What is the WEBMANIFEST file format?
A .webmanifest file is the Web Application Manifest, a JSON document that a browser reads to install and display a Progressive Web App (PWA). It holds a single JSON object whose members describe the app: name, short_name, icons, start_url, scope, display, background_color, and theme_color, among others. When you add a PWA to a phone home screen or a desktop, these values decide the app icon, its title, and how the window opens.
The format is a W3C standard, first drafted in 2013 and supported in browsers from Chrome 45 in 2015. A page links to it in the HTML head:
<link rel="manifest" href="/app.webmanifest">The registered media type is application/manifest+json. The .webmanifest extension is the one IANA registered, though many sites still name the file manifest.json. Both work as long as the server sends a JSON-valid content type.
Security & safety
RISK: LOWA .webmanifest file is plain-text JSON with no executable code, so opening it cannot run anything on your machine. The only practical risk is that a manifest can declare protocol_handlers or file_handlers that register a PWA to handle links or file types once the app is installed, which is a browser-mediated permission, not an action of opening the file. Editing an invalid manifest can break PWA installation but poses no security threat.
Format details
in a nutshell- Firefox WebExtension manifest - Browser extensions use a manifest file, but it is named manifest.json with a .json extension, not .webmanifest.
- Java JAR/app manifests - Unrelated MANIFEST.MF metadata inside Java archives; different format and purpose.
Programs that open WEBMANIFEST files
Technical details
deep spec| Encoding | UTF-8 text |
| Byte order | Not applicable (text) |
| Container | JSON object with top-level keys called members |
| Compression | None (may be gzip/brotli compressed in transit by the web server) |
| Typical size | Under 5 KB |
| Structure | A single JSON object whose members describe a web application: name, short_name, description, icons (array of image objects with src, sizes, type), start_url, scope, display, orientation, background_color, theme_color, categories, screenshots, shortcuts, share_target, protocol_handlers, and file_handlers. |
| Integrity | None built in; integrity relies on HTTPS transport and same-origin/CORS fetch rules |
| Platforms | Windows, macOS, Linux, Android, iOS, ChromeOS |
| Notes | Referenced from a page's HTML head via <link rel="manifest" href="app.webmanifest">. The browser reads it to install a Progressive Web App, set the home-screen icon and name, and control the launch display mode. Servers should return it with the application/manifest+json media type, though browsers also accept application/json. When the manifest is on a different origin than the page scope it must be fetched with CORS. |
| Released | 2013 (first W3C Working Draft, December 17, 2013) |
| Latest version | W3C Working Draft (ongoing) |
| Open standard | Yes · royalty-free |
| Specification | www.w3.org |
WEBMANIFEST conversions
Community Q&A
asked by usersNo questions yet - be the first to ask about WEBMANIFEST files.