Download and unzip
Save the ZIP and extract it. You should end up with a folder that has
manifest.json directly inside it — that exact folder is what Chrome needs.
Tollgate caps and reports AI usage across your team — Claude Code and Codex on each machine, and Claude, ChatGPT and Codex in the browser. Add the browser half in about a minute.
Server address already configured Prompt text never leaves the browser Chrome or Edge 116+
The extension is not on the Chrome Web Store — it is served by your own server, so nothing leaves your network. Chrome loads it from a folder on disk.
packages/extension, so there is nothing to
download. Rebuild the image from the current repository, or point
EXTENSION_PACKAGE_DIR at the extension directory. The steps below are
otherwise unchanged.
Save the ZIP and extract it. You should end up with a folder that has
manifest.json directly inside it — that exact folder is what Chrome needs.
Open the extensions page, turn on Developer mode, click Load unpacked, and choose the folder you just extracted.
On Edge use edge://extensions. Browsers block links to these pages, so paste it into the address bar.
Click the extension's icon and enter the single-use code from your administrator. The server address is already filled in:
Your browser then appears on the dashboard's Devices page, labelled Browser.
SHA-256 of the ZIP this server is currently serving. It changes whenever the extension sources change, and never otherwise.
f80854593fe9e72e7265fe4ee687c18da46d6253d698f43ace0d6cf6538b43c0
On Windows: Get-FileHash .\tollgate-extension-1.1.0.zip
On macOS or Linux: shasum -a 256 tollgate-extension-1.1.0.zip
The machine-readable form is at /install/extension.json.
Nothing is being served, so there is no checksum to compare against.
Every copy this server hands out has the same extension id, so a new version replaces the old one in place. Nobody re-enrols, and nobody needs their install code a second time.
The extension asks this server every few minutes whether it is current. When it is not, its icon gets a mark and the popup offers the new build.
A browser cannot update an extension it did not install, so this step is yours — but it is two clicks, and it keeps everything: the enrolment, the device, and any usage still waiting to be sent.
Administrators only. Chrome installs the signed build itself and re-checks this server a few times a day, so updates need no action from anyone — and the extension cannot be removed.
Add this to ExtensionInstallForcelist via Group Policy or your MDM:
The id is fixed for the life of this deployment. On Windows that is HKLM\Software\Policies\Google\Chrome\ExtensionInstallForcelist.
Counting fires when a prompt is submitted, not when a reply finishes — submission is something these apps must handle predictably, so it survives their redesigns.
Claude, Claude Code, ChatGPT and Codex. The two pairs share a domain and are kept apart by path, so they never report as one blob.
Only a length is sent. These apps are used for personal things too, and a usage report is no reason to collect that.
Browser activity lands beside the CLI devices for the same person, on the same Devices and Usage pages.
Prompts are queued locally when the server is unreachable and sent when it comes back. A closed laptop loses nothing.
A browser that has gone quiet is shown as “not reporting”, never as confirmed disablement — the difference is not something the extension can know.
It asks for permission to reach one origin — this one. Nothing is sent anywhere else, and there is no vendor in the middle.
Worth saying out loud before you roll it out, because the two halves differ.
No prompt is ever stopped in the browser. Treat it as visibility. Blocking is what the CLI does on the machine.
No browser API exposes a model's token accounting, so web rows record no token count rather than a guessed one.
Any extension can be removed; this one reports its own removal. To prevent it, force-install it by policy across the fleet.
The CLI installs on the machine and enforces the limit inside Claude Code and Codex — per-hour, per-day, per-model and per-project.
An administrator creates the person in the dashboard, which produces one command to paste on their machine. It installs the runtime this server was built from, registers the device, and starts enforcing — no npm account and no internet needed on the target.
Open the dashboard