browser. Anyone with access to the browser, including live view users, can then inspect those extensions' code and storage. Kernel rejects `2` because it turns off DevTools everywhere, including the CDP connection Kernel uses to control the browser.
+
## Extensions requiring enterprise policies
For a complete list of available extension settings and policies, refer to the [Chrome Enterprise Policy documentation](https://chromeenterprise.google/policies/extension-settings/).
@@ -184,7 +222,3 @@ Once you successfully upload an enterprise policy extension, Kernel handles the
5. **Installation** - Chrome installs the extension via enterprise policy when the browser starts
No additional HTTP server or manual policy configuration is needed. The extension works seamlessly in any browser session that it's uploaded to.
-
-### Debugging with DevTools
-
-Chrome blocks DevTools and CDP on extensions installed through enterprise policy. To inspect your extension, set `DeveloperToolsAvailability` to `1` in `chrome_policy`. See [Inspect enterprise policy extensions with DevTools](/browsers/chrome-policies#inspect-enterprise-policy-extensions-with-devtools).
From 64beaa888a3a89e6a880aa8ce7b91345716ea370 Mon Sep 17 00:00:00 2001
From: akxue <18199652+akxue@users.noreply.github.com>
Date: Thu, 8 Oct 2026 21:05:46 +0000
Subject: [PATCH 3/5] Frame extension DevTools docs around enterprise policy
---
browsers/chrome-policies.mdx | 4 ++--
browsers/extensions.mdx | 6 +++---
2 files changed, 5 insertions(+), 5 deletions(-)
diff --git a/browsers/chrome-policies.mdx b/browsers/chrome-policies.mdx
index 9d118530..f8eab730 100644
--- a/browsers/chrome-policies.mdx
+++ b/browsers/chrome-policies.mdx
@@ -272,9 +272,9 @@ const browser = await kernel.browsers.create({
```
-### Debug extensions that use `webRequestBlocking`
+### Debug extensions added through enterprise policy
-Chrome blocks DevTools on extensions that use `webRequestBlocking`. Set `DeveloperToolsAvailability` to `1` to allow it. See [Debugging your extensions](/browsers/extensions#debugging-your-extensions).
+Chrome blocks DevTools on extensions added through enterprise policy, which Kernel uses for extensions that request `webRequest` or `webRequestBlocking`. Set `DeveloperToolsAvailability` to `1` to allow it. See [Debugging extensions added through enterprise policy](/browsers/extensions#debugging-extensions-added-through-enterprise-policy).
### Restrict navigation to specific URLs
diff --git a/browsers/extensions.mdx b/browsers/extensions.mdx
index e0e49ef7..755888bc 100644
--- a/browsers/extensions.mdx
+++ b/browsers/extensions.mdx
@@ -138,9 +138,9 @@ Loading an extension triggers a Chromium restart, which takes several seconds an
You can open DevTools on your extension or attach to its service worker over CDP to read its console, set breakpoints, and inspect its storage. This works by default for most extensions.
-### Extensions that use `webRequestBlocking`
+### Debugging extensions added through enterprise policy
-Chrome only grants `webRequestBlocking` to extensions installed through enterprise policy, so Kernel [installs these extensions that way](#extensions-requiring-enterprise-policies). Chrome blocks DevTools on those extensions by default. To allow it, set `DeveloperToolsAvailability` to `1` in [`chrome_policy`](/browsers/chrome-policies) when you create the browser or pool:
+Kernel adds your extension through enterprise policy when its manifest requests `webRequest` or `webRequestBlocking` and the upload includes `update.xml` and a `.crx` (see [Extensions requiring enterprise policies](#extensions-requiring-enterprise-policies)). Chrome blocks DevTools on extensions added this way by default. To allow it, set `DeveloperToolsAvailability` to `1` in [`chrome_policy`](/browsers/chrome-policies) when you create the browser or pool:
```python Python
@@ -170,7 +170,7 @@ const browser = await kernel.browsers.create({
```
-This applies to every extension Kernel installed this way in that browser. Anyone with access to the browser, including live view users, can then inspect those extensions' code and storage. Kernel rejects `2` because it turns off DevTools everywhere, including the CDP connection Kernel uses to control the browser.
+This applies to every extension added through enterprise policy in that browser. Anyone with access to the browser, including live view users, can then inspect those extensions' code and storage. Kernel rejects `2` because it turns off DevTools everywhere, including the CDP connection Kernel uses to control the browser.
## Extensions requiring enterprise policies
From 1b8602cf7e7bc3da5e4a8d8755ec971793967f6d Mon Sep 17 00:00:00 2001
From: akxue <18199652+akxue@users.noreply.github.com>
Date: Thu, 8 Oct 2026 21:09:49 +0000
Subject: [PATCH 4/5] Move enterprise policy DevTools docs under the enterprise
policy section
---
browsers/chrome-policies.mdx | 2 +-
browsers/extensions.mdx | 70 +++++++++++++++++++-----------------
2 files changed, 38 insertions(+), 34 deletions(-)
diff --git a/browsers/chrome-policies.mdx b/browsers/chrome-policies.mdx
index f8eab730..70d37d89 100644
--- a/browsers/chrome-policies.mdx
+++ b/browsers/chrome-policies.mdx
@@ -274,7 +274,7 @@ const browser = await kernel.browsers.create({
### Debug extensions added through enterprise policy
-Chrome blocks DevTools on extensions added through enterprise policy, which Kernel uses for extensions that request `webRequest` or `webRequestBlocking`. Set `DeveloperToolsAvailability` to `1` to allow it. See [Debugging extensions added through enterprise policy](/browsers/extensions#debugging-extensions-added-through-enterprise-policy).
+Chrome blocks DevTools on extensions added through enterprise policy, which Kernel uses for extensions that request `webRequest` or `webRequestBlocking`. Set `DeveloperToolsAvailability` to `1` to allow it. See [Debugging with DevTools](/browsers/extensions#debugging-with-devtools).
### Restrict navigation to specific URLs
diff --git a/browsers/extensions.mdx b/browsers/extensions.mdx
index 755888bc..40d4eea2 100644
--- a/browsers/extensions.mdx
+++ b/browsers/extensions.mdx
@@ -138,39 +138,9 @@ Loading an extension triggers a Chromium restart, which takes several seconds an
You can open DevTools on your extension or attach to its service worker over CDP to read its console, set breakpoints, and inspect its storage. This works by default for most extensions.
-### Debugging extensions added through enterprise policy
-
-Kernel adds your extension through enterprise policy when its manifest requests `webRequest` or `webRequestBlocking` and the upload includes `update.xml` and a `.crx` (see [Extensions requiring enterprise policies](#extensions-requiring-enterprise-policies)). Chrome blocks DevTools on extensions added this way by default. To allow it, set `DeveloperToolsAvailability` to `1` in [`chrome_policy`](/browsers/chrome-policies) when you create the browser or pool:
-
-
-```python Python
-from kernel import Kernel
-
-kernel = Kernel()
-
-browser = kernel.browsers.create(
- extensions=[{"name": "request-signer"}],
- chrome_policy={
- "DeveloperToolsAvailability": 1,
- },
-)
-```
-
-```typescript Typescript/Javascript
-import Kernel from '@onkernel/sdk';
-
-const kernel = new Kernel();
-
-const browser = await kernel.browsers.create({
- extensions: [{ name: 'request-signer' }],
- chrome_policy: {
- DeveloperToolsAvailability: 1,
- },
-});
-```
-
-
-This applies to every extension added through enterprise policy in that browser. Anyone with access to the browser, including live view users, can then inspect those extensions' code and storage. Kernel rejects `2` because it turns off DevTools everywhere, including the CDP connection Kernel uses to control the browser.
+
+If Kernel added your extension through enterprise policy, Chrome blocks DevTools on it by default. See [Debugging with DevTools](#debugging-with-devtools) to allow it.
+
## Extensions requiring enterprise policies
@@ -222,3 +192,37 @@ Once you successfully upload an enterprise policy extension, Kernel handles the
5. **Installation** - Chrome installs the extension via enterprise policy when the browser starts
No additional HTTP server or manual policy configuration is needed. The extension works seamlessly in any browser session that it's uploaded to.
+
+### Debugging with DevTools
+
+Chrome blocks DevTools on extensions added through enterprise policy by default. To allow it, set `DeveloperToolsAvailability` to `1` in [`chrome_policy`](/browsers/chrome-policies) when you create the browser or pool:
+
+
+```python Python
+from kernel import Kernel
+
+kernel = Kernel()
+
+browser = kernel.browsers.create(
+ extensions=[{"name": "request-signer"}],
+ chrome_policy={
+ "DeveloperToolsAvailability": 1,
+ },
+)
+```
+
+```typescript Typescript/Javascript
+import Kernel from '@onkernel/sdk';
+
+const kernel = new Kernel();
+
+const browser = await kernel.browsers.create({
+ extensions: [{ name: 'request-signer' }],
+ chrome_policy: {
+ DeveloperToolsAvailability: 1,
+ },
+});
+```
+
+
+This applies to every extension added through enterprise policy in that browser. Anyone with access to the browser, including live view users, can then inspect those extensions' code and storage. Kernel rejects `2` because it turns off DevTools everywhere, including the CDP connection Kernel uses to control the browser.
From a850f1cc2401ddcf7b885540329993bbe6012d9c Mon Sep 17 00:00:00 2001
From: Anna Wang
Date: Thu, 8 Oct 2026 14:57:24 -0700
Subject: [PATCH 5/5] Apply suggestion from @AnnaXWang
---
browsers/chrome-policies.mdx | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/browsers/chrome-policies.mdx b/browsers/chrome-policies.mdx
index 70d37d89..dab93ac9 100644
--- a/browsers/chrome-policies.mdx
+++ b/browsers/chrome-policies.mdx
@@ -274,7 +274,7 @@ const browser = await kernel.browsers.create({
### Debug extensions added through enterprise policy
-Chrome blocks DevTools on extensions added through enterprise policy, which Kernel uses for extensions that request `webRequest` or `webRequestBlocking`. Set `DeveloperToolsAvailability` to `1` to allow it. See [Debugging with DevTools](/browsers/extensions#debugging-with-devtools).
+Chrome blocks DevTools by default on extensions added through enterprise policy, which Kernel uses for extensions that request `webRequest` or `webRequestBlocking`. Set `DeveloperToolsAvailability` to `1` to enable it. See [Debugging with DevTools](/browsers/extensions#debugging-with-devtools).
### Restrict navigation to specific URLs