Documentation Index
Fetch the complete documentation index at: https://docs.velatir.com/llms.txt
Use this file to discover all available pages before exploring further.
Overview
Deploy the Velatir browser extension to managed devices with pre-configured settings. Pick a deployment method below; the browser support and configuration reference follow underneath.Deployment methods
Choose the path that matches your platform and tooling. The MSI is the recommended route for Windows fleets.Windows MSI (recommended)
Intune, SCCM, or any tool that runs an MSI. Per-machine (HKLM) and per-user (HKCU) packages, plus the optional directory-context host.
Alternative Windows methods
PowerShell script, manual registry, and Intune Settings Catalog. Also covers Vivaldi and Brave.
macOS (Jamf / MDM)
A single .mobileconfig profile for Chrome, Edge, Firefox, Vivaldi, Brave, and ChatGPT Atlas.
Vendor-managed & other browsers
Island, Prisma Access, Surf, and browsers without a policy surface.
Extension Details
| Browser | Extension ID | Store Link |
|---|---|---|
| Chrome | bbiokppljpbjgiogcoggjnfffbeiihja | Chrome Web Store |
| Edge | phgnjcoglpdamjjmidheehacjbkgkooc | Edge Add-ons |
| Firefox | velatir@velatir.com | Firefox Add-ons |
| Vivaldi | bbiokppljpbjgiogcoggjnfffbeiihja | Chrome Web Store (same listing as Chrome) |
| Brave | bbiokppljpbjgiogcoggjnfffbeiihja | Chrome Web Store (same listing as Chrome) |
| ChatGPT Atlas (macOS) | bbiokppljpbjgiogcoggjnfffbeiihja | Chrome Web Store (same listing as Chrome) |
Supported Browsers
Velatir’s deployment methods cover every browser that publishes an enterprise policy surface. Where a browser does not yet expose one, the relevant limitation is called out inline.| Browser | Deployment | Policy location |
|---|---|---|
| Chrome | MSI / GPO / mobileconfig | HKLM\SOFTWARE\Policies\Google\Chrome / com.google.Chrome |
| Edge | MSI / GPO / mobileconfig | HKLM\SOFTWARE\Policies\Microsoft\Edge / com.microsoft.Edge |
| Firefox | MSI / GPO / mobileconfig | HKLM\SOFTWARE\Policies\Mozilla\Firefox / org.mozilla.firefox |
| Vivaldi | MSI / GPO / mobileconfig | HKLM\SOFTWARE\Policies\Vivaldi / com.vivaldi.Vivaldi |
| Brave | MSI / GPO / mobileconfig | HKLM\SOFTWARE\Policies\BraveSoftware\Brave / com.brave.Browser |
| ChatGPT Atlas | mobileconfig (macOS only) | com.openai.atlas.web |
| Island Browser | Vendor console | Details |
| Prisma Access Browser (formerly Talon) | Vendor console | Details |
| Surf Security | Vendor console | Details |
| Perplexity Comet | Manual install | Details |
| Arc | Manual install | Details |
| Dia | Manual install | Details |
| Opera / Opera GX | Manual install | Details |
Managed Configuration
The extension accepts configuration via managed storage:| Property | Type | Description |
|---|---|---|
apiToken | string | Your Velatir API key |
organizationName | string | Display name shown in the extension |
Additional properties (
endpoint, organizationId, enabledServices) are available for advanced configurations. Contact support if you need these.Directory Context (optional)
The Windows MSI ships with an optional native messaging host that attaches each signed-in user’s department, office, OU hierarchy, and group memberships from Active Directory or Microsoft Entra ID to every trace. AddENABLE_LDAP_HOST=1 to the MSI command line to install it alongside the extension.
See Directory Context for the admin consent step in Entra, the single-machine verification, and what does (and does not) get sent.
Vendor-managed browsers (Island, Prisma Access, Surf)
Enterprise browsers ship their own management plane and do not honour host-OS Chromium policy registry keys or managed-preference plists for extension force-install. The Velatir extension can still be force-installed and pre-configured, but the configuration lives in each vendor’s admin console rather than in the MSI or.mobileconfig.
For all three browsers, paste these values into the vendor’s extension policy field:
| Field | Value |
|---|---|
| Extension ID | bbiokppljpbjgiogcoggjnfffbeiihja |
| Update URL | https://clients2.google.com/service/update2/crx |
| Managed-storage JSON | {"apiToken":"vltr_yourApiTokenHere","organizationName":"Your Organization"} |
Island Browser
- Sign in to the Island admin console
- Go to Device Management > Extensions > Extension Policy
- Add a new policy, paste the extension ID above, and set installation mode to Force-installed
- In the extension configuration field, paste the managed-storage JSON
- Scope the policy to your user / device groups
Prisma Access Browser (formerly Talon)
Talon Cyber Security was acquired by Palo Alto Networks in December 2023 and the browser is now sold as Prisma Access Browser. Extension management is administered from Strata Cloud Manager.- Sign in to Strata Cloud Manager
- Open the Prisma Access Browser policy profile you want to scope this to
- Under Manage Extensions / Configure Extensions, allow
bbiokppljpbjgiogcoggjnfffbeiihjaand set it to force-install from the Chrome Web Store update URL - Paste the managed-storage JSON into the extension’s configuration field
Palo Alto documents a Windows registry root at
HKLM\Software\Policies\Palo Alto Networks\PrismaAccessBrowser for policies like SSO, but does not publish a registry path for ExtensionInstallForcelist. Extension force-install must go through Strata Cloud Manager.Surf Security
- Sign in to the Surf admin console
- Open the extension management section
- Add
bbiokppljpbjgiogcoggjnfffbeiihjaas a force-installed extension - Provide the managed-storage JSON in the extension configuration field
Browsers without an enterprise policy surface
These browsers do not publish a policy framework that can force-install an extension. The extension still works — users install it manually from the Chrome Web Store and enter the API token from the extension popup the first time it opens.- Arc (The Browser Company) — Arc documents only a small set of Arc-specific feature toggles via a user-local plist. There is no Chromium-style
ExtensionInstallForcelistsurface. With Arc in maintenance mode, this is unlikely to change. - Dia (The Browser Company) — Dia’s for-work page advertises support for “standard Chromium enterprise policies” but the company has not yet published the registry path, preference domain, or any policy key list. When they publish a policy reference, we will add Dia to the MSI / mobileconfig.
- Perplexity Comet — Perplexity advertises 500+ Chromium policies via MDM but has not published the registry root. Admins who need centralised configuration can request the enterprise admin guide directly from Perplexity.
- Opera / Opera GX — Opera does not honour Chromium policy registry keys or managed-preference plists. Users on Opera install via Opera’s “Install Chrome Extensions” add-on and complete the API token from the extension popup.
- Open the Chrome Web Store listing for Velatir
- Click Add to browser
- Open the Velatir popup and enter the API token + organisation name
Verification
Windows
- Trigger an Intune sync on the device or wait for the scheduled check-in
- Verify policies are applied:
- Chrome: Navigate to
chrome://policyand click Reload policies - Edge: Navigate to
edge://policyand click Reload policies - Firefox: Navigate to
about:policies - Vivaldi: Navigate to
vivaldi://policyand click Reload policies - Brave: Navigate to
brave://policyand click Reload policies
- Chrome: Navigate to
- Verify you see:
- Chrome / Edge / Vivaldi / Brave:
ExtensionInstallForcelistwith the Velatir extension ID, and your configuredapiTokenandorganizationName - Firefox:
ExtensionSettingscontainingvelatir@velatir.comwithforce_installedmode
- Chrome / Edge / Vivaldi / Brave:
- Confirm the extension is installed:
- Chrome:
chrome://extensions - Edge:
edge://extensions - Firefox:
about:addons(should show “Installed by enterprise policy”) - Vivaldi:
vivaldi://extensions - Brave:
brave://extensions
- Chrome:
macOS
- After the Jamf profile deploys, verify the plist files exist:
- Check the applied settings:
- Verify policies in the browser:
- Chrome:
chrome://policy - Edge:
edge://policy - Firefox:
about:policies - Vivaldi:
vivaldi://policy - Brave:
brave://policy - ChatGPT Atlas: open the extensions page from the Atlas menu and confirm Velatir is present
- Chrome:
- Confirm the extension is installed:
- Chrome:
chrome://extensions - Edge:
edge://extensions - Firefox:
about:addons - Vivaldi:
vivaldi://extensions - Brave:
brave://extensions - ChatGPT Atlas: extensions panel in the Atlas menu
- Chrome:
Troubleshooting
Extension not installing
- Windows: Verify the device has synced with Intune. Check Devices > Monitor > Device configuration status
- macOS: Verify the configuration profile is installed under System Settings > Privacy & Security > Profiles
- Firefox (macOS): Ensure
EnterprisePoliciesEnabledis set totruein the plist. Firefox ignores all policies without it. - Ensure the browser is installed before the policy applies
- Check the browser’s policy page for errors (
chrome://policy,edge://policy, orabout:policiesfor Firefox)
Configuration not appearing
- Windows: Verify the script is running in 64-bit PowerShell with administrator / SYSTEM privileges
- macOS: Check that the preference domain matches exactly (
com.google.Chrome,com.microsoft.Edge, ororg.mozilla.firefox) - Firefox (Windows): If using
policies.json, check that the file exists atC:\Program Files\Mozilla Firefox\distribution\policies.json. Firefox updates can remove this directory. - Restart the browser after policy changes
Policy conflicts (Windows)
If multiple Intune profiles configureExtensionInstallForcelist, they may conflict. Use the MSI or the PowerShell script instead of the Settings Catalog to avoid this issue, as both write to a high-numbered value name (1000) that does not collide with MDM-managed entries.
32-bit vs 64-bit context (Windows)
Registry changes may be written toWOW6432Node if the script runs in 32-bit context. Always run the configuration and uninstall scripts in 64-bit PowerShell.
Browser Extension Overview
General extension features and manual installation
Get API Token
Set up your Velatir account and get an API token