Feedback on staging, localhost and VPN-only sites

The extension runs in the reviewer’s own browser, signed in as they already are. If they can see the page, they can comment on it.

Start free Every feature for 14 days, then pick a plan or stay on Free. No card needed.
Nothing deployed to your site No proxy, no IP allowlist
staging.ashgrove-lettings.example/repairs/new
Basic Auth
My tenancyPaymentsRepairs

Report a repair

Tell us what’s wrong and we’ll book a contractor.

PostcodeBS1 4DJEnter a valid postcode RoomKitchen
What’s wrong?Tap under the sink is dripping
Send request We reply within one working day.

Try it: click anything on this staging page to comment. The site, people and issue numbers are made up.

Who can comment, wherever the site is

There are three ways in. Your team uses the extension. Clients who won’t install anything use a review link. Anyone who can’t reach the site at all comments on a journey you share.

Where the site isYour team, with the extensionClients, on a review linkPeople you share a journey with
A live siteclient.exampleYesYesYes
Staging behind a password or Basic Authstaging.client.exampleYes

After the usual password prompt

No

Our servers can’t get past the password

Yes
Localhostlocalhost:3000Yes

On the machine running it

NoYes

The way to show it to anyone else

VPN or intranetintranet.corp.localYes

While on the VPN. The browser must also be able to reach How’s that? to save comments

NoYes
Strict security headersCSP, Trusted Types, X-Frame-Options DENYYes

The extension doesn’t run as a script on your page or put it in a frame

Sometimes

Best-effort, see below

Yes

To comment with the extension, add the site’s address to a project, open the page in Chrome or Edge, press Alt+Shift+C and click what you mean. Our automated tests run against a page with a strict CSP, Trusted Types and X-Frame-Options DENY; if your site still breaks, tell us.

Why proxy-based tools can’t open these

A proxy-based tool fetches your page from its own servers and shows you their copy.

Those servers don’t have your staging password, aren’t on your VPN and can’t see your laptop. Some ask you to allowlist their IP addresses, which helps with staging but not with localhost. Not every feedback tool works this way: others use an extension, or a script you add to the site.

Nothing to deploy

  • No snippet in your build and no plugin
  • No CSP exception or nonce
  • No IP allowlist or open firewall port

Proxy-based tool

  1. Reviewer’s browser
  2. Tool’s server
  3. staging.client.example

The tool’s server is asked for a password it doesn’t have, or can’t find the host at all.

How’s that? extension

  1. Reviewer’s browser
  2. staging.client.example

The page loads exactly as it does without us.

  1. /login
  2. /tenancy
  3. /repairs/new
  4. Menu open
Rachel Kerr

Can “Room” default to the last one they reported?

step 3 of 4, field “Room”, journey snapshot

Recorded on a laptop on the VPN. Rachel commented from home. Names are made up.

For people who can’t reach the site: share a journey

Click through the site once while the extension records. Each step saves a copy of the page itself, not a picture of it: the layout, text, images, open menus and dialogs. Reviewers open the steps in their own browser and pin comments just as they would on the live site.

Record
Press Alt+Shift+R. A step is saved on each page load, route change and opened dialog, and Alt+Shift+S captures a hover or menu state. Steps stay in your browser while you record.
Check, then publish
Rename or remove steps, add a note and choose which form values to hide. Passwords and hidden fields are never captured, and nothing is uploaded until you press Publish.
Comment
Reviewers open each step from the project’s storyboard. It opens in its own tab at the size it was recorded, and links between steps work. No VPN, no access to your machine.
Keep the feedback
Comments attach to elements on the page the same way as on a live site, so they can be found again on the real site once it’s deployed.

Steps are static copies: scripts don’t run, forms don’t submit, and a native dropdown can’t be captured open.

What the extension can access

It asks for broad access because we can’t know your addresses in advance, like localhost or an intranet hostname. It only switches on for sites in one of your projects.

What leaves your browser

When you post a comment: the text, a screenshot of the visible tab, a description of the element, the page address, browser, operating system and screen size. Password fields, and anything marked data-annotate-mask, are blacked out before the screenshot is uploaded.

When you publish a journey: its snapshots. Steps stay inside the extension until you press Publish.

<all_urls>
Chrome shows this as “Read and change all your data on all websites”. It lets the extension work on any address you add to a project. A small script loads on each page, checks the address against a list of your project addresses kept inside the extension, and stays off if there’s no match. The check happens in your browser, so we never learn which sites you visit. It also takes the screenshot when you post a comment.
scripting
Adds the comment layer to tabs that were already open before you installed it.
sidePanel
Shows the comment list beside the page.
storage
Remembers your settings and the list of addresses in your projects.
identity
Opens our sign-in page in a small window. You can revoke the extension from your account at any time.
contextMenus
Adds “Open How’s that?” to the right-click menu of the toolbar button, so you can jump to the app or the current site’s project.

With journeys switched on, Alt+Shift+R can record any page you choose, even one outside your projects, but only after you press it.

Without the extension, there are limits

For reviewers who won’t install anything, a review link opens the page through our servers instead. That route is best-effort.

  • It only reaches sites our servers can reach: not localhost, not a VPN, not a page behind Basic Auth.
  • Screenshots are drawn from the page rather than taken by the browser, so they can differ slightly.
  • Service workers are switched off, and a script that sends the browser straight to the real address leaves the review.
  • Some sites won’t look exactly right through it.

For staging, localhost and VPN sites, use the extension or a journey.

Questions developers ask first

Does anything get deployed to my site?

No. There’s no script, snippet, plugin or header change. The site is exactly the same with or without How’s that?.

Does page content pass through your servers?

Not in extension mode. The page loads normally in your browser, straight from your server, and only the comment, its screenshot and the details listed above are uploaded. Review links are different: they load the page through our servers, which is why they only work on sites we can reach. Journeys upload the snapshots you publish.

Does it work with single-page apps and hash routing?

Yes. The extension follows history and #hash route changes, and each project can treat the part after # as a separate page or ignore it.

Can one project cover localhost, staging and production?

Yes. A project can hold several addresses, including wildcards such as *.preview.example.com.

Which browsers does the extension run in?

Chrome and Edge. There’s no Safari extension; Safari users can comment through a review link on sites we can reach.

If you can open it, you can comment on it.

Start free No card needed.
Book online
Sam at Northlight

Shortened it to “Book online” so it fits on one line. How’s that?

Claire Hughes Resolved

Spot on, thanks.