LokiVeil

LokiVeil is an experimental Chrome extension that covers chosen fields on a web page with opaque boxes, for rehearsing screen-share demos on fictional pages. It is a visual mask for test data, not a privacy tool.

You want to rehearse a product demo on a fictional test page and see how selected fields can be covered, and the whole page curtained, while you share your screen.

LokiVeil actual application or output
Actual LokiVeil options page with an imported fictional profile. This demonstrates configuration, not verified protection of private data. Use synthetic pages only.

Before you start

Your first result

  1. Download and read

    On https://perunlight.com/lokiveil/, click Download synthetic-data demo; you can compare the file with the SHA-256 shown on that page. Extract the ZIP and read INSTALL.md and PRIVACY.md.

  2. Install the extension

    Open chrome://extensions, turn on Developer mode, click Load unpacked and select the extracted extension folder (not the ZIP). LokiVeil asks for no site access when installed.

  3. Open a fictional page

    Open your fictional test page over http(s). Before you authorise it, the LokiVeil popup shows NOT PROTECTED: “This site is not authorised, so nothing is masked here.”

  4. Authorise only that site

    Click the LokiVeil toolbar icon, click Authorise this site and accept Chrome's permission prompt. The tab reloads, because the curtain has to start before the page paints. You can also use Authorise an origin in Options.

  5. Add a site profile

    Click Options. Under Import and export, use Import a profile bundle (.json); or under New profile enter Profile id, Allowed origin, Path pattern and Rules (Selector, Min, Max) and click Save profile. Each rule's match count must stay between Min and Max, or the page is reported as not ready.

  6. Check readiness

    Reload the page, open the popup and click Re-check. Use the page for a demo only when the badge says DEMO READY; pages that do not match their profile stay curtained.

  7. During the demo

    Force curtain covers the whole page at once (CURTAIN DOWN). Pick fields reveals the page so you can click fields to capture selectors. Use it only with fictional data, and click Stop picker before you share your screen.

  8. Clean up

    Click Revoke in the popup (or remove the site in Options) and reload open tabs. Options → Delete all LokiVeil data removes profiles, settings and picks; it does not revoke site access, so do both.

Cover four fields on a fictional customer page

Input: examples/lokiveil/fictional-crm-demo.html (a fictional customer record) and examples/lokiveil/fictional-crm-profile.json (a profile for http://localhost:8000/fictional-crm-demo.html covering the name, email, phone and two account numbers).

  1. Save both example files in one folder. In a terminal, go to that folder and run: python3 -m http.server 8000. Then open http://localhost:8000/fictional-crm-demo.html in Chrome.
  2. Click the LokiVeil icon, click Authorise this site and accept the prompt.
  3. Click Options; under Import and export choose Import a profile bundle (.json), keep Merge and select fictional-crm-profile.json.
  4. Reload the demo page, open the popup and click Re-check.
  5. Try Force curtain. When you are finished, click Revoke and reload the page.

Expected: Options confirms “Imported 1 profile(s) in merge mode; 1 stored.” and lists the profile fictional-crm with 4 rules. After the reload, the popup should report DEMO READY with the expected matches (1, 1, 1 and 2), and the customer name, email, phone and both account numbers are covered. Force curtain covers the whole page. After Revoke and a reload, LokiVeil no longer runs on the page.

Troubleshooting

The page stays curtained or the badge says NOT READY.

The profile does not match the page. Check that Allowed origin and Path pattern match the address exactly (for example http://localhost:8000, not 127.0.0.1) and that each selector finds the expected number of elements (see the Rules table in the popup). Click Re-check after changes.

The popup says “LokiVeil only works on http(s) pages.”

Serve the page from a local web server, such as python3 -m http.server 8000, instead of opening the file directly.

The popup says NOT RUNNING, or nothing changes after revoking.

Reload the tab: authorising and revoking only take effect after a reload. NOT RUNNING means the site is authorised but LokiVeil has not started in that tab yet.

Load unpacked shows an error.

Select the extracted extension folder that contains manifest.json, not the ZIP or the folder above it.

Options shows a Commercial unlock box.

Ignore it. This build has no paid tier and no checkout, and it does not check keys.

Compatibility and limits

Guide and examples: 30 September 2026. Examples are fictional or synthetic. Online guide · Support