What "Purple Potassium" actually means
It is Google's internal label for a permissions violation: the manifest requests permissions (or host access) that the reviewer judges broader than the stated purpose needs, or that are used without a clear justification in the listing.
- Broad host access —
<all_urls>or widehost_permissionswhen the feature only touches a few sites. - Powerful permissions kept "just in case" —
tabs,webRequest,cookies,scriptingthat no shipped feature actually uses. - No per-permission justification — the store listing does not explain why each permission is required.
How to fix it and resubmit
- Minimize. Remove every permission a real feature does not call. If you can replace broad access with
activeTab+scripting(granted on click), do it — reviewers strongly prefer this. - Narrow host access. Replace
<all_urls>with the specific match patterns your extension needs (https://*.example.com/*). - Justify each one. In the listing, add a short "needed because of <feature>" line for every remaining permission. Reviewers approve what they understand.
- Match the single purpose. Every permission should trace back to your one stated purpose. Anything that doesn't is what got flagged.
Rule of thumb: if you cannot point to the exact line of code that uses a permission, remove it before you resubmit.
Purple Potassium is one of six rejection families (permissions, metadata/Blue Argon, single purpose, privacy, remote code, functionality/Yellow Magnesium). If your email mentions more than one, fix them together — a second rejection resets the review clock.
Not sure which permission got flagged?
Paste your rejection email or your manifest.json — get the exact cause in seconds, free. Or we fix it and resubmit for you.