A small program inside your browser that changes how pages look #
extension · add-on
It adds one button to a row the page already has. It doesn't open a separate website, and it only loads on the sites it names.
Every word the other pages use, with its plain-language version attached. If a page here ever lost you, that word is below.
No term matches that search.
extension · add-on
It adds one button to a row the page already has. It doesn't open a separate website, and it only loads on the sites it names.
supported site
The extension names its sites in advance and the browser holds it to that list. The current one is on the home page; new sites arrive with an ordinary update.
reaction layer
It isn't a copy of the site's own numbers and the site can't switch it off. Everyone with the extension sees the same layer on the same page.
reaction button
It shows the top 3 emoji left on that item and the running total. Clicking it opens the picker.
picker
Every emoji in one grid, plus search, your recently used, and the reactions already left on the item. What is in it is on The emoji palette.
action row
Like, Share, Star, upvote — whatever that site offers. Emojery mounts its button inside that same row rather than floating one somewhere over the page.
native button
Emojery leaves it alone by default. 2 settings change that: "Hide original buttons" hides it in your browser only, and "Auto-press original buttons" presses it for you when the emoji you picked has an obvious equivalent.
popup
Your reaction history, the per-site switches, your account, and the Report tab for a page where the button never appeared.
site adapter
Every supported site needs its own, because every site is built differently. When a site redesigns its pages that is the piece that needs updating, and the counts are untouched by it (why).
reaction badge
The top 3 emoji and the running total, as an image that renders for everyone, extension or not. Build one on Reaction badge. Not to be confused with the number on the toolbar icon, which counts the buttons on the page in front of you.
target
A video, a post, a repository, a product. 2 people arriving from 2 different links to the same video are reacting to the same target.
canonical target key
A site name plus that item's own identifier, derived the same way in your browser and on the server, so tracking parameters and link variants all land on the same count. It is what the extension asks about, rather than whatever is in your address bar.
aggregate count
42 people picked 🔥, and that's all anyone ever learns. Emojery has no way to show who reacted, because it never publishes that.
one account, one reaction
Picking a different emoji replaces your old one instead of adding a vote, and picking the same one again takes it back. Holding that rule up is the entire reason there is a sign-in at all.
counters cache
It is kept so pages load quickly, which is why a count can trail the real one by about a minute. The public record is the authority: add it up again and you get the same totals (why a count can look stale).
anti-abuse
Automated and duplicate voting is what they are for. How they decide is deliberately not published, which makes this the one part of the system you cannot recompute — the status page reports it as our own assertion rather than a verifiable one.
transparency log
Anyone can download the whole thing and read every line. Nobody's name is in it. How it is built is on The transparency log.
append-only
Changed your mind? That's a new line. Deleted your account? Also a new line, and it subtracts your old reactions back out of the totals.
hash · fingerprint
Same data, same string, every time. Any change, however tiny, produces a completely different one — which is what makes it useful as a fingerprint.
Merkle tree · root hash
Each entry's fingerprint feeds into the one above it, up to a single value covering everything below. Alter any entry anywhere and that top value changes, so an entire history can be checked with 1 comparison.
signed checkpoint
The signature proves it came from us. The fingerprint proves nothing in the list has moved since it was taken.
anchor
A public GitHub folder, an independent archive, a Bitcoin block. We can change our own database; nobody can change a block from last week. They differ in what you have to trust: an organization, a mathematical proof, or nothing but a copy.
timestamp · OpenTimestamps
Checkpoint fingerprints are sealed into the Bitcoin blockchain through OpenTimestamps. Confirmation takes hours; after that the date is out of anyone's hands, ours included.
witness log · Sigstore Rekor
We hand Sigstore Rekor the signed checkpoint bytes and it records them in its own tamper-evident log within seconds. It proves an outside organization saw the same fingerprint we published, so we can't later claim we published something else.
archive · Software Heritage
A public-good source-code archive, Software Heritage, that we ask to copy the log repository. Each copy gets a permanent identifier, so the contents on that date can be fetched even if the original repository is rewritten or gone.
tamper-evident
The design doesn't try to make a change impossible. It makes every change leave a mark that a stranger can find afterwards, which is a stronger promise than a policy.
split view
The classic way a public record gets faked. It is caught by comparing what our servers hand you against the copy published where we can't reach it.
verifier
A separate open-source project with no special access — it sees exactly what you see. Anyone can run it on a schedule. Details on The open-source verifier.
revocation
Deleting an account, or a reaction later identified as abuse, is recorded as a reversal rather than an erasure — so the history stays complete and the total stays correct.
reason code
A short public label: an account erased at its owner's request, votes reversed after moderation. Every one of them is listed in the public revocation feed. It records what was claimed, and no amount of math can prove the claim was truthful.
open source
You or anyone else can read what the program actually does before trusting it, and keep reading it after every update.
provider sign-in · OpenID
Google, Apple, Microsoft or Twitch vouches for the sign-in in its own window; Emojery asks it for the standard openid scope only, so no name, email or picture changes hands. No password is ever created on Emojery's side. What each party learns, on How sign-in works.
epoch key · blind signature
Reactions are signed with it, and the pseudonym in the public log is derived from it. Before it can sign, the operator signs the key blind: the extension hides it during signing, so the operator can vouch that the key belongs to an enrolled account without learning which key it vouched for. The private half never leaves your device. Details on How sign-in works.
enrollment proof · zero-knowledge proof
A zero-knowledge proof written to the log when an account is created: it shows the provider signed a sign-in for this account, checked against the provider's published keys, without revealing which account. The verifier checks every one. Details on How sign-in works.
one-way keyed hash
Your sign-in provider hands over an opaque id for your account; what we keep is a string that id produces under a key held outside the database. That string is your account, so a stolen copy of the database yields no ids: the key that produces them is not in it. We hold that key, so we can check whether a provider account you name has an Emojery account — which is what an access or deletion request needs.
session token
Kept by the extension on your device and sent with the reactions you submit, so you aren't signing in with the provider every time. Signing out clears it.
rotating pseudonym
Not a name, not a provider id. It is derived from the signing key your extension makes every 30 days, so it changes on purpose and the public record can't be used to follow an account from month to month.
Community insights
On, a reaction also carries your country and city, language, browser family and operating system, for aggregate maps. Off, those fields go out empty. It starts on, it lives in the popup's settings, and the exact list is in the privacy policy.
content script
Anything that draws into a site needs one, which is why your browser warns that the extension can "read and change" data on those sites. Emojery's reads the page to find the action row and the target, and stops there.
host permission
Emojery names the sites it supports plus its own. Your browser enforces that list and the extension cannot quietly extend it. The breakdown is on Browser permissions.
manifest
It ships inside the extension, your browser enforces it, and the install prompt you saw was generated from it. Extending it takes a new store-reviewed release — the current list.
You tap an emoji, it becomes a line on a public list nobody can edit, a fingerprint of that list is published where we can't reach it, and a free program anyone can run adds the whole thing back up.