The Rogue Checkout
Google Chrome features an advanced web API designed to allow websites to install custom “Payment Handlers.” In theory, this allows an online store to install a mini-application inside your browser to process credit cards or cryptocurrency directly, without redirecting you to a standard payment gateway like PayPal. In practice, allowing arbitrary websites to install deep financial processing hooks into your browser is a massive security risk. If you only ever buy things using standard credit card forms or official third-party redirects, you must completely lock down this API to prevent malicious sites from silently installing rogue payment processors.
How to Block Payment Handlers Globally
You can permanently lock the browser out of the payment API via the Site Settings.
- Open the Google Chrome desktop browser.
- Click the three vertical dots (⋮) in the top right corner and select Settings.
- In the left-hand sidebar, click on Privacy and security.
- In the main window, click on Site settings.
- Scroll down to the bottom and click to expand Additional permissions.
- Click on Payment handlers.
- Under the “Default behavior” heading, select the radio button for “Don’t allow sites to install payment handlers.”
A Secure Pipeline
The change takes effect instantly. Google Chrome will completely sever its internal connection to the Payment Request API. The browser will instantly auto-reject every single request from any website attempting to install a custom checkout script. You will never see a permission pop-up, and you can browse e-commerce sites knowing they are physically blocked from altering your browser’s financial architecture.