Key takeaways
- Read the store rules first: no rewards for installs or reviews, no hidden ads or affiliate tags, and no remote code in the extension.
- Keep the points balance on your server, tied to a user account, never in the extension's local storage.
- Open the offerwall in a new tab with a link your server signs, and credit points only when a postback arrives.
Can you monetize a Chrome extension with an offerwall?
Yes, if the offerwall is optional, clearly labeled, and opened by the user from your extension’s own interface. The pattern that fits store rules is simple: users sign in to an account on your server, earn points by completing offers on a wall that opens in a new tab, and spend those points on something inside your extension, such as premium features or higher limits. Your server signs the wall link and credits points when the offerwall sends a postback.
What you must not do is just as clear: reward users for installing or reviewing your extension, inject ads or affiliate tags into the websites users visit, or make the wall a condition for using the extension. This guide covers the rules, the architecture, and the code that ties it together.
What the Chrome Web Store and Firefox Add-ons rules say
Browser stores review extensions more strictly than most app stores, and monetization is a common reason for rejection. These are the points that matter for an offerwall, taken from the current policies. Policies change, so read them again before each release.
Chrome Web Store
- Ads are part of your product. The Ads policy says ads are reviewed as part of your extension, must be presented in context or clearly state which product they are bundled with, must be easy to remove by changing settings or uninstalling, and that forcing users to click on ads or submit personal information for advertising to fully use an extension is prohibited.
- No incentives to install. Google’s Spam FAQ says offering incentives to download a Chrome Web Store extension is not allowed, and the Spam and Abuse policy names incentivized reviews and ratings as manipulation.
- Affiliate links need disclosure and user action. The Affiliate Ads policy requires any affiliate program to be described prominently in the store listing, the interface, and before installation, and requires a related user action before each affiliate code, link, or cookie is added.
- No remotely hosted code. Under the Manifest V3 requirements, an extension may load data from your server, but not logic. A
<script>tag pointing outside the extension package is a listed violation. - Single purpose. An extension must have a single, narrow purpose and must not bundle unrelated functionality.
- User data. If your extension handles user data, you must post an accurate privacy policy, and the store’s disclosure and consent rules apply.
- No notification spam. Extensions that abuse notifications with spam, ads, promotions, or unwanted messages are not allowed.
Firefox Add-ons
- Mozilla’s Add-on Policies require advertising injected into web pages to be clearly identified as coming from the add-on.
- Modifying web content or redirects to add affiliate tags is not permitted, while affiliate promotions inside interface elements clearly identified as belonging to the add-on are acceptable.
- Add-ons must be self-contained and must not load remote code for execution.
- If the add-on sends data outside Firefox, users need a clear way to control it right after installation, and personal data requires an explicit opt-in.
Microsoft Edge Add-ons and other stores have their own policies, so check each store you publish in.
Why an offerwall fits inside these rules
Most extension monetization that gets rejected touches the websites users visit: injected banners, swapped affiliate codes, or redirected searches. An offerwall does none of that. It lives behind a button in your own popup or options page, it opens only when the user clicks, and it shows third-party offers on a page that is clearly separate from the sites the user browses.
It also fits the single purpose rule best when the points stay inside your product. A tab manager that lets users unlock extra workspaces with points, or a writing tool that trades points for more monthly checks, gives the rewards an obvious link to the extension’s purpose. If the points turn into cash or gift cards, you are effectively running a rewards site, and How to start a rewards website covers what that adds.
The architecture: accounts and points on your server
An offerwall pays per user, so you need to know who the user is. That means an account on your server:
- Sign-in. The user signs in from the extension, for example with your own login or a provider such as Google, and the extension keeps a session token.
- A stable user ID. Your server assigns each account a random ID that never changes. This is the ID you put in the wall link.
- The balance lives on the server. Points are added and removed only by your server. Anything stored in the extension’s local storage can be edited by the user, so treat it as a display cache at most.
- Features are unlocked by the server. When the user spends points, your server records the purchase and tells the extension what is unlocked.
Your privacy policy and store listing should describe this account and what you store, and should mention that an offerwall partner receives the user ID when the user opens the wall.
Open the offerwall in a new tab with a signed link
The link hash salt is a secret, and anything shipped inside an extension package can be read by anyone who installs it. So the extension never builds the link. It asks your server for it, then opens it in a new tab:
document.getElementById("earn").addEventListener("click", async () => {
const res = await fetch("https://example.com/api/wall-link", {
headers: { Authorization: "Bearer " + sessionToken }
});
const data = await res.json();
chrome.tabs.create({ url: data.url });
});
Your server checks the session, then builds the link for that user. On Sharklio it looks like this in PHP:
$hash = hash_hmac("sha256", $userId, $linkHashSalt);
$url = "https://wall.sharklio.com/" . $appId
. "?user_id=" . rawurlencode($userId)
. "&hash=" . $hash
. "&sub1=extension";
echo json_encode(["url" => $url]);
A few details make this work well:
- A tab, not a frame. The Sharklio wall only loads inside frames and pop-ups on the https website you registered for the app, so an iframe inside your popup will not load. A new tab works everywhere, and keeping the wall as an ordinary web page also keeps it outside your extension’s code. For the same reason, do not add the floating button script to extension pages.
- Tag the source. The
sub1value is available as the{sub1}macro in your postbacks and as a group in the Reporting API, so you can compare users from the extension with users from your website. - Allow the request. Your extension needs permission to call your API, either through the host permissions in its manifest or through CORS rules on your server.
The Offerwall link docs have the same code in Node.js and Python, and Offerwall integration: iframe, link or API? compares the options in more depth.
Credit points with postbacks, not with the extension
When a user completes an offer, the offerwall calls your postback URL server to server. Your handler checks the signature, then:
- Status 1, credited: add the reward to the user’s balance, once per transaction ID.
- Status 3, pending: optionally show the reward as pending, if you turned pending events on.
- Status 4, rejected: nothing to add.
- Status 2, reversed: take the reward back, if you credited it.
The extension then simply asks your server for the current balance when the popup opens. Never let the extension tell the server that an offer was completed: only the postback can do that. Postback security lists the checks your handler should run, and What is a postback URL? explains the idea.
Illustrative example: a tab manager with a premium tier
A tab manager extension has 30,000 weekly users. Premium costs $3 a month or 3,000 points, and the wall shows rewards at 1,000 points per $1 the developer earns, with a 100% user split. If 4% of users open the wall in a month and 15% of those complete an offer averaging $1.20, that is 180 completions and $216 in payouts. Some of those users would never have paid for premium, so the wall reaches people a subscription never would. The numbers are made up to show the method, not to predict results.
Mistakes that get extensions rejected or abused
Do not do this
- Give points for installing your extension, rating it, or reviewing it.
- Show offers or ads inside the websites users visit.
- Make the wall a condition for using the extension’s basic features.
- Ship the link hash salt or postback key inside the extension.
- Keep the balance in local storage and trust it.
- Send notifications about new offers that users never asked for.
One more rule from the traffic side: do not buy installs of your extension just to send those users to the wall. Grow the extension on its merits, then monetize the users who stay. If you are on the other side and want users for your extension, How to promote a browser extension or desktop app covers what advertisers may and may not pay for.
Launch checklist
- The rewards feature fits your extension’s single purpose, and the points unlock something inside it.
- The listing, the interface, and the privacy policy describe the offerwall and the account.
- Users sign in, and each account has a random, permanent user ID.
- The wall opens in a new tab, from a clearly labeled button, with a link your server signs.
- Points are credited only by postbacks, once per transaction ID, and taken back on reversals.
- The extension works without the wall, and nothing touches the websites users visit.
- Users under 16 are kept away from the wall.
A Sharklio direct link for your extension
Sharklio’s Direct link integration is made for places like an extension popup: a signed link your server builds, opened in a new tab, with no SDK and no website restriction. You set your own currency name, icon, rate, and user split, and every result reaches your server by postback with your sub ID attached. Publisher applications open soon; prepare with Get your publisher account approved.
Frequently asked questions
Is it allowed to put an offerwall in a Chrome extension?
The Chrome Web Store has no rule against offerwalls as such, but its ads, affiliate, user data, and spam policies all apply. Keep the wall optional, clearly labeled, opened by the user from your own interface, and never reward installs or reviews.
Can I give users points for installing my extension?
No. Google’s Spam FAQ says offering incentives to download a Chrome Web Store extension is not allowed, and incentivized ratings and reviews are treated as manipulation.
Can I show the offerwall inside the extension popup?
Not on Sharklio. The wall only loads in frames on the website you registered for the app. Open it in a new tab instead, which also keeps it outside your extension’s code.
Where should the points balance be stored?
On your server, tied to the user’s account. The extension can show it, but anything stored only in the extension can be changed by the user.
Can I add affiliate links to my extension as well?
Possibly, within the stores’ affiliate rules. Chrome requires prominent disclosure and a related user action before each affiliate code, and Firefox does not allow adding affiliate tags to web content.