Last updated: September 24, 2026
YouTube Playlist Search is a Chrome extension that replaces YouTube's "Save to playlist" picker with a searchable one covering every playlist you own. It fetches your playlists directly from YouTube and lets you save videos to them.
As of version 2.0.0 the extension adds nothing to YouTube's own page and reads no data out of it. Its interface is drawn in a private container of its own, and its data comes from YouTube's API rather than from the rendered page.
This extension does not collect, store, transmit, or sell personal data to the extension developer or any third party. No analytics, tracking, or remote logging is performed. The extension developer does not operate a backend server and never receives any of your data.
Your username, email, and profile photo are ignored. The extension reads only the playlist content, the YouTube session value, and the save-request signal described below. None of it is sent to the developer or any third party.
The extension only communicates with YouTube. It calls YouTube's internal "InnerTube" API (https://www.youtube.com/youtubei/v1/*) as a same-origin request from the YouTube tab you already have open. The only other requests are for the playlist thumbnails shown in the picker: these are the image addresses YouTube itself returns, on YouTube's image server (i.ytimg.com), loaded the same way YouTube's own pages load them — so your browser fetches and caches them exactly as it does when you browse YouTube. No requests are made to any other server, and no data is sent to the extension developer.
The extension does not use OAuth, does not use chrome.identity, and does not obtain, store, or transmit any access tokens or refresh tokens.
Because InnerTube requests originate from a youtube.com page, your browser automatically attaches your existing YouTube session cookie — the same way it does when you click around YouTube normally. To satisfy InnerTube's authentication scheme, the extension reads the SAPISID cookie from document.cookie on the current YouTube tab and uses it to compute a short-lived SAPISIDHASH authentication header. The cookie value and the derived hash are only ever sent back to youtube.com itself as part of these same-origin API calls. They are never stored, logged, or transmitted anywhere else.
This is the one genuinely new behaviour in version 2.0.0, and it deserves to be described plainly rather than buried.
When you click "Save" on a YouTube video — from the player, from a ⋮ menu in a feed, from search results, anywhere — YouTube's own web app sends a request to its own server saying, in effect, "this user wants to save this video." The extension watches for that specific request and uses it as the signal to open its picker.
To do that, it installs a small script into the YouTube page itself (a MAIN-world content script, intent-hook.js) that wraps the browser's fetch and XMLHttpRequest functions. Concretely:
/youtubei/v1/get_panel and /youtubei/v1/playlist/get_add_to_playlist. Every other request on the page — video playback, comments, ads, search, sign-in, everything — is ignored and never inspected.panelId, params, continuation, and videoId.Two honest consequences of this design:
MAIN world shares the page's environment, which means youtube.com could in principle detect that the extension is installed, or feed it a fake save request. The extension therefore treats everything crossing that boundary as untrusted, and the worst a forged message can achieve is opening the extension's own picker for a video of YouTube's choosing — something the page could equally do by navigating. The script is kept deliberately small and logic-free to keep that surface minimal.webRequest permission, which does not require any page-world code. It does not work: YouTube sends these request bodies as a compressed stream, and Chrome hands streamed uploads to extensions with no readable content whatsoever. The permission was removed rather than kept as dead weight.If you would rather the extension not observe anything at all, it works without this: the toolbar icon, the right-click menu, and Alt+S all open the same picker using only the page's URL. Those paths involve no observation of YouTube's requests.
The extension reads the following from YouTube:
INNERTUBE_CONTEXT, the brand-channel session ID if you are acting as a channel, and which of your signed-in Google accounts the page is using), read from the page's own configuration script. This is what makes an API call from your session valid, and is the same configuration YouTube's own code uses. It is sent only back to YouTube.All searching and filtering happens locally in your browser. So that the playlist picker opens instantly, the extension keeps the last list of your playlists (titles, video counts, privacy, thumbnail addresses, and the order YouTube lists them in) for the signed-in account in chrome.storage.session. That storage is held in memory only: it is never written to disk, never leaves your browser, and is erased when you quit the browser. It never includes which videos are in which playlist, your searches, or video IDs, and it is replaced by a fresh copy from YouTube every time the picker opens. Nothing about your playlists is written to chrome.storage.local, localStorage, cookies, or any other persistent storage. The only thing written to disk is two display preferences, listed under Permissions below.
The extension declares three Chrome API permissions in manifest.json:
scripting — to dynamically register its content scripts once you grant the YouTube host permission.contextMenus — to add a single "Save to playlist" item to the right-click menu on YouTube video links.storage — used for the in-memory playlist list described above, for two display preferences, and to delete records that earlier versions stored (onboarding flags and a content-script registration error), which this version no longer writes:chrome.storage.session, memory only, cleared when the browser quits): the last list of your playlists for one signed-in account, so the picker opens without waiting.chrome.storage.local): the sort order you last chose (for example "A → Z") and the privacy setting new playlists are created with (Private, Unlisted or Public). These are two fixed words, not playlist names, IDs or searches, and they never leave your browser.Runtime diagnostics are written only to the local DevTools console. They are not persisted, copied into the YouTube page DOM, or transmitted.
Site access is https://www.youtube.com/* only, and is requested as an optional host permission that you grant explicitly via the welcome page's "Grant access" button. The extension does not run on any other site, subdomain, or scheme.
A small service worker (background.js) registers or unregisters the content scripts, works out which video a save request refers to, and opens the welcome page on first install. It stores nothing itself; it only allows the YouTube tab to use the in-memory chrome.storage.session area described above. It never sees your playlists, your cookies, or your authentication headers — those exist only inside the YouTube tab. There is no popup.
The extension does not request the webRequest permission. An earlier design used it to observe save requests; it was removed because Chrome cannot read the bodies of these particular requests at all, making the permission useless while still widening what the extension could see.
There is none. Version 2.0.0 removed the last bundled dependency (MiniSearch, previously used for search ranking; the current search is a plain substring match over your own playlist titles). The extension is entirely first-party code. No remote executable code is loaded at runtime, and no third-party SDKs, analytics, or frameworks are used.
The extension calls YouTube's internal InnerTube API (https://www.youtube.com/youtubei/v1/*) — the same API YouTube's own web UI uses. This is not a public, documented API, and Google may change or restrict it without notice.
Three honest implications of that choice:
We chose this design over the public YouTube Data API v3 because v3 requires OAuth, a Google Cloud project, and is subject to daily quotas — adding friction for users without changing what data is accessible.
If this policy changes, the updated version will be posted on this page with a new "Last updated" date.
Email: playlist@codyh.xyz