Skip to content

Browser extension

GameDock Companion

GameDock Companion is a Chrome extension that reads the game stores you are already signed into, so your library, licences and receipts can reach your GameDock account without GameDock's servers ever holding your store logins. It is the most sensitive thing GameDock asks of you, so this page is written to be read rather than skimmed past.

Last updated 5 Oct 2026

On this page · 8

Why it exists at all#

Steam publishes no API for what you paid, or for your full licence list. Neither does PlayStation, for your order history. The only way to see those things is from a browser that is already signed in, so something, somewhere, has to use your store session.

There are two ways to build that. GameDock could ask you for your store cookies and keep them on its servers, which is what makes the feature easy and the company a target: one break-in and every user's storefront session is gone at once. Or the work can happen in your own browser, where the session already lives, and only the result is sent. That is what the extension is. A server that never holds your store credentials cannot lose them.

That is the whole trade, and it is worth saying plainly: the extension has to be able to do something uncomfortable (read a signed-in session) for GameDock to avoid doing something worse.

It starts with access to nothing#

Installing the Companion grants it one website: your own GameDock hub. Not Steam, not PlayStation, not any store. Each platform is switched on individually, by you, on the extension's Sources page, which opens by itself the first time you install it.

You can check this rather than take our word for it. Install the extension, open chrome://extensions, and look at its site access: GameDock's own domain, alone. Turn a source on and Chrome shows you exactly which sites it is about to allow, before anything is granted. Turn it off and the access is gone immediately, along with anything the extension was holding for that platform.

What each source reads#

SourceWhat it readsWhat you get
SteamWhat it readsYour store and help session cookies, your account name, and the licence, wallet-history and receipt pages those sessions can open. If your Steam profile is private, also each game's achievements page on Steam Community.What you getFull owned-games and DLC list, what you actually paid, achievements from a private profile, wishlist writes and key redemption.
PlayStationWhat it readsYour NPSSO sign-in cookie, which never leaves your browser, and your order history.What you getLibrary, trophies, wishlist and spend.
XboxWhat it readsA Microsoft sign-in token from the session you already have open.What you getLibrary, playtime and achievements, including Xbox 360.
RetroAchievementsWhat it readsYour username and web API key, read from your own settings page.What you getYour retro unlocks alongside everything else.
GOGWhat it readsA one-time sign-in code from a login page you complete yourself.What you getLibrary and order history.
Epic GamesWhat it readsYour order history, wishlist and achievement progress from the session you already have open.What you getLibrary including claimed giveaways, wishlist, achievements and spend.
SteamGridDBWhat it readsYour SteamGridDB API key, once, when you ask. It is read from your own SteamGridDB account preferences. It never creates a key for you.What you getArtwork search with your own key.

What is kept, and for how long#

Credentials are held in the extension only long enough to hand them over, and the hub, not the extension, is the only durable store. Anything the hub keeps is encrypted at rest.

ItemWhere it goesHow long the extension keeps it
Steam session cookiesWhere it goesUsed in your browser. Never sent to GameDock.How long the extension keeps itNever stored. Read per request.
Steam access token, for remote install onlyWhere it goesRead from your Steam session when you ask GameDock to start an install on another computer, sent to GameDock for that one request, passed to Steam, and not kept.How long the extension keeps itNever stored.
PlayStation NPSSO cookieWhere it goesUsed in your browser to obtain a one-time code. Never sent to GameDock.How long the extension keeps itNever stored.
PlayStation one-time codeWhere it goesSent to GameDock, which completes the sign-in server-side.How long the extension keeps itTen minutes at most, removed as soon as it is used.
GOG one-time codeWhere it goesSent to GameDock, which completes the sign-in server-side.How long the extension keeps itNever stored. Passed straight through.
Microsoft / Xbox tokensWhere it goesSent to GameDock, which completes the sign-in server-side.How long the extension keeps itUntil the next successful sync, then removed. Dropped unread after 24 hours if no sync happens.
RetroAchievements API keyWhere it goesSent to GameDock.How long the extension keeps itUntil the next successful sync, then removed.
SteamGridDB API keyWhere it goesSent to GameDock, which searches SteamGridDB with it for your own artwork.How long the extension keeps itUntil GameDock has taken it, then removed.
Your library, receipts and wishlistsWhere it goesSent to GameDock, which is where your library lives.How long the extension keeps itNot stored in the extension at all.

What it never does#

  • It never sends anything to any server but your own GameDock hub. There is one destination address, compiled into the extension; there is no analytics service, no telemetry, no error reporter and no third party of any kind.
  • It never reads a site you have not switched on. It cannot: Chrome enforces this, not our good intentions.
  • It never reads your browsing history. It does not hold the permission that would let it, which is why the install prompt does not mention one.
  • It never sees your passwords. You sign in to each store yourself, in that store's own page.
  • It never records what you click, type or scroll.
  • It never downloads or runs code from anywhere. Everything it does ships inside the reviewed package.
  • It never touches your card number. Purchase history includes amounts and a payment-method label like “wallet” or “VISA”; card numbers, billing account ids and masked card names are deliberately skipped.
  • It does nothing while you are signed out of GameDock. Every action needs a fresh, single-use token from your own signed-in session.

Promises we can be held to#

Each of these is a statement about how the code works today, not an intention. If any of them stops being true, it is a breaking change and will be announced in the app before it ships, not quietly edited into this page.

  • One destination. The extension will never send your data to any origin other than the GameDock hub compiled into it.
  • No standing access. Any new platform will arrive as a permission you are asked for, never as one added to an update you already trust.
  • No credential outlives its use. A captured token is removed once the hub has taken it, and ages out on its own if that never happens.
  • No analytics, ever. Not usage statistics, not crash reports, not a pixel.
  • Readable code. The published build is minified but never obfuscated, variable names are left intact, and each file carries a header saying so.
  • Disconnect means disconnect. Turning a source off (in the extension, or from Settings › Sync on the Hub, which reaches in and does it here) removes the browser access and clears any secret that source had captured, in the same action.

The risk worth knowing about#

This is the part most products would leave out. Several platforms' terms restrict automated access to your account in broad language: Steam's Subscriber Agreement is the clearest example, and it permits Valve to restrict or terminate an account for it. Using GameDock means acting on your own account through software, and that could in principle put a platform account of yours at risk of limitation or suspension by that platform.

GameDock reads at a modest pace: its servers check each store about once a day (Steam up to every six hours), and the extension reads only when you press sync unless you switch on its background sync. That is far from the heavy automation those clauses exist to catch. But the honest position is that the risk is yours, not ours, and you should get to weigh it knowingly rather than discover it later. The full statement is in the terms.

Turning it off, and getting it deleted#

Both are self-service on the hub: Settings › Sync disconnects one platform, and erases what it added if you ask it to; Account › Delete account closes the whole thing. Uninstalling the extension stops any further reading immediately, but it does not by itself delete what has already synced, so use one of those pages if that is what you want. For a copy of what GameDock holds about you, or a correction to it, email support@gamedock.co or use the contact form.