# Thru Wallet > An experimental, self-custody browser extension for Thru's native Layer 1 betanet. Chrome Web Store: https://chromewebstore.google.com/detail/thru-wallet/ocahgpmgfeapjnceaknkikanjikhjgok Extension id: ocahgpmgfeapjnceaknkikanjikhjgok Listing: 1.4.1 · updated 2026-10-04 · 272 KiB · 5 permissions · betanet Store state: 1.4.1 live on the Chrome Web Store since 2026-10-04. It is the same build as source release v1.4.1. Verified against the live page on 2026-10-04 Extension source: https://github.com/buildbyravi/thru-wallet-ext Website source: https://github.com/buildbyravi/thru-wallet-web Privacy: https://github.com/buildbyravi/thru-wallet-ext/blob/main/PRIVACY.md Not production-ready and not security-reviewed. Use betanet testnet funds only. This is community software, not affiliated with or endorsed by Unto Labs. Do not use it with real financial value. ## Source release (extension main branch) - Tag v1.4.1, released 2026-10-03, merge commit cee006e from PR #16 - Contract v15, 83 methods - 14 routes, popup 400px, 0 DOM sinks - Vault: PBKDF2-SHA256 · 600,000, AES-256-GCM - Packages @thru/sdk@0.4.1 and @thru/programs@0.4.1, network betanet (https://rpc.betanet.thru.org) - Permissions: storage, alarms, sidePanel, clipboardRead, notifications - Suite at release: 20 suites · 1,641 assertions - Read from the extension repository at cee006e: package 1.4.1, contract v15 with 83 declared methods, @thru packages at 0.4.1, and a CSP whose only connect-src is the betanet RPC. Merged 2026-10-03, tagged the same minute, published to the store the next day. ## Audited status document (behind both) - docs/STATUS_AND_ROADMAP.md still says contract v12, 81 methods, audited 2026-09-26 at 4aa55ba - The published package and the code both run contract v15 with 83 methods. Prefer src/ over the document ## Not verified - 0 of 36 rows ticked in docs/MANUAL_SMOKE_CHECKLIST.md as of 2026-10-04 (95 individual checks) - Published on 2026-10-04, one day after merge, on automated evidence alone (20 suites · 1,641 assertions) ## Incoming contract (open, not merged) - Contract v16, 81 methods (-2 from v15), on the stacked chain #17 then #18 - Removes tx.send and token.transfer; 19 source files change; package version stays 1.4.1 - Merging it closes the documentation gap and opens a different one. main would describe contract v16 while the package in the Chrome Web Store is contract v15 — and the chain does not bump the package number, so both would be called 1.4.1. A build from main after the merge would answer to the same version string as the store build while speaking a different contract. The fix is a version bump in the same change that merges the chain. - Do not describe v16 as shipped. It is not on main and not in the store ## Do not - Request or reveal a seed, private key, or password - Invent window.thru or an extension provider contract - Treat unverified chain behavior as measured - Collapse the artifacts. The store serves 1.4.1 and main is release v1.4.1 — the same build since 2026-10-04 — but the status document still says v12 and 0 of 36 manual smoke rows are ticked - Report a published package as a verified one, or the status document as current - Quote the released build's inactivity-based auto-lock as something an installed extension does today ## Read - /docs/overview - /docs/installation - /docs/security-model - /docs/ai-and-mcp - /llms-full.txt - https://thru.org/docs/llm.txt - https://scan.thru.org/api/mcp ## Routes - `/welcome` — First-run create or import - `/unlock` — Password unlock - `/dashboard` — Balances and primary actions - `/accounts` — Account list, pin, hide, order - `/account` — Single-account detail - `/add-account` — Derive or import another account - `/keyring` — Keyring management - `/export` — Password-gated secret export - `/send` — Native or token send, then review - `/receive` — Address and QR - `/faucet` — Betanet faucet claim - `/history` — Decoded activity stream - `/settings` — Network, lock, window, security - `/reset` — Destroy the local vault ## Features - [STABLE] Wallet Core: Create and import wallets — Generate a recovery phrase, import an existing phrase, or import a private key. Key material is created locally. The extension does not ask a page, agent, or remote service to hold it. - [STABLE] Wallet Core: Multiple accounts, one wallet — Derive further HD accounts from a seed keyring. A private-key-only vault cannot derive new accounts — that limit is intentional, not a missing button. - [STABLE] Wallet Core: Multi-seed keyring vault — Several seed and private-key keyrings can sit side by side. Labels, the active account, and keyring metadata stay in the background, not in the page. - [STABLE] Wallet Core: Password-encrypted local storage — PBKDF2 with 600,000 SHA-256 iterations, then AES-256-GCM. Ciphertext lives in chrome.storage.local. Decrypted vault data lives only in chrome.storage.session and is wiped when the browser session ends. - [STABLE] Wallet Core: Configurable auto-lock — Default is 15 minutes, user-configurable from 0 to 240, and changing it is password-gated. 1.4.1 stamps every API request and locks on measured idleness, so background sync no longer counts as activity. It is the first packaged build whose behavior matches the listing's inactivity-lock wording — 1.2.0 ran a fixed-period alarm under that same sentence. - [NEW] Wallet Core: Lock on demand — 1.4.1 adds an explicit lock button in Settings and a Ctrl+L shortcut, so clearing decrypted keys does not mean waiting out the timer or closing the browser. The store listing advertises the shortcut. - [NEW] Wallet Core: Security posture, computed not promised — 1.4.1 replaces the dashboard's coming-soon security tile with checks derived from state the background already owns: signing re-auth, auto-lock window, keyring origin, backup state. A value that cannot be read says unknown instead of grading itself. - [STABLE] Daily Use: Balances in human-scale THRU — 1 THRU = 1e9 base units. The human amount is primary. Raw units stay visible underneath so a faucet credit of 10000 base units cannot be mistaken for 10000 THRU. - [STABLE] Daily Use: Account creation and faucet claims — Create the on-chain account and claim from the faucet where the active network supports one. Betanet's faucet is a managed program whose vault credited 10,000 base units on the reset chain. Contract v13 drops the signing-password demand from a claim: an incoming credit is not a spend. - [STABLE] Daily Use: Native sends and decoded history — Review precedes send. History is one flat stream: a known time comes from the containing block, otherwise the row shows Block instead of an invented date. No per-card fee line is shipped. 1.4.1 refreshes the feed every 30 seconds while it is open, which the listing now advertises as live auto-sync. - [NEW] Daily Use: Repeat-transfer detection — Contract v15 adds tx.checkDuplicate: the same recipient and amount inside 30 seconds, or still in flight, is caught before signing. v1.4.1 moved the tracking to submission time, so the Repeated Transaction card covers the whole pending window, and the send proceeds only with an explicit allowDuplicate the backend enforces. - [NEW] Daily Use: Desktop notifications — 1.4.1 posts a native notification when a transaction confirms or fails, so a closed popup is not a blind spot. It is the fifth manifest permission, it is a Settings toggle, and the message carries no amount, address, or signature. - [STABLE] Daily Use: Popup and side panel, mutually exclusive — The shared page is 400px in the toolbar popup. Side Panel Mode is an explicit Settings choice and calls chrome.sidePanel.open() from a user gesture. It never calls setPanelBehavior, so the toolbar icon still opens the popup. - [ALPHA] Daily Use: Receive address and QR — The receive route shows the address and a canvas QR. Explorer links point at scan.thru.org and carry ?network=betanet. Canvas paint, clipboard prompts, and the exact explorer path are still manual browser checks. - [ALPHA] Daily Use: Account pin, hide, and order — Labels, hiding, pinning, and ordering are part of the shipped account routes. Contacts CRUD on top of the contacts.* backend is still a follow-up screen, not a promised address book. - [ALPHA] Token Work: Token balances, honestly — token.getBalances reads official @thru/programs/token bindings. A missing token account is a proven zero. A failed read is unknown — never a fabricated 0. Decimals come from the mint when a balance exists. - [NEW] Token Work: Token drawer from the balance box — 1.4.1 makes the whole balance box the token entry: click it, press Enter, or use the token strip and a drawer slides up with the full list and a live search. The inline dashboard token ledger is gone rather than duplicated. - [NEW] Token Work: Custom tokens, verified on-chain — Contract v14 adds token.readMint, so a pasted contract address is read from the chain and the mint's own symbol and decimals are used. Free-typed metadata is what made an added token burn the wrong number of base units. - [ALPHA] Token Work: Token transfer, live probe open — token.transfer shipped in contract v8 with signing auth. A missing recipient token account can be initialized by the sender in a preceding transaction. Whether a never-registered owner can receive, and the token-program fee, are still unmeasured. - [PLANNED] Token Work: Contacts — Backend contact methods exist. A full contacts screen is not the current product surface. Arbitrary contacts are never registered on-chain by the v12 just-in-time path. - [PLANNED] Future Modules: Local wallet MCP companion — A future companion may read permitted non-secret state and prepare intents. It must not receive a seed, password, or private key, and it must not sign or broadcast on its own. - [PLANNED] Future Modules: Isolated launchpad, DEX, prediction — The legacy surface was deleted, not hidden. A return is only allowed as a new feature module with verified program semantics, guarded DOM, and its own tests. Nothing of that kind ships today. - [PLANNED] Future Modules: No injected dApp provider — Thru's documented wallet is the hosted iframe, not an extension provider. This project will not invent window.thru or copy connect(), getSigningContext(), and signTransaction() into a browser injection. ## Gaps - Run the browser smoke checklist for popup and side-panel layout, focus, canvas QR, clipboard, desktop notifications, and worker eviction. - The published 1.4.1 package has no recorded manual verification. All 36 rows of docs/MANUAL_SMOKE_CHECKLIST.md are unticked — 95 individual checks once popup and side panel are counted separately — and the build reached the store one day after merging on automated evidence alone. Users are the first browser run. - The repository's own docs/STATUS_AND_ROADMAP.md still describes contract v12 with 81 methods at 4aa55ba. Main is contract v15 with 83. A rewrite is written and mergeable on the open #17 to #18 chain, where the document describes v16 — so the fix for the stale document arrives attached to another contract change. - The v16 chain changes the contract without changing the package number. If it merges as-is, a build from main calls itself 1.4.1 and speaks contract v16, while the 1.4.1 in the Chrome Web Store speaks v15. Two different builds would answer to one version string. - The changes freshest to the package are the ones no browser has confirmed: duplicate detection across the whole pending window, desktop notification delivery, and the dark-mode action grid, drawer ledger, and connection footer. - Betanet itself is unaudited infrastructure and Thru's last testnet before mainnet. A 1-base-unit transfer fee was measured once, on one amount and one size. - Live v12 activation — multi-account creation and owned-recipient just-in-time registration — still needs a safe network-reachable pass. - Token transfer code is shipped; the token-program fee and never-registered owner case are not yet measured. The pending token lab exercises deploy, add, send, and receive, but on a chain nobody has certified. - Custom networks stay quarantined until HTTPS policy, narrow host permission, capability records, and password re-auth ship together. - No injected dApp provider. Do not invent window.thru. - Launchpad, DEX, and prediction UI are deleted. Future work belongs in isolated feature modules. ## Roadmap - 01 [open] Verify the package a real user can install — 1.4.1 is live on the Chrome Web Store as of 2026-10-04 and every row of docs/MANUAL_SMOKE_CHECKLIST.md is still unticked. Install the published package from the store — not a local dist/ — and run the 36 rows against it. Start with what is newest: duplicate detection while a transfer is still pending, desktop notification delivery and its Settings toggle, popup and side-panel mutual exclusion, and the dark-mode action grid, drawer ledger, and connection footer. - 02 [open] Merge the v16 chain with a package bump — Pull requests #17 and #18 are stacked and mergeable, and they carry contract v16: tx.send and token.transfer are retired, 19 source files change, a storage-migrations suite is added, and docs/STATUS_AND_ROADMAP.md is finally rewritten to describe the code. What the chain does not do is bump the package number. Merging it as-is leaves main describing contract v16 under the same 1.4.1 string the store serves as contract v15. Bump the version in the same change. - 03 [open] Live v12 activation pass — Create several HD accounts on betanet and exercise send just-in-time registration for an owned, absent recipient. Confirm the target signer and offline-versus-absent handling. - 04 [open] Token transfer and token lab live probe — Measure the token-program fee and whether a sender-initialized token account can target a never-registered owner. The pending scripts/token-lab.mjs walks deploy, add, send, and receive — a live run is still the evidence, not the script's existence. Use a throwaway wallet. Do not guess the fee in the UI. - 05 [open] Betanet block time and explorer confirmation — Betanet is documented at roughly six-second blocks, so a transfer should settle in about one block. Confirm block-time availability through the RPC, first-load latency, whether an authoritative fee exists outside the current detail call, and that the ?network=betanet explorer links resolve. - 06 [blocked] Custom network re-enable — Keep activation disabled until HTTPS policy, narrow host permission, per-network capability records, and password re-auth land together. Localnet was removed from the shipped wallet for exactly this reason. Removing a legacy record is already allowed. - 07 [blocked] Provider contract watch — Do not inject a browser provider until Thru publishes, and this project validates, an extension-compatible contract covering discovery, permission, approval, signing ownership, and submission. ## MCP policy Explorer MCP: https://scan.thru.org/api/mcp Protocol: https://thru.org/docs/llm.txt A future local wallet MCP may read permitted non-secret state and prepare intents. It must never receive secrets, sign directly, broadcast directly, or mutate security settings. Allowed: - wallet_get_public_accounts - wallet_get_balances - wallet_get_assets - wallet_get_activity - wallet_get_networks - wallet_get_capabilities Protected: - wallet_prepare_native_send - wallet_prepare_token_transfer - wallet_prepare_swap — only after real Thru-native swap support exists - wallet_prepare_launchpad_create — only after verified launchpad semantics exist Forbidden: - Mnemonic or private-key export - Password access - Direct signing or direct broadcast - Reset wallet or security-setting mutation - Raw decrypted vault access or arbitrary chrome.storage access Read first: - AGENTS.md — rules, commands, traps, reporting. - docs/DOCS_INDEX.md — documentation map. - docs/PROJECT_LEDGER.md — past, present, and future identifiers. - docs/STATUS_AND_ROADMAP.md — audited baseline and open checks. Verify its version numbers against src/shared/contract/manifest.js before quoting them. - extension.md — the Chrome Web Store listing copy, its permission justifications, and the listing changelog. - CONTEXT.md — file-by-file repository map. - docs/MCP_AGENT_INTEGRATION.md — safe companion plan. - https://thru.org/docs/llm.txt — official protocol entry point. - /llms.txt on this site — short website context, including the store link. ## Changelog ### 1.4.1 · 2026-10-04 · Live on the Chrome Web Store Package 1.4.1 was approved and published. For the first time since this site started tracking it, the store build and the source tree are the same build. - Listing now reads 1.4.1, updated 2026-10-04, 272 KiB, with five screenshots and a linked developer website at thruwallet.vercel.app. It replaced 1.2.0 from 2026-09-23, which was 209 KiB. - The description was replaced along with the package: betanet rather than alphanet, plus the token drawer, verified custom tokens by contract address, live 30-second activity auto-sync, desktop notifications, and Ctrl+L. - The Offered by PWNX0 row is no longer shown on the listing page, so this site no longer asserts a publisher name. - Auto-lock is the one claim that used to be wrong in both directions: the listing had always advertised an inactivity lock while 1.2.0 ran a fixed-period alarm. 1.4.1 is the first package where the behavior and the sentence match. - Published one day after the source release — merged 2026-10-03 as cee006e, tagged v1.4.1, approved 2026-10-04. Submission, merge, and publication stayed three separate events to the end. - Unchanged: docs/STATUS_AND_ROADMAP.md still claims contract v12 with 81 methods, and all 36 rows of docs/MANUAL_SMOKE_CHECKLIST.md are still unticked. ### 1.4.1 · 2026-10-03 · Merged and released — the betanet build is tagged v1.4.1 PR #16 merged into main as cee006e and shipped as GitHub release v1.4.1. The source is betanet now; the store package is not. - Merged at 13:56 UTC and tagged thirteen seconds later, carrying Design System v2, betanet, @thru 0.4.1, the token drawer, chain-verified custom tokens, desktop notifications, and the send hardening pass. - Numbered 1.4.1 rather than 1.4.0 because 1.4.0 was submitted to the store and never published, so no released version is skipped. - Contract v15 with 83 declared methods is what main exports. This site reads its source facts from cee006e. - Gate at merge: 20 suites and 1,641 assertions green, plus the CI build-and-test job. - Still not installable from the store. The listing serves 1.2.0 until someone uploads the 1.4.1 package and a reviewer approves it. - docs/STATUS_AND_ROADMAP.md was not touched by the merge and still claims contract v12 with 81 methods at 4aa55ba. ### 1.4.0 · 2026-10-03 · Submitted to the Chrome Web Store — never published The betanet package is with Chrome's reviewers. Submitted is not published: the listing keeps serving 1.2.0 until a reviewer approves, and the public page is the only thing this site treats as proof. - Package 1.4.0 submitted with the rewritten betanet description and the fifth permission, notifications, justified in the dashboard. - The live listing page re-read on 2026-10-03 still reports 1.2.0, 2026-09-23, 209 KiB — unchanged, as expected during review. - Source side: PR #16 is in final review at 9086b22, with @thru/sdk and @thru/programs synced to 0.4.1. - This site tracks submission and merge as two separate events, because a rejection moves one without the other. ### site · 2026-10-02 · Three clocks: store build, source baseline, pending 1.4.0 The extension's betanet work is reviewed and CI-green on an open pull request, so this site now tracks it as a third, clearly separate object instead of folding it into either shipped artifact. - Pending release block records PR #16 at 1338380: package 1.4.0, contract v15, 83 methods, @thru 0.4.0, betanet RPC. - Chrome Web Store facts re-verified against the live listing on 2026-10-02 and left at 1.2.0 / 2026-09-23 / 209 KiB. - Alphanet wording replaced with betanet where the project's target chain is meant, and kept where the shipped package is meant. - Auto-lock copy corrected: the pending build measures real inactivity, so the old 'the source says fixed-period alarm' gap is retired on merge, not before. ### 1.4.0 · 2026-10-02 · Betanet migration, token drawer, desktop notifications — pending Package 1.4.0 exists as reviewed source on an open pull request. It is not merged to main and it is not what Chrome installs today. - Betanet is the default and only enabled network: rpc.betanet.thru.org, explorer links carry ?network=betanet, and the CSP connect-src allows nothing else. - Program addresses come from @thru/programs 0.4.0 managed-genesis registry instead of the reverse-engineered marker-byte addresses the 2026-09-26 chain reset deleted. - The balance box is the token entry: click it and a sliding drawer lists tokens, searches, and adds a custom token by contract address after the chain supplies symbol and decimals. - Optional desktop notifications on transaction confirm or fail, which is the fifth manifest permission and a Settings toggle. - Auto-lock now measures real inactivity, the faucet no longer demands a signing password, and a repeat transfer inside 30 seconds is detected before it is signed. - Localnet is gone from the shipped wallet and the manifest homepage points at thruwallet.vercel.app. - Packages tracked the chain twice: 0.3.16 to 0.4.0 for the managed-genesis reset, then a 0.4.1 sync at 9086b22. ### v13 → v15 · 2026-10-02 · Contract moves to v15, 83 methods Three contract steps ride with the pending package: one deliberate behavior break and two additive reads. Append-only discipline holds for everything else. - v13 modifies tx.claimFaucet: auth drops from signing to unlocked and the vestigial password param leaves the declaration. Old callers that still send one are ignored, not rejected. - v14 appends token.readMint so a pasted contract address is verified on-chain before a custom token joins the ledger. - v15 appends tx.checkDuplicate for repeat transfers inside 30 seconds or still in flight, plus an optional allowDuplicate on the send methods. - Method count moves 81 → 83. The UI-to-background agreement is still enforced in both directions by test-contract.mjs. ### site · 2026-09-26 · Dossier site, with the store as the install path This website now leads with the Chrome Web Store listing and keeps source install, docs, and the v12 status baseline in the same dossier. - Chrome Web Store link on the header, homepage, install page, footer, llms.txt, and catalog API. - Listing facts recorded beside the source baseline so the two versions are not collapsed into one. - Docs hub, architecture flow, security principles, agent policy, and a Postgres-backed desk ledger. ### v12 · 2026-09-26 · Status baseline: contract v12, 81 methods The extension status document, audited at commit 4aa55ba, is the source baseline this site describes. It is newer than the packaged listing. - tx.registerAccount for an exact vault-owned address, unlocked-only, no value transfer. - tx.getCachedHistory for cache-first History paint, scoped by network and address. - Send review waits for just-in-time activation and shows the matched recipient label as display-only. - Signing password re-auth remains opt-in. The default is session signing while unlocked. ### 1.2.0 · 2026-09-23 · Chrome Web Store listing Thru Wallet is listed as an experimental self-custody wallet for Thru alphanet. Version 1.2.0, 209 KiB, offered by PWNX0. - Store id ocahgpmgfeapjnceaknkikanjikhjgok. - Disclosed privacy posture: data is not collected. Policy lives in the extension repository. - Listing copy mentions a 15-minute lock. The source describes that timer as a fixed-period alarm, not inactivity detection. - The listing is explicit: not affiliated with Unto Labs, and not for real financial value. ### v8 · 2026-09-18 · Token transfer shipped in code Token methods sit on official @thru/programs/token bindings. Live fee and recipient-owner questions stayed open on purpose. - token.transfer uses signing auth and mint units, never THRU units. - A missing recipient token account can be initialized by the sender first. - Failed balance reads stay unknown. They are not rendered as zero. ### v7 · 2026-09-18 · Custom networks quarantined Settings no longer offers Add custom network. The background also refuses activation, including direct API calls and stale storage. - network.setActive accepts enabled built-ins only. - A custom id returns CUSTOM_NETWORK_DISABLED. - Legacy rows remain visible so they can be removed. ### v6 · 2026-09-18 · Reset and auto-lock hardened Destructive and security-timer changes are enforced in the background, not only by the form that triggered them. - Reset requires confirmation and an unlocked-wallet password check. - Auto-lock changes are password-gated. - Generic settings writes reject security-sensitive keys. ## Docs ## Doc: Overview (/overview) Thru Wallet is an experimental Chrome extension for personal key management and basic account operations on Thru's native Layer 1 betanet. It is unofficial, self-custody, and deliberately narrower than a general dApp wallet. > Not production-ready. Not security-reviewed. Not affiliated with Unto Labs. Betanet testnet funds only. ## Install The packaged extension is listed on the Chrome Web Store: - Listing: [Thru Wallet](https://chromewebstore.google.com/detail/thru-wallet/ocahgpmgfeapjnceaknkikanjikhjgok) - Extension id: `ocahgpmgfeapjnceaknkikanjikhjgok` - Listing version: **1.4.1**, updated 2026-10-04, 272 KiB, five permissions — verified against the live page on 2026-10-04 - Same build as source release **v1.4.1**, merged as `cee006e` on 2026-10-03 and published to the store a day later - Not verified: all 36 rows of `docs/MANUAL_SMOKE_CHECKLIST.md` are unticked — 95 individual checks, since most rows are run twice for popup and side panel - Source: [buildbyravi/thru-wallet-ext](https://github.com/buildbyravi/thru-wallet-ext) - This site: [buildbyravi/thru-wallet-web](https://github.com/buildbyravi/thru-wallet-web) Use the store unless you are auditing or rebuilding. The full steps live on the [install page](/install) and in [Installation](/docs/installation). ## What it is for - Create, import, lock, and unlock a local vault. - Hold multiple keyrings and accounts. - Read a THRU balance with raw units still visible. - Create an on-chain account, claim a faucet where the network supports one, and send native THRU after review. - Show a receive address and QR, plus decoded history when the shape is known. - Read token balances and prepare token transfers on official program bindings, with live questions still open. ## What it is not Thru's own wallet architecture is an embedded, iframe-hosted wallet. There is no published standard yet for third-party extensions to plug into dApps built with Thru's SDKs. This project does **not** inject `window.thru`. Rabby, MetaMask, Phantom, and Keplr are UX references only. Thru is not EVM. ## Three artifacts, not one | | Chrome Web Store | Source `main` | Audited status doc | | --- | --- | --- | --- | | Version | **1.4.1**, 2026-10-04 | **1.4.1**, released 2026-10-03 | describes `4aa55ba`, 2026-09-26 | | Commit | built from `cee006e` | `cee006e` (PR #16 merged) | `4aa55ba` | | Contract | v15, 83 methods | v15, 83 methods | claims v12, 81 methods | | Packages | @thru 0.4.1 | @thru 0.4.1 | @thru 0.3.16 | | Network | betanet RPC | betanet RPC, nothing else in CSP | alphanet RPC | | Permissions | 5, adding `notifications` | 5, adding `notifications` | 4 | | State | what Chrome installs today | what the source builds | **behind both** | The first two columns finally agree. The betanet work merged on 2026-10-03 as [v1.4.1](https://github.com/buildbyravi/thru-wallet-ext/releases/tag/v1.4.1) and was published to the store on 2026-10-04 — package **1.4.0 had been submitted the day before and was never published**, which is why the release carries the 1.4.1 number. Submission, merge, and publication stayed three separate events, and this site only moved its listing facts when the public page moved. What the agreement does not include is verification: **0 of 36** rows in `docs/MANUAL_SMOKE_CHECKLIST.md` are ticked — **95** individual checks counting popup and side panel separately. The package reached users one day after merge on 20 automated suites and no recorded manual run. It also does not last. Contract **v16** is written on the stacked, mergeable chain [#17](https://github.com/buildbyravi/thru-wallet-ext/pull/17) → [#18](https://github.com/buildbyravi/thru-wallet-ext/pull/18): it retires `tx.send` and `token.transfer`, taking 83 methods down to 81, and rewrites the status document to match. The chain does not bump the package number, so merging it as-is would leave `main` describing contract v16 under the same **1.4.1** string the store serves as contract v15. Shared by all three: 14 routes, one popup stack, a 400px popup, 0 DOM sinks with the ratchet closed, and a vault built on PBKDF2-SHA256 at 600,000 rounds then AES-256-GCM. Say which artifact you mean. "Thru Wallet supports betanet" is true of the package Chrome installs today and of the source; "Thru Wallet is verified on betanet" is true of neither. ## The chain moved underneath the store build The extension repository records a managed-genesis reset on 2026-09-26: the single-node alphanet is gone, betanet is Thru's final testnet before mainnet, and the old reverse-engineered program addresses no longer exist on-chain. The published 1.4.1 package points at the betanet RPC and nothing else: `connect-src` allows one origin. The alphanet-era 1.2.0 package left the install path on 2026-10-04. Building from `main` at `cee006e` gets you the same wallet the store serves. ## Doc: Installation (/installation) Two paths. Most people should take the first. ## Chrome Web Store 1. Open the listing: [Thru Wallet on the Chrome Web Store](https://chromewebstore.google.com/detail/thru-wallet/ocahgpmgfeapjnceaknkikanjikhjgok). 2. Confirm the extension id `ocahgpmgfeapjnceaknkikanjikhjgok`, the developer website `thruwallet.vercel.app`, and version **1.4.1**. 3. Add it to Chrome. Pin it. The first run offers to create or import a wallet. 4. Read the [privacy policy](https://github.com/buildbyravi/thru-wallet-ext/blob/main/PRIVACY.md). The developer discloses that the item does not collect or use your data. The listing is community software. It is not an Unto Labs product and it has not been audited. > The packaged 1.4.1 build targets betanet, which replaced the reset alphanet on 2026-09-26. It is the same code as release v1.4.1, merged as `cee006e`. Build from source if you want to audit it or patch it; otherwise the store package is the same thing. ## Load unpacked For a checkout you can read: ```bash git clone https://github.com/buildbyravi/thru-wallet-ext.git cd thru-wallet-ext npm install npm test npm run build ``` Then: 1. Open `chrome://extensions`. 2. Enable **Developer mode**. 3. Choose **Load unpacked**. 4. Select the `dist/` folder, not the repository root. 5. Pin the extension. `npm test` is deterministic and local. It does not close the browser smoke checklist or the live-chain probes. ## After it is installed - Reload the **extension**, not only the popup, when the service worker may be stale. Chrome caches it. Reopening the popup can run new UI against old background code. - Select `dist/` again after every `npm run build`. - Do not import a phrase you also use anywhere with real value. - Custom networks cannot be activated. If a legacy row appears, Remove is the only action. ## Listing versus source | | Store | Unpacked | | --- | --- | --- | | Who | Anyone trying the wallet | Someone auditing, patching, or needing betanet now | | Version | Listing 1.4.1, 2026-10-04 | The commit you built | | Updates | Chrome updates the package | You rebuild dist/ | | Contract | v15, as built from `cee006e` | v15 at `main` (`cee006e`) | | Network | betanet RPC | betanet RPC | If those two disagree, the source tree wins for source claims — including over `docs/STATUS_AND_ROADMAP.md`, which still describes contract v12. The listing wins for what Chrome will actually install today. ## Doc: Features (/features) Status words on this site are narrow. - **STABLE** means the route and the background path exist, and the project treats them as the product. - **ALPHA** means the code is real, but a browser check or a live-chain measurement is still open. - **NEW** means it arrived in the 1.4.1 package on 2026-10-04. You can install it today, and no manual browser run is recorded against it yet. - **PLANNED** means it is not a thing you can do in the extension today. ## Wallet core Create or import a phrase or a private key. Derive more HD accounts from a seed keyring. Keep several keyrings. Encrypt the vault with PBKDF2 (600,000 SHA-256 iterations) and AES-256-GCM. Ciphertext is in `chrome.storage.local`. Decrypted material is only in `chrome.storage.session`. Auto-lock defaults to 15 minutes and is configurable from 0 to 240, password-gated either way. In 1.2.0 it was a fixed-period alarm despite the label. 1.4.1 stamps `lastActivityAt` on every API request and locks on measured idleness, with background sync explicitly not counting as activity — and it adds an immediate lock button plus Ctrl+L. ## Daily use Balances show human-scale THRU and the raw base units. 1 THRU = 1e9 base units. Account creation and faucet claim exist where the network supports them; contract v13 makes a faucet claim unlocked-only rather than signing-gated. Native send goes through review, and contract v15 catches a repeat transfer to the same recipient inside 30 seconds before it is signed. History is one flat stream: block time when known, otherwise `Block `, refreshed every 30 seconds. Optional desktop notifications announce confirm or fail. The popup is 400px. The side panel is an explicit opt-in and does not steal the toolbar click. ## Token work `token.getBalances` and `token.transfer` are implemented on official `@thru/programs/token` bindings. A missing token account is a proven zero. A failed read is unknown. The token-program fee is unmeasured, and the UI is supposed to say so rather than quote the native 1-base-unit fee. The token list lives in a drawer opened from the balance box, and a custom token is added by contract address: `token.readMint` reads the mint from the chain and uses its own symbol and decimals, because typed metadata is what made an added token spend the wrong number of base units. Contacts CRUD is not a shipped screen. Account pin, hide, and order exist on the account routes. ## Not shipping Launchpad, DEX, and prediction UI were deleted. A future version of any of them has to be a separate feature module. There is no injected provider. ## Doc: Architecture (/architecture) The extension is one direction of calls, with the background holding authority. ```text src/ui/app/routes/* -> bridge.send(method, params) src/background/api-router.js -> auth + contract + dispatch src/background/services/* -> adapters src/lib/vault.js src/lib/thru-client.js src/lib/networks.js ``` ## UI route stack Fourteen routes share the kit, the router, the modal, and the focus trap: welcome, unlock, dashboard, accounts, account, add-account, keyring, export, send, receive, faucet, history, settings, reset. ## Bridge The UI does not call `chrome.runtime.sendMessage` except through the bridge. BigInt values are stringified before the port. The router names the method and field path if a payload cannot be serialized. ## API router The manifest is the allowlist. Auth tiers include password and signing. `tx.registerAccount` is the narrow unlocked-only signing exception, and only for an exact vault-owned address. The pending v13 step adds a second, equally narrow one: a faucet claim is an incoming credit, so it is unlocked-only too. ## Networks `networks.js` is the only place an RPC URL, explorer URL, or program address is allowed to live, and anything stored that is meaningful on one chain only is namespaced by network id. Betanet is the one enabled entry; localnet, testnet, and mainnet are declared and disabled so the storage-scoping machinery has something to exercise. A build check fails if the enabled list and the manifest's `connect-src` ever disagree. ## Sacred files Do not casually edit `src/lib/vault.js`, `src/lib/thru-client.js`, or `src/lib/networks.js`. Derivation has golden tests. The betanet release had to touch `thru-client.js` for the 0.4.x package shapes and the betanet move — the rename of `ALPHANET_RPC` to `BETANET_RPC` is the one intentional export change, and the PDA vectors stayed pinned. Program addresses now come from the managed-genesis registry in `@thru/programs` rather than from reverse-engineered marker bytes, so a redeployment lands as a version bump instead of a pasted string. ## Website This site is not the extension. Product copy lives in `src/content/`. The Postgres desk stores field notes and smoke-check marks. It does not store secrets, and it is not a wallet backend. ## Doc: Security model (/security-model) > This extension has not had a security review. The notes below are design constraints, not a certification. ## Custody Seeds, private keys, and passwords stay inside the extension. Export re-checks the password even when the wallet is unlocked. Agents, pages, and this website are outside the boundary. Encrypted vault bytes may persist. Decrypted vault data belongs only in the session store, which is wiped when the browser session ends. ## Signing Signing requires an unlocked wallet. Password re-authentication for ordinary signing is **off by default**. Turning that preference on goes through a password-gated settings path. Generic `settings.set` rejects security-sensitive keys. Do not extend the v12 registration exception to send, faucet, token transfer, export, or contacts. ## DOM `innerHTML` and related sinks are ratcheted at zero. New interface code uses the kit DOM factory. Lifecycle tests look for a seeded mnemonic, private key, or password in text, attributes, dataset values, input values, and the URL. ## Networks Custom endpoints cannot become active, including by a direct bridge call or by stale storage. Re-enabling them requires HTTPS policy, host permission, a verified capability record, and password re-auth — together, not one at a time. Localnet was removed from the shipped wallet for the same reason: selecting it bound the extension to a localhost endpoint the user may not control. ## Permissions 1.4.1 requests five: `storage`, `alarms`, `sidePanel`, `clipboardRead`, and `notifications`. The fifth is new, it is a Settings toggle, and the notification body says only that a transfer confirmed or failed — no amount, address, or signature. The CSP remains `default-src 'none'` with `script-src 'self'` and a single `connect-src` origin. ## What tests do not prove Layout, real focus, canvas QR, the side panel, clipboard prompts, and service-worker eviction are browser facts. See the [status page](/status). ## Doc: Roadmap (/roadmap) Remaining work is independent. Custom networks and a dApp provider stay blocked until their preconditions exist. Do not "helpfully" implement either early. ## Open 1. Verify what shipped. 1.4.1 is live on the store and all 36 rows of `docs/MANUAL_SMOKE_CHECKLIST.md` are unticked. Install the published package, not a local `dist/`, and run them for both popup and side panel, including desktop notifications. 2. Merge the v16 chain with a version bump. #17 and #18 are mergeable and carry contract v16; landing them without a package bump puts two different contracts behind one version string. 3. Exercise v12 account activation and owned-recipient just-in-time registration on betanet. 4. Probe token transfer: fee, and a never-registered recipient owner. Run the token lab against a live chain. 5. Confirm betanet block-time availability, fee source, and the `?network=betanet` explorer routes. ## Blocked Custom network activation waits on four controls at once: HTTPS with a localhost exception, narrow host permission, per-network capability records, and password re-auth. An extension provider waits on a published Thru contract. The hosted iframe methods are not that contract. ## Already done Launchpad quarantine, route lifecycle coverage, custom-network quarantine, token transfer code, and contract v12 registration plus history cache. Merged as v1.4.1 on 2026-10-03 and published to the store on 2026-10-04: the whole betanet adaptation — @thru 0.4.1 packages, managed-genesis addresses, contract v13 to v15, the token drawer, and inactivity-based auto-lock. Done does not mean live-certified: the manual checklist behind it is still 0 of 36. ## Doc: Changelog (/changelog) This site keeps several clocks and refuses to merge them. - **Listing version**, such as Chrome Web Store 1.4.1 on 2026-10-04. What Chrome installs. - **Contract version**, such as v15 in the published build, v12 in a status document that has not caught up, or v16 on an open pull request. Three live numbers; say which. - **Package version**, such as 1.4.1 — merged, tagged, and published, but not manually verified. - **Submission state**, which is not a version at all: submitted, approved, or rejected. - **Desk notes**, which are rows in Postgres and can be added without a code change. The rendered history is on the [changelog](/changelog). Authored entries live in `src/content/changelog.ts`. Desk notes are not a release. They are a ledger. When you add a release, say which artifact moved. A store update that does not bump the contract is still a release. A contract bump that is not in the listing is not yet what Chrome will install. A reviewed pull request is not a release at all — it is a promise with CI attached. ## Doc: AI agents and MCP (/ai-and-mcp) Prefer the official read-only explorer MCP for live chain queries: [scan.thru.org/api/mcp](https://scan.thru.org/api/mcp). Protocol context starts at [thru.org/docs/llm.txt](https://thru.org/docs/llm.txt). A local wallet companion is a plan, not a shipped server. ## Allowed reads These are non-secret and still privacy-sensitive. A companion needs an explicit per-session permission. - `wallet_get_public_accounts` - `wallet_get_balances` - `wallet_get_assets` - `wallet_get_activity` - `wallet_get_networks` - `wallet_get_capabilities` ## Protected intents Preparation only. The human reviews in the extension. The background signs after auth policy. - `wallet_prepare_native_send` - `wallet_prepare_token_transfer` - Swap and launchpad preparation only after those programs are real and verified. ## Forbidden - Mnemonic or private-key export - Password access - Direct signing or direct broadcast - Reset, or mutation of security settings - Raw decrypted vault access, or arbitrary `chrome.storage` access Account addresses and balances are not secrets, but they are not public telemetry either. This website does not ask for them. ## Doc: MCP and AI policy (/mcp-and-ai) Read in this order when working on the extension: 1. `AGENTS.md` 2. `docs/DOCS_INDEX.md` 3. `docs/STATUS_AND_ROADMAP.md` 4. `CONTEXT.md` 5. `docs/MCP_AGENT_INTEGRATION.md` 6. [https://thru.org/docs/llm.txt](https://thru.org/docs/llm.txt) For this website, start with [`/llms.txt`](/llms.txt) and [`/llms-full.txt`](/llms-full.txt). ## Rules that do not soften - Do not request, store, print, or reveal a mnemonic, private key, or password. - Do not invent protocol behavior, token fees, explorer routes, or a `window.thru` provider. - Do not collapse the published package, the `main` tree, and the stale status document into one "current version" — the first two match today, the third does not. - Do not quote `docs/STATUS_AND_ROADMAP.md` version numbers without checking `src/shared/contract/manifest.js`; on `main` at `cee006e` the doc still says v12 while the code exports 15. - Do not mark a smoke check passed because a Node test passed. - Use official SDK and program surfaces when they exist. The pinned packages are the implementation authority for a checkout. ## This site's machine surfaces | Surface | Use | | --- | --- | | /llms.txt | Short context and the store link | | /llms-full.txt | Docs, routes, policy, changelog | | /api/catalog | Listing, contract facts, desk counts | | /api/doc?slug= | One document as JSON | | /api/changelog | Authored history | | /api/field | Desk notes | | /api/health | Database reachability | ## Doc: Content guide (/content-guide) Authored product copy is TypeScript, so a change is reviewable. | File | What it feeds | | --- | --- | | src/content/site.ts | Name, warning, store link, listing facts, contract facts, the store/release/status-doc tracks and the unverified block, nav | | src/content/features.ts | Feature groups and status badges | | src/content/routes.ts | The 14-route table | | src/content/security.ts | Principles, gaps, signing notes | | src/content/architecture.ts | Five-layer flow and contract breaks | | src/content/ai.ts | MCP policy tables | | src/content/roadmap.ts | Numbered open and blocked steps | | src/content/changelog.ts | Authored release history | | src/content/docs.ts | Docs hub markdown | | src/content/smoke.ts | Smoke checklist seed and open doc slots | ## Desk `/desk` writes Postgres: field notes and smoke-check marks. The gate requires an explicit `DESK_PASSWORD`; there is no default password. Without both `DATABASE_URL` and `DESK_PASSWORD`, the desk remains read-only. The gate does not protect a wallet. It only slows casual edits to the ledger. Do not put secrets in a desk note. Notes are rendered publicly on the changelog. ## Store link The canonical install URL is exported as `chromeStoreUrl` from `src/content/site.ts`. Header, homepage, install page, footer, JSON-LD, llms files, and `/api/catalog` all read that constant. If the listing moves, change it once. ## Release tracks `site.ts` exports five things that must not be edited as if they were one: - `site.listing` — only ever what the live Chrome Web Store page says. Re-read the page before touching it and record the date in `verifiedOn`. A submission, a merge, and a GitHub release are all forbidden from writing here; on 2026-10-04 a changed public page did. - `storeStatus` — the package in front of the store and the date it was published. `state` runs `upload-pending` → `in-review` → `published`, and reaching `published` is the only thing that licenses an edit to `site.listing`. - `site.contract` — the code facts on the extension's `main` branch, with `auditedCommit` and `auditedOn` deliberately lagging while the status document does. - `release` — the merged, tagged source release, with its PR number, merge commit, and tag. - `auditedDoc` and `unverified` — what the repository still claims about itself, and what nobody has checked. Both exist so that "shipped" is never allowed to read as "verified". `releaseTracks` renders the first three on the status page and the homepage. When two of them converge — as the store and the source did on 2026-10-04 — say so explicitly rather than deleting a track; the convergence is the news.