如何仅生成签名Firefox扩展文件而不发布至AMO?
Hey there, let's fix this frustrating issue you're dealing with—you need a signed XPI for self-hosting, but web-ext sign keeps pushing your extension back to AMO (which gets it taken down again). Here's how to resolve this permanently:
1. Remove or Replace the AMO-Assigned Extension ID in Your Manifest
The biggest culprit here is likely the unique ID AMO assigned to your extension when you first published it. If this ID is still in your manifest.json (under browser_specific_settings.gecko.id), running web-ext sign will automatically link your build to your existing AMO entry, triggering an unwanted re-publish.
Fix this by:
- Deleting the ID field entirely: Firefox will generate a temporary ID for self-hosted extensions, and the signed XPI will still work perfectly for your users.
- Using a custom ID: If you want a consistent identifier, replace the AMO ID with a custom one in email format (e.g.,
my-extension@my-domain.com). The email doesn't need to be real—just follow the format.
2. Run web-ext sign With the Correct Parameters
Once your manifest is updated, use this command to generate a signed XPI without touching AMO:
web-ext sign --api-key <your-api-key> --api-secret <your-api-secret>
If you want to be extra explicit and eliminate any chance of accidental AMO uploads, add the --no-amo-upload flag:
web-ext sign --api-key <your-api-key> --api-secret <your-api-secret> --no-amo-upload
As MDN states, this uses Mozilla's signature API to produce your signed XPI without creating or updating any distribution listing on AMO—exactly what you need for self-hosting.
3. Verify the Result
After running the command, check the web-ext-artifacts folder for your signed XPI. To confirm it didn't end up on AMO:
- Log into your AMO developer account and check your extension's version history—there should be no new entries.
- You can also unzip the XPI and inspect the manifest or
install.rdfto confirm it's not linked to an AMO distribution ID.
Bonus: Use a Separate API Key (Optional)
To keep your self-hosted work completely isolated from your old AMO extension, consider creating a new set of API keys in your Mozilla developer account (or even a separate account if you prefer). This removes any risk of accidental cross-association between your self-hosted build and the AMO entry that was taken down.
内容的提问来源于stack exchange,提问作者Prerak Sola

