Ori Sky @ori.mx · 10/09/2026I may have miscalculated how much Safe Badge is actually costing me for the month. I have no idea how I messed up so monumentally but What I previously calculated: $36 What it will actually cost: $1 160
Ori Sky @ori.mx · 09/09/2026This is on my list of things to do for sure, but I still appreciate you bringing it up. I can’t estimate when I’ll be able to because of burnout reasons honestly lol, but I wanna as soon as possible. 110
Ori Sky @ori.mx · 04/09/2026At some point I should probably deal with the 27 unread emails dating back to 2025 :3 000
Ori Sky @ori.mx · 04/09/2026I’ll probably need to do some of the stuff I’ve been putting off for Safe Badge soon (like client-side caching). Sick atm but I noticed it’s eaten through my free allowance for the month already lol. Probably means it’ll end up costing about $40 for the month if it continues at the same rate. 030
Ori Sky @ori.mx · 29/08/2026Took my fursuit out for the first time. I should have done this way way way sooner. I had so much fun and made some new frens I think too?? 140
Ori Sky @ori.mx · 27/08/2026i um decided to try this on again for the first time in years and um um um 031
Ori Sky @ori.mx · 25/08/2026Eepy. I’m gonna see if I can add client-side caching for safe badge at some point so it can remember who’s had one of the tags on their stream. Maybe tomorrow but we’ll see 010
Ori Sky @ori.mx · 25/08/2026However using the tags is still entirely fine as well as the browser part of it looks for them anyway. 010
Ori Sky @ori.mx · 25/08/2026Hi! I just saw this and wanted to mention that Twitch should no longer be asking for any permissions. The FAQ on the website explains why this was a problem in the first place, but I’ve updated the button on the site to request no permissions at all now. 240
Ori Sky @ori.mx · 24/08/2026Bug fixes: * Fixed badge behaving incorrectly for lots of shared chat / guest streamer scenarios. * Fixed badge positioning in various places. * Fixed badge not displaying in sidebar. * Fixed sidebar padding acting weirdly. It's now consistent! 110
Ori Sky @ori.mx · 24/08/2026New features: * Now displays badge on front page carousel. * Now displays badge beside guest streamers on channel pages. * Now grants badge for the OptedOutOfGenAI tag. * Now fetches stream title through GraphQL for extra evidence. 100
Ori Sky @ori.mx · 24/08/2026Safe Badge 0.2.1 is now available on Firefox and should be available on Chrome soon (awaiting review)! Changelog below. 163
Ori Sky @ori.mx · 22/08/2026Btw if anyone happens to have feature requests or suggestions for Safe Badge, as it is open-source now, you can open tickets at github.com/ori-sky/safe... 010
Ori Sky @ori.mx · 22/08/2026This is something I could potentially do client-side with caching. I wouldn’t wanna store that in the database though, for privacy reasons. But I’ll look into this, thanks for the idea! It’d have to be a similar sort of thing with it being a best guess, but not being guaranteed. 010
Ori Sky @ori.mx · 22/08/2026I guess thinking about it, I could maaybe represent this a bit better. Right now it might be confusing if someone's badge disappears. Maybe I could have it display a different colored icon or something. (yellow? but I want to keep color blindness in mind obviously) 110
Ori Sky @ori.mx · 22/08/2026Something I'm quite proud of that might not be immediately obvious. When viewing a streamer using shared chat in the Twitch sidebar, they only get a Safe Badge if their entire group should have the badge. If one guest does not have the badge, the sidebar doesn't either, preventing any AI training. 170
Ori Sky @ori.mx · 22/08/2026The Firefox addon for Safe badge finally got approved! Here it is: addons.mozilla.org/en-GB/firefo... It's also linked on safebadge.ori.mx 073
Ori Sky @ori.mx · 21/08/2026For what it’s worth, for everyone in this thread, I’ve now removed the openid permission scope. It’ll no longer request anything at all. When you auth with Twitch, it won’t be requesting *any* permissions from the user now. Bit uneasy just in case it breaks in the future, but yeah hope this helps. 030
Ori Sky @ori.mx · 21/08/2026Alright, Safe Badge no longer requires any OAuth permission scopes from the streamer. I'm a bit uneasy doing this as it's against the Twitch API documentation, but Twitch will no longer claim that it'll get your email addr, profile pic, etc. It wouldn't get those anyway, but, it's a lot clearer now. 000
Ori Sky @ori.mx · 21/08/2026Okay it sounds like omitting the scope shouuuld be fine. One of the admins in the Twitch developer Discord server suggested this so I might just do that. It’ll avoid confusion in the long run. 100
Ori Sky @ori.mx · 21/08/2026Also, sorry for the delay on the Firefox version of the extension. Nothing I can do other than wait. 030
Ori Sky @ori.mx · 21/08/2026I could omit the openid scope but this is bad for two reasons. 1. Twitch OAuth requires at least one scope. Not using a scope is undocumented and could break at any time. 2. OpenID gives a signed ID token based on the random nonce, allowing for slightly stronger authentication of the user. 100
Ori Sky @ori.mx · 21/08/2026I have raised this as a Twitch API bug here: github.com/twitchdev/is... Someone else raised this as a bug back in 2023, so it is *not* just me: github.com/twitchdev/is... 100
Ori Sky @ori.mx · 21/08/2026As described by Twitch's OpenID documentation (dev.twitch.tv/docs/authent...), the OAuth application does not receive email addr, profile pic, preferred username, etc, unless the OAuth URL explicitly includes "claims" as a query parameter with a JSON-encoded object that includes "email", etc. 111
Ori Sky @ori.mx · 21/08/2026Safe Badge's OAuth URL looks like this (split up): https: //auth.twitch.tv/authorize ?response_type=code &client_id=9lfupp0yvz1ymn2mk5st0747lpto9x &redirect_uri=https%3A%2F%2Fsafebadge.ori.mx%2Fauth%2Ftwitch%2Fcallback &scope=openid &state={random} &nonce={random} 111
Ori Sky @ori.mx · 21/08/2026Also, regarding the Safe Badge confirmation button seemingly requesting email addr, I've addressed this but I want to address it more thoroughly. The weakest permission I can request is "openid". This is designed specifically for authenticating users with a strong guarantee. 100
Ori Sky @ori.mx · 21/08/2026That sort of thing is obviously not ideal and it's a lot more effort on my part, but if enough people want it I could make it as a separate extension. The whole point of the extension is to make it easy to see who has opted out, though. Not to require massive work on the part of users. 010
Ori Sky @ori.mx · 21/08/2026I could in theory write some alternate version of the extension that doesn't require host permissions, but it won't have any integration with the Twitch website. It would have to be entirely manual, where the user copies a username into a text field and gets a response. 120
Ori Sky @ori.mx · 21/08/2026Host permission means the extension can read and change stuff on web pages, which is required in order to lookup users and add the badge to them. However, a malicious extension could very much use this to read data and send it somewhere, or worse, modify the page maliciously. 110
Ori Sky @ori.mx · 21/08/2026I've seen concerns about the permissions required by the Safe Badge extension. It requires host permissions on the Twitch and dashboard domains, which *can* be dangerous if an extension is malicious. I'm considering alternatives (that would most likely be less user-friendly), but let me explain: 110
Ori Sky @ori.mx · 19/08/2026The code is now open-source! I’ve published it under the Affero General Public License version 3 (AGPL-3.0-only). This ensures that anyone deciding to host it themselves must publish the code to ensure people know what’s changed. Code is available here: github.com/ori-sky/safe... 010
Ori Sky @ori.mx · 19/08/2026* Badges will appear in more places including raid targets in the dashboard. * Tags are now fetched for all channels to ensure the badge can be displayed based on tags. Previously this required the tag to exist somewhere on the page. * Lots of cleanup in the code. Speaking of which… 110
Ori Sky @ori.mx · 19/08/2026I’ve updated Safe Badge to 0.2.0! Update the extension in Chrome/Edge to get it. Also Firefox is in review :3 Bear in mind you may need to re-enable it as it now requires permission on the dashboard subdomain in order to show the badge on raid targets. Reminder: safebadge.ori.mx Changelog below:safebadge.ori 3159
Ori Sky @ori.mx · 19/08/2026New version of Safe Badge in review for Chrome…. and Firefox :3 Made some good improvements but I’ll post more once it’s actually published. 071
Ori Sky @ori.mx · 17/08/2026Sorry for the delay in Safe Badge stuff. I was honestly really busy with other stuff at the weekend and might have burnt myself out a bit. Still coming back to it as soon as I can. 040
Ori Sky @ori.mx · 15/08/2026Sorry for formatting, I’m copying straight from my phone’s todo list lol. - [x] GenAIOptOut - [x] GenAIIsOff - [x] GenAIOptedOut - [x] GenAIOff - [x] NoAI - [x] NoAITraining - [x] AIOptOut - [x] NoGenAI - [x] AIOptedOut - [x] GenAITrainingOff - [x] NoGenerativeAITraining - [x] NoGenerativeAI 100
Ori Sky @ori.mx · 15/08/2026Ah sorry if I’ve confused you. The extension does support several tags that are, or have been, in use. Unfortunately it doesn’t support that one (OptOutGenAI) but I’m gonna add some more when I get a chance. The ones it supports right now are: (next post) 100
Ori Sky @ori.mx · 14/08/2026I will definitely still publish for Firefox (and Opera and etc), but that kinda feels less important than proving it’s trustworthy tbh. 020
Ori Sky @ori.mx · 14/08/2026Slight priority change, I’m gonna clean up the Safe Badge code a bit first and then I’ll make it open source. I’ve heard the concerns about trusting a new browser extension and about trusting something that authenticates you via Twitch, so I wanna both build trust and maybe let others contribute too 140
Ori Sky @ori.mx · 14/08/2026Welp. I’ve got quite a lot of feedback to go through once I have free time lmao 000
Ori Sky @ori.mx · 14/08/2026Sorry just saw this! I know nothing about doing this but I’ll definitely look at it. 110
Ori Sky @ori.mx · 14/08/2026Sorry only just saw this too. In terms of email, I’ve added an FAQ on the website. TLDR I never get access to email, verification status, etc. The FAQ links to the Twitch docs stating that in order to receive that, my OAuth URL would need to include a query parameter “claims”, which it doesn’t. 010