Feedback on staging, localhost and VPN-only sites
The extension runs in the reviewer’s own browser, signed in as they already are. If they can see the page, they can comment on it.
Report a repair
Tell us what’s wrong and we’ll book a contractor.
Try it: click anything on this staging page to comment. The site, people and issue numbers are made up.
Who can comment, wherever the site is
There are three ways in. Your team uses the extension. Clients who won’t install anything use a review link. Anyone who can’t reach the site at all comments on a journey you share.
| Where the site is | Your team, with the extension | Clients, on a review link | People you share a journey with |
|---|---|---|---|
A live siteclient.example | Yes | Yes | Yes |
Staging behind a password or Basic Authstaging.client.example | Yes After the usual password prompt | No Our servers can’t get past the password | Yes |
Localhostlocalhost:3000 | Yes On the machine running it | No | Yes The way to show it to anyone else |
VPN or intranetintranet.corp.local | Yes While on the VPN. The browser must also be able to reach How’s that? to save comments | No | Yes |
| Strict security headersCSP, Trusted Types, X-Frame-Options DENY | Yes The extension doesn’t run as a script on your page or put it in a frame | Sometimes Best-effort, see below | Yes |
To comment with the extension, add the site’s address to a project, open the page in Chrome or Edge, press Alt+Shift+C and click what you mean. Our automated tests run against a page with a strict CSP, Trusted Types and X-Frame-Options DENY; if your site still breaks, tell us.
Why proxy-based tools can’t open these
A proxy-based tool fetches your page from its own servers and shows you their copy.
Those servers don’t have your staging password, aren’t on your VPN and can’t see your laptop. Some ask you to allowlist their IP addresses, which helps with staging but not with localhost. Not every feedback tool works this way: others use an extension, or a script you add to the site.
Nothing to deploy
- No snippet in your build and no plugin
- No CSP exception or nonce
- No IP allowlist or open firewall port
Proxy-based tool
- Reviewer’s browser
- Tool’s server
- staging.client.example
The tool’s server is asked for a password it doesn’t have, or can’t find the host at all.
How’s that? extension
- Reviewer’s browser
- staging.client.example
The page loads exactly as it does without us.
/login/tenancy/repairs/new- Menu open
Recorded on a laptop on the VPN. Rachel commented from home. Names are made up.
For people who can’t reach the site: share a journey
Click through the site once while the extension records. Each step saves a copy of the page itself, not a picture of it: the layout, text, images, open menus and dialogs. Reviewers open the steps in their own browser and pin comments just as they would on the live site.
- Record
- Press Alt+Shift+R. A step is saved on each page load, route change and opened dialog, and Alt+Shift+S captures a hover or menu state. Steps stay in your browser while you record.
- Check, then publish
- Rename or remove steps, add a note and choose which form values to hide. Passwords and hidden fields are never captured, and nothing is uploaded until you press Publish.
- Comment
- Reviewers open each step from the project’s storyboard. It opens in its own tab at the size it was recorded, and links between steps work. No VPN, no access to your machine.
- Keep the feedback
- Comments attach to elements on the page the same way as on a live site, so they can be found again on the real site once it’s deployed.
Steps are static copies: scripts don’t run, forms don’t submit, and a native dropdown can’t be captured open.
What the extension can access
It asks for broad access because we can’t know your addresses in advance, like localhost or an intranet hostname. It only switches on for sites in one of your projects.
What leaves your browser
When you post a comment: the text, a screenshot of the visible tab, a description of the element, the page address, browser, operating system and screen size. Password fields, and anything marked data-annotate-mask, are blacked out before the screenshot is uploaded.
When you publish a journey: its snapshots. Steps stay inside the extension until you press Publish.
<all_urls>- Chrome shows this as “Read and change all your data on all websites”. It lets the extension work on any address you add to a project. A small script loads on each page, checks the address against a list of your project addresses kept inside the extension, and stays off if there’s no match. The check happens in your browser, so we never learn which sites you visit. It also takes the screenshot when you post a comment.
scripting- Adds the comment layer to tabs that were already open before you installed it.
sidePanel- Shows the comment list beside the page.
storage- Remembers your settings and the list of addresses in your projects.
identity- Opens our sign-in page in a small window. You can revoke the extension from your account at any time.
contextMenus- Adds “Open How’s that?” to the right-click menu of the toolbar button, so you can jump to the app or the current site’s project.
With journeys switched on, Alt+Shift+R can record any page you choose, even one outside your projects, but only after you press it.
Without the extension, there are limits
For reviewers who won’t install anything, a review link opens the page through our servers instead. That route is best-effort.
- It only reaches sites our servers can reach: not localhost, not a VPN, not a page behind Basic Auth.
- Screenshots are drawn from the page rather than taken by the browser, so they can differ slightly.
- Service workers are switched off, and a script that sends the browser straight to the real address leaves the review.
- Some sites won’t look exactly right through it.
For staging, localhost and VPN sites, use the extension or a journey.
Questions developers ask first
Does anything get deployed to my site?
No. There’s no script, snippet, plugin or header change. The site is exactly the same with or without How’s that?.
Does page content pass through your servers?
Not in extension mode. The page loads normally in your browser, straight from your server, and only the comment, its screenshot and the details listed above are uploaded. Review links are different: they load the page through our servers, which is why they only work on sites we can reach. Journeys upload the snapshots you publish.
Does it work with single-page apps and hash routing?
Yes. The extension follows history and #hash route changes, and each project can treat the part after # as a separate page or ignore it.
Can one project cover localhost, staging and production?
Yes. A project can hold several addresses, including wildcards such as *.preview.example.com.
Which browsers does the extension run in?
Chrome and Edge. There’s no Safari extension; Safari users can comment through a review link on sites we can reach.
If you can open it, you can comment on it.
Shortened it to “Book online” so it fits on one line. How’s that?
Spot on, thanks.
Can “Room” default to the last one they reported?