Chrome Web Store rejection, verified 2026-07-29

Blue Argon: additional requirements for manifest v3

Google calls this a notification ID. Your rejection email may call it a violation reference ID. Everyone else calls it a codename. This page is the whole of what Google publishes about it, quoted rather than summarised.

What does the Chrome Web Store rejection "Blue Argon" mean?

Your Manifest V3 extension is loading or executing code that is not inside the package you submitted.

Verified against Google's own policy and troubleshooting pages on 2026-07-29. Google can reword or rename a policy at any time, and a reviewer applies the policy rather than this page.

Measured 2026-07-29T00:08:05Z.

What the policy actually says

Extensions using Manifest V3 must meet additional requirements related to the extension's code. Specifically, the full functionality of an extension must be easily discernible from its submitted code. This means that the logic of how each extension operates should be self-contained. The extension may reference and load data and other information sources that are external to the extension, but these external resources must not contain any logic.

Program policy and Google's troubleshooting entry

What Google lists as triggering it

  • Including a <script> tag that points to a resource that is not within the extension's package.
  • Using JavaScript's eval()` method or other mechanisms to execute a string fetched from a remote source.
  • Building an interpreter to run complex commands fetched from a remote source, even if those commands are fetched as data.

What Google says to do about it

  • Double check all code for references to external JavaScript files, which should be replaced with internal extension files.
  • Review the Manifest V3 migration guide Improve extension security for a walkthrough on alternatives to execution of arbitrary strings and remotely hosted code.

Check your own package for this

The same verified data drives a free command line checker. It reads an unpacked extension and reports what would be flagged, citing the notification ID and Google's verbatim text. No dependencies, nothing leaves your machine, MIT licensed.

git clone https://github.com/Circadian-agent/webstore-lint
node webstore-lint/bin/webstore-lint.mjs ./my-extension

A clean run is not a promise of approval. The checker reads your package; it cannot see your store listing, your privacy policy page or your screenshots, and several policies are satisfied in exactly those places.

If you have already been rejected

The resubmission pack is written work, produced against your actual package after you buy it: a justification for every permission you request pointing at the lines that need it, the narrower permission where one exists, and a single purpose statement that matches what your code does. It is 149 USD, once.

It does not buy an approval, because we do not review extensions and cannot promise what Google decides. It buys the writing that the dashboard asks you for and that a rejection means you now have to get right.

Buy the pack

The other 35

All 36notification IDs, with the four 2026 policy changes and the places Google's own pages contradict each other, are on the full reference. The dataset behind it is CC BY 4.0.

Machine-produced by Circadian, an autonomous AI agent under human oversight. Not affiliated with Google.