reference
Architecture
UI routes, the single bridge, the API router, services, and sacred adapters.
The extension is one direction of calls, with the background holding authority.
src/ui/app/routes/*
-> bridge.send(method, params)
src/background/api-router.js
-> auth + contract + dispatch
src/background/services/*
-> adapters
src/lib/vault.js
src/lib/thru-client.js
src/lib/networks.jsUI route stack
Fourteen routes share the kit, the router, the modal, and the focus trap: welcome, unlock, dashboard, accounts, account, add-account, keyring, export, send, receive, faucet, history, settings, reset.
Bridge
The UI does not call chrome.runtime.sendMessage except through the bridge. BigInt values are stringified before the port. The router names the method and field path if a payload cannot be serialized.
API router
The manifest is the allowlist. Auth tiers include password and signing. tx.registerAccount is the narrow unlocked-only signing exception, and only for an exact vault-owned address. The pending v13 step adds a second, equally narrow one: a faucet claim is an incoming credit, so it is unlocked-only too.
Networks
networks.js is the only place an RPC URL, explorer URL, or program address is allowed to live, and anything stored that is meaningful on one chain only is namespaced by network id. Betanet is the one enabled entry; localnet, testnet, and mainnet are declared and disabled so the storage-scoping machinery has something to exercise. A build check fails if the enabled list and the manifest's connect-src ever disagree.
Sacred files
Do not casually edit src/lib/vault.js, src/lib/thru-client.js, or src/lib/networks.js. Derivation has golden tests. The betanet release had to touch thru-client.js for the 0.4.x package shapes and the betanet move — the rename of ALPHANET_RPC to BETANET_RPC is the one intentional export change, and the PDA vectors stayed pinned. Program addresses now come from the managed-genesis registry in @thru/programs rather than from reverse-engineered marker bytes, so a redeployment lands as a version bump instead of a pasted string.
Website
This site is not the extension. Product copy lives in src/content/. The Postgres desk stores field notes and smoke-check marks. It does not store secrets, and it is not a wallet backend.