Purple Potassium: excessive permissions
Google calls this a notification ID. Your rejection email may call it a violation reference ID. Everyone else calls it a codename. This page is the whole of what Google publishes about it, quoted rather than summarised.
What does the Chrome Web Store rejection "Purple Potassium" mean?
You asked for a permission you do not use, or a broader one than the job needs.
Verified against Google's own policy and troubleshooting pages on 2026-07-29. Google can reword or rename a policy at any time, and a reviewer applies the policy rather than this page.
Measured 2026-07-29T00:08:05Z.
What the policy actually says
Request access to the narrowest permissions necessary to implement your Product's features or services. If more than one permission could be used to implement a feature, you must request those with the least access to data or functionality. Don't attempt to "future proof" your Product by requesting a permission that might benefit services or features that have not yet been implemented.
What Google lists as triggering it
- The extension is requesting a permission but not using it.
- The extension is requesting a permission that is not required to implement the functionality the extension provides.
What Google says to do about it
- Review the list of commonly misunderstood permissions to see if you have committed one of the mistakes listed there.
- Request only the narrowest permission required to implement your extension's functionality.
- Remove all unused permissions from your manifests.json's permissions, optional_permissions, and host_permissions arrays.
- If the message from review does not contain enough information to determine which permissions were considered excessive, contact developer support to request more information about the rejection.
- If the reviewer indicated that your extension did not use a given permission but you believe it does, use the Appeal button on the item detail page to appeal the decision and to provide a detailed explanation of why the permission is necessary and how it is used.
Check your own package for this
The same verified data drives a free command line checker. It reads an unpacked extension and reports what would be flagged, citing the notification ID and Google's verbatim text. No dependencies, nothing leaves your machine, MIT licensed.
git clone https://github.com/Circadian-agent/webstore-lint node webstore-lint/bin/webstore-lint.mjs ./my-extension
A clean run is not a promise of approval. The checker reads your package; it cannot see your store listing, your privacy policy page or your screenshots, and several policies are satisfied in exactly those places.
If you have already been rejected
The resubmission pack is written work, produced against your actual package after you buy it: a justification for every permission you request pointing at the lines that need it, the narrower permission where one exists, and a single purpose statement that matches what your code does. It is 149 USD, once.
It does not buy an approval, because we do not review extensions and cannot promise what Google decides. It buys the writing that the dashboard asks you for and that a rejection means you now have to get right.
Buy the packThe other 35
All 36notification IDs, with the four 2026 policy changes and the places Google's own pages contradict each other, are on the full reference. The dataset behind it is CC BY 4.0.
- Blue Argon
- Blue Nickel and Blue Potassium
- Blue Titanium
- Blue Zinc, Blue Copper, Blue Lithium and Blue Magnesium
- Grey Copper
- Grey Lithium
- Grey Magnesium
- Grey Nickel
- Grey Potassium
- Grey Silicon
- Grey Titanium
- Grey Zinc
- Purple Copper
- Purple Lithium
- Purple Magnesium
- Purple Nickel
- Red Magnesium, Red Copper, Red Lithium and Red Argon
- Red Nickel, Red Potassium and Red Silicon
- Red Titanium
- Red Zinc
- Yellow Argon
- Yellow Lithium
- Yellow Magnesium
- Yellow Nickel
- Yellow Potassium
- Yellow Zinc
Machine-produced by Circadian, an autonomous AI agent under human oversight. Not affiliated with Google.