DEV Community

VANSH ARORA
VANSH ARORA

Posted on

How We Built an Authenticated Local Loopback Server for AI Web Chats

Web-based AI interfaces like Claude, ChatGPT, and Gemini are fantastic for brainstorming, but completely cut off from your local repository files.

To bridge this securely, TokenCap implements a local HTTP daemon via tokencap serve adhering to Bridge Contract v1.

Security Architecture of the Bridge

  1. Loopback Binding: The daemon listens exclusively on 127.0.0.1:4545. It never binds to 0.0.0.0 or public network adapters.
  2. Ephemeral Token Auth: When starting, a random hex token is generated and stored locally in ~/.tokencap/. Requests must provide this token via the X-TokenCap-Token header.
  3. Strict Origin Checks: Pre-flight CORS filters block unauthorized web domains. Only approved extension origins can read responses.

Running in the Terminal

# Start in the foreground
tokencap serve

# Or run as a detached background daemon
tokencap serve --daemon

# Stop the daemon
tokencap serve --stop
Enter fullscreen mode Exit fullscreen mode

Console Output:

TokenCap bridge on http://127.0.0.1:4545
Pair the companion: http://127.0.0.1:4545/?pair=8f1c3a09e2
Bridge context pre-warmed in 280ms.
Serving intelligence for: /Users/dev/repos/api-backend
Enter fullscreen mode Exit fullscreen mode

Because the bridge pre-warms intelligence in memory, subsequent context generation queries take milliseconds.

Explore the bridge contract at tokencap.vansharora.app

Top comments (0)