Frequently asked questions

How to configure model providers, when the bridge is needed, and what ChatPanel can and can't see.

Do I need an API key or to install anything to start chatting?

No. The moment you install the extension you can chat — ChatPanel ships with a small private AI model that runs right in your browser on WebGPU. There's no API key, no account, and nothing to run.

Your first message downloads the model once (about 700 MB, cached in your browser), then it works offline and everything you type stays on your machine. It's a small model, so it's meant for quick help and trying things out — when you want stronger answers, add your own API key (many providers have free tiers), connect a local runner like Ollama or LM Studio, or install the Gateway/Bridge for more. Runs on any OS with a modern Chromium browser (Chrome/Edge 113+); if your browser has no WebGPU, ChatPanel points you to add a key instead.

Can ChatPanel hide my personal info from the model? (PII redaction)

Yes. Turn on Privacy → Redaction (the 🛡 button in the composer, or Settings → Privacy) and ChatPanel replaces sensitive values with opaque placeholders before anything is sent to the model, then restores them in the reply you read. The AI model only ever sees placeholders like [[EMAIL_1]] or [[PERSON_1]]; your real values are restored in the reply, and the mapping stays in your browser. (Tools you've configured — local history search and any MCP integrations — do receive the real values, so they can actually search and act.)

Two ways to replace a value, both set in the custom dictionary:

It applies to every model-bound call — your chat, plus background ones like title and topic generation, autocomplete, and the meeting scribe.

How do I auto-redact names, orgs & locations? (local AI detection)

Patterns (emails, phones, cards, keys) are caught automatically. Detecting names, organizations and locations needs a model — ChatPanel runs it locally, so raw text never leaves your machine. You pick the detector under Settings → Privacy → Detector. Easiest first:

Pick which categories to redact — e.g. turn Locations off to keep city names readable for “how far is X from Y” questions.

Detection is cached, time-limited, and fail-open — if it's slow or down, ChatPanel falls back to pattern redaction so chat never blocks. The detector sees the raw text, so keep it local (the bundled NER and a local LLM both stay on your machine).

What's free vs Pro in redaction?

Free redacts structured secrets — emails, phones, cards, API keys, IPs — on your chat, plus a small custom dictionary, fully reversible. Pro adds AI auto-detection of names / orgs / locations, redaction across page, meeting, history and tool context (not just the chat line), an unlimited dictionary, and per-category control.

What is the ChatPanel Bridge, and why do I need it?

Browser extensions run in a sandbox — for your safety, Chrome won't let a web extension launch programs, read your filesystem, or run a terminal. That's a problem for ChatPanel, because the whole point is to talk to the AI agents already installed on your machine — Claude Code, Codex, GitHub Copilot, Antigravity CLI (Google's successor to Gemini CLI; Gemini CLI remains available for business/enterprise).

The bridge is a tiny source-available helper that runs locally and closes that gap. The extension talks to it over localhost (a loopback connection that never leaves your computer), and the bridge does the things a sandbox can't: it starts your local CLI agents, spawns local MCP servers (a uvx/npx command), and proxies remote MCP servers that refuse browser connections — streaming everything back to the panel.

YOUR COMPUTER · nothing leaves it Your browser ChatPanel side panel (sandboxed) localhost ChatPanel bridge tiny local helper (source-available) runs & proxies Local AI agents Claude Code · Codex · Antigravity CLI Local MCP servers npx / uvx — spawned for you Remote MCP servers proxied — no browser-origin block

One tiny helper, three jobs: run your CLI agents, spawn local MCP servers, and reach remote MCP servers that block browsers. No ChatPanel cloud in the path

Do you always need it? No — only when something must run outside the browser sandbox: a local CLI agent, a local (command) MCP server, or a remote MCP server that blocks browser origins. If you just point ChatPanel at a cloud API or a local model server (your own OpenAI/Anthropic/Ollama endpoint), and use only remote MCP servers that accept browser connections, the extension talks to them directly and no bridge is required.

What is the ChatPanel Gateway? (privacy for tools outside the extension)

The ChatPanel Gateway is a local redacting proxy / model router. Point any OpenAI- or Anthropic-compatible client at it on localhost — a coding agent (OpenCode, aider, Pi), your own scripts, or the ChatPanel extension itself — and it redacts every request, then forwards the cleaned traffic to either a model API you bring (your own key — no bridge needed) or your subscription CLI agents (Codex / Claude Code, via the bridge). Whatever runs behind it only ever sees placeholders like [[PERSON_1]] — the real values never leave your machine.

YOUR COMPUTER · localhost only — nothing leaves it Any OpenAI/Anthropic client OpenCode · aider · scripts · the ChatPanel extension ChatPanel Gateway redact ⇄ restore model router no bridge via bridge Model API — your key (no bridge) OpenAI · Anthropic · local · OpenRouter Bridge → Codex / Claude Code your subscription login

Point any OpenAI/Anthropic client at the gateway; it redacts, then routes to a model API you bring (no bridge) or your subscription agents via the bridge — chosen by the request's model name. No ChatPanel cloud in the path

It's not name-detection only — the gateway runs the same redaction engine as the extension: deterministic patterns (emails, phones, cards, SSNs, API keys, IPs), a custom dictionary with optional permanent aliases, and name/org/location detection via a bundled NER (an in-process NER model — no Python, no extra service) or a local LLM. It also speaks the OpenAI and Anthropic protocols, supports streaming, and — as a model router — can either drive your subscription agents (via the bridge) or forward to a model API endpoint you bring.

You'll configure it right here in the extension — enter the gateway URL and set up the privacy rules, registered clients, and logging, the same way you configure the bridge and your agents today.

Use ChatPanel from Codex, Claude Code & other CLI agents (MCP)

Any agent that speaks MCP — Copilot in VS Code, Cursor, Claude Code, Codex — can reach your ChatPanel history (past chats, meeting transcripts and notes — redacted on the way out), your memory (the durable facts you've told ChatPanel about yourself), every skill installed on your machine, the small models that answer in milliseconds, the privacy detector, and the coding agents you're already signed in to. One server: chatpanel-gateway mcp.

The point: work that belongs on your machine stops having to be pasted into a cloud agent's context. Copilot can ask your Claude Code a question, check a log for personal data before it goes anywhere, or hand a refactor to an agent running in your own directory.

Two commands — you never touch a config file

You don't need to find, open or edit config.toml. Open a terminal and paste these two lines:

# 1 — install ChatPanel (macOS / Linux, no Node.js needed; the gateway brings the bridge)
curl -fsSL https://dl.chatpanel.net/install.sh | bash

# 2 — connect every agent you already have
chatpanel-gateway connect

On Windows, step 1 is irm https://dl.chatpanel.net/install.ps1 | iex in PowerShell. Then quit and reopen Codex / Claude Code and ask it something only your history knows — “what did we decide in Tuesday's meeting?”

Step 2 detects the agents installed on your machine, writes the correct config for each one in its own format, backs up every file it touches, and never modifies MCP servers you already had. Running it twice changes nothing the second time. To see exactly what it would do while writing nothing:

chatpanel-gateway connect --dry-run

It configures Codex, Claude Code and Gemini/Antigravity for you, and prints an exact copy-paste snippet for the agents whose config format it won't risk rewriting (OpenCode, Copilot, Hermes, Pi) — a guessed format that clobbers your config would be worse than asking.

Just one agent? Its own CLI can do it — still no config file

# Codex
codex mcp add chatpanel -- chatpanel-gateway mcp

# Claude Code  (--scope user = available in every project)
claude mcp add --scope user chatpanel chatpanel-gateway mcp

Confirm it landed with codex mcp list or claude mcp get chatpanel, then restart the agent. To undo either: codex mcp remove chatpanel / claude mcp remove chatpanel.

Prefer to edit the config files yourself? (optional)

Codex — ~/.codex/config.toml:

[mcp_servers.chatpanel]
command = "chatpanel-gateway"
args = ["mcp"]

If your Codex is a managed/corporate build and a tool call is rejected with “Automatic approval review failed” (an auto_review guardian can't assess a tool it doesn't know), pre-approve ChatPanel's read-only tools — one block per tool:

[mcp_servers.chatpanel.tools.smart_search]
approval_mode = "approve"
[mcp_servers.chatpanel.tools.search_history]
approval_mode = "approve"
[mcp_servers.chatpanel.tools.get_record]
approval_mode = "approve"
[mcp_servers.chatpanel.tools.find_related]
approval_mode = "approve"
[mcp_servers.chatpanel.tools.list_history]
approval_mode = "approve"
[mcp_servers.chatpanel.tools.recall]
approval_mode = "approve"
[mcp_servers.chatpanel.tools.list_skills]
approval_mode = "approve"
[mcp_servers.chatpanel.tools.open_skill]
approval_mode = "approve"
[mcp_servers.chatpanel.tools.read_skill_file]
approval_mode = "approve"

(chatpanel-gateway connect writes exactly these for you. remember and forget are left out on purpose — they write to your memory, so you approve them once yourself.)

Gemini / Antigravity — ~/.gemini/settings.json:

{ "mcpServers": { "chatpanel": { "command": "chatpanel-gateway", "args": ["mcp"] } } }

OpenCode — opencode.json:

{ "mcp": { "chatpanel": { "type": "local", "command": ["chatpanel-gateway", "mcp"], "enabled": true } } }

The tools: smart_search, search_history, get_record, find_related, list_history, list_briefs, get_brief (your chats/meetings/notes and what they add up to); recall, remember, forget (your durable facts — name, preferences, what you're working on); list_skills, open_skill, read_skill_file (your installed skills); redact_check, read_document, decide, rerank, web_search (what this machine can do); and list_models, ask_model, ask_status (your models). Everything a history tool returns is redacted at your configured tier — a [[PLACEHOLDER]] in a result is the privacy working, not a bug. Skills and coding agents come from the bridge (optional): without it, the rest still works and those tools tell you how to install it. See what's running any time with chatpanel-gateway local.

VS Code (GitHub Copilot) & Cursor

VS Code — .mcp.json in the project, or mcp.json in your user profile for every project:

{ "servers": { "chatpanel": { "type": "stdio", "command": "chatpanel-gateway", "args": ["mcp"] } } }

Cursor — the same shape in ~/.cursor/mcp.json, under mcpServers rather than servers.

Ask another model — and hand over real work

ask_model passes a question to any model this machine can reach and returns the answer. Every answer says which model produced it, whether the text left your machine, and what redaction replaced on the way out — you asked a server on localhost, so that line is the only way to know the question went to a cloud. list_models groups by the same fact, so an agent can keep sensitive text on the box by picking one that runs here.

The model you ask is blind: no files, no shell, no web, no tools. It answers from the prompt and nothing else, so asking it can't reach anything the caller couldn't already reach — and the caller can't raise that ceiling, because it comes from your config file, not the conversation.

delegate_task is the other half: one of your coding agents running here, with its real tools, in a directory you name — the refactor a remote agent would need forty file reads to attempt. It doesn't exist until you switch it on: with no directories configured it isn't listed, isn't callable, and isn't mentioned to the model. To enable it, add the directories an agent may work in to ~/.chatpanel/gateway.config.json and restart:

{ "mcp": { "ask": { "delegate": {
    "roots": ["/Users/you/code/app"],
    "permissionMode": "acceptEdits"
} } } }

acceptEdits (the default) lets it edit files in that directory while the shell still asks — which is denied, since nobody's there to answer. "default" makes it read-only; "bypassPermissions" also gives it the shell. A path outside every root is refused, and .. can't climb out.

How should I install the gateway? npm first, binary as a fallback

Install with npm if you can. Redaction and routing behave identically either way, but the local AI models — speech-to-text, voice cloning, diarization, the bundled NER — depend on which runtime is underneath, and the two are not equivalent.

# the recommended route (needs Node.js 18+)
npm i -g @chatpanel/gateway --ignore-scripts
chatpanel-gateway --install     # runs it at login

Why --ignore-scripts? It is the install, not a workaround. The gateway has no install script of its own, and the only two in its dependency tree are ones it needs nothing from: onnxruntime-node's downloads the CUDA/TensorRT providers on Linux x64 (225 MB from NuGet) which the gateway never loads — it asks ONNX Runtime for cpu on every engine — and its CPU bindings for macOS, Windows and Linux are already inside the package; protobufjs's prints a version-range advisory. Skipping them also means a global install runs no code from 114 transitive packages. npm 12 and newer blocks those scripts anyway and prints a warning that reads like a failure — it is not, and the flag turns it into a quiet install. Do not take npm's suggested --allow-scripts=onnxruntime-node,protobufjs: on Linux x64 it starts the 225 MB CUDA download.

Most people reading this already have Node: it is the same prerequisite the CLI coding agents use. If node -v prints a version, you are ready.

npm says EACCES and tells you to chown ~/.npm? That hint is about npm's cache and usually is not the problem. Look at the npm error path line instead: the folder that is not yours is your global npm folder (npm prefix -g), typically left root-owned by an earlier sudo npm i -g. If that folder is inside your home folder, take it back with sudo chown -R "$(whoami)" "$(npm prefix -g)" and run the install again, without sudo. If it is a system folder such as /usr/local, use the standalone binary below instead. (It is npm i, not npx i: npx would run an unrelated package called i.)

What you get on npm that the binary cannot give you:

The standalone binary is still there for machines without Node, or where installing it is a hassle:

# macOS / Linux
curl -fsSL https://dl.chatpanel.net/install.sh | bash

# Windows (PowerShell)
irm https://dl.chatpanel.net/install.ps1 | iex

One self-contained file, nothing else to install — the bridge is inside it. It does redaction, routing, the MCP server and Kokoro text-to-speech perfectly well. A single-file executable cannot carry a native library, so it runs models on the WebAssembly runtime — full-precision, single-threaded — which is why the engines above are out of reach there and the rest are slower.

Not sure which you are on? The extension's Gateway tab says so (and warns if you are on the slower build), or GET /health → stt.runtime reports native or wasm.

Don't install both. This one bites hard: install.sh puts a binary in ~/.local/bin, which usually comes before npm's directory on your PATH, so it wins — and the login service keeps launching it. The symptom is npm appearing to do nothing: you install it, and the extension still reports the WASM build and still says voice cloning is unavailable. To switch to npm: delete ~/.local/bin/chatpanel-gateway, then re-run chatpanel-gateway --install so the service points at the npm one.

With redaction on, how do my tools (MCP) still get the real data?

The model only ever sees placeholders like [[PERSON_1]] — but a tool that searches or acts needs the real value to work. The gateway squares this with a per-request vault (a private map of [[PERSON_1]] → "Alex Rivera"): it restores the real value just-in-time so the tool runs on it, then re-redacts the tool's result before the model sees it. The agent never sees the real value; the tool does.

Follow the name, left → right real value hidden code 1 🧑 You ask on your computer "Alex Rivera" 2 🛡️ ChatPanel hides the name [[PERSON_1]] 3 🤖 AI model sees only the code [[PERSON_1]] 4 🛡️ ChatPanel reveals it for your tool "Alex Rivera" 5 🔧 Your tool runs on the real name real results 6 🛡️ You get the answer AI never saw the name real names

Read 1 → 6. The real name (amber) becomes a code (green) the moment it could reach the AI, and is revealed only between ChatPanel and your own tool. The AI never sees the real name — you always do

Step by step, for “search for Alex Rivera’s open tickets”:

  1. You ask → the gateway redacts → the model reads search [[PERSON_1]]'s tickets.
  2. The model calls the tool with the placeholder: search({ query: "[[PERSON_1]]" }).
  3. The gateway restores the args from the vault → search({ query: "Alex Rivera" }).
  4. Your client runs the tool on the real value and returns real tickets.
  5. The gateway re-redacts the result into the same vault → the model sees [[PERSON_1]] again.
  6. The model's answer streams back → the gateway restores placeholders → you read the real names.

Who actually runs the tool? Not the model, and not ChatPanel. With function/tool calling the model only asks for a tool by name (it returns the request and pauses) — your client runs it, the same as it would without ChatPanel. The gateway just translates the values (codes ⇄ real) on the arguments and results as they pass through. Model requests → client executes → gateway translates.

One control governs the trust boundary — Gateway → Tools receive:

Under the hood — the gateway, the harness & tool data (technical)

The gateway is the harness — ChatPanel implements it (the shared @chatpanel/pii engine); you don't write any glue. It owns a per-request vault, redacts on the way out, restores on the way back, and brokers tool arguments. Components and the flow (method names omitted):

ChatPanel Gateway — the harness Detector in-process NER · local LLM Redaction engine redact ⇄ restore Vault placeholder ⇄ real (per request) Tool broker (the harness) real args for local · keep code for remote MCP finds names Client CLI agent / extension Your tool runs in the client Model / agent Bridge → Codex / Claude · or a model API 1 your text 8 answer (real) 3 clean text 4 tool call (code) 7 safe result 5 real args 6 real result

green = the code the model sees · amber = the real value (only the client, its tool, and you). The Vault is the one shared map both the Redaction engine and the Tool broker use.

The harness can only swap values on traffic that crosses the gateway — the prompt, the reply, and tool calls relayed through it. So:

  • Tools surfaced to the gateway (OpenAI tool-calls / the bridge's tool relay) are brokered: real args in, results re-redacted out. These get valid data.
  • Tools an agent runs entirely on its own — that the gateway never sees — operate on the redacted placeholders the agent was handed. That's the privacy guarantee holding (no PII leaks), but the trade-off is those uncontrolled tools act on codes, not real values. You can't both hide a value from the agent and have its opaque internal tools use the real one — only a layer that holds the vault (the gateway/harness) can restore it, and only for calls it can see.

What about Codex / Claude Code (subscription agents via the Bridge)?

Here the gateway redacts the prompt the agent receives, so the agent reasons on placeholders. But a CLI agent runs its own tools — reading files, running shell, its own MCP servers — as local side effects the gateway never sees, and it calls its own model under your subscription. So the gateway does not mediate those: the agent's tools can read your real local files directly (the gateway redacted the conversation, not your disk), and what the agent gathers goes to its model outside the gateway.

  • What the gateway does control: the text you send into the agent (redacted) and the reply you get back (restored), plus any tools ChatPanel arms (page tools / MCP from the client) — those are relayed through the harness and brokered.
  • What it doesn't: a trusted local agent's own file/shell access and its direct model calls. The gateway scrubs PII from the conversation; it does not sandbox the agent.
  • Want every model request redacted end-to-end? Use the API backend instead — then the gateway sits in the full path and redacts each request to the model, rather than handing the job to a self-driving agent.

Bridge vs Gateway — which do I need, and how do I install?

Install the Gateway — it brings the Bridge. Since gateway 0.6.92 the two ship as one install: the Gateway carries the Bridge inside it and starts it alongside itself, so there is one command to run and one thing to update. They stay two processes on purpose — the Bridge is the small, dependency-free process that spawns your coding agents and holds your source-control tokens; the model runtimes (redaction, speech, voice) live in the Gateway — so a Gateway restart never interrupts a running agent.

Install it — npm is the recommended route when you have Node.js:

# recommended (needs Node.js 18+, which you likely already have)
npm i -g @chatpanel/gateway --ignore-scripts   # two commands — PowerShell has no &&
chatpanel-gateway --install                   # gateway on http://127.0.0.1:4320, bridge on :4319
# --ignore-scripts is part of the install: the only two install scripts in the tree fetch CUDA providers
# the gateway never loads, and print a version advisory. npm 12+ blocks them anyway — the flag makes that
# a quiet install instead of a warning that looks like a failure. Details above, under "How should I install".
# Updating on Windows: stop the running gateway first (chatpanel-gateway --stop), or npm fails with EBUSY on a loaded DLL.
# Windows and "chatpanel-gateway is not recognized"? npm's global bin folder is not on this shell's PATH yet:
# open a new PowerShell, or run it by path:  node "$(npm root -g)/@chatpanel/gateway/bin/chatpanel-gateway.js" --install

# no Node? the standalone binary works too — some local models are out of reach
curl -fsSL https://dl.chatpanel.net/install.sh | bash    # macOS / Linux
irm https://dl.chatpanel.net/install.ps1 | iex           # Windows (PowerShell)

Both do redaction and routing identically. The binary cannot run the fastest local models — voice cloning and Parakeet speech-to-text among them — and is slower on the rest; see how should I install the gateway. Install one, not both: the binary shadows npm on your PATH, which makes an npm install look like it did nothing.

Then point any OpenAI-compatible client at http://127.0.0.1:4320/v1. The request's model name (codex, claude, …) selects which agent the Bridge drives behind it — or switch the gateway to its api backend to forward to a provider endpoint instead.

Use it as a model in the ChatPanel extension — Settings → API tab → add a custom OpenAI-compatible endpoint:

Pick that model from the side-panel dropdown and chat as usual; every request is redacted on the way out and restored in the reply. You can also configure the gateway directly from the extension's Gateway tab. The three pieces — extension, bridge, gateway — are versioned and released independently.

Why did the bridge ask to access my Desktop / Documents / Downloads?

Those are macOS privacy prompts (Apple's TCC system), not something the bridge wants for itself. The bridge launches your local agents, and when one of them reads or writes a file in a protected folder, macOS asks your permission and attributes the prompt to the parent app — the bridge.

You can grant or deny per folder; denying simply limits the agents to non‑protected directories. They only touch files when you ask a question that needs them (or when you point an agent at a working directory).

If the prompts reappear after a bridge update, that's expected: macOS ties approvals to an app's exact code signature, so a new build re-asks. A fully signed & notarized release keeps the approvals stable across updates.

Does my data go through ChatPanel's servers?

No. ChatPanel is local-first. Your prompts, keys, and history live in your browser; the bridge runs entirely on your machine. Content goes only to the model or agent endpoint you choose — we have no cloud in the data path and never see your conversations.

Can I read the source? How do I know what it sends where?

The code is not public — the extension, the bridge and the gateway ship as ordinary, minified JavaScript, and only the redaction engine is source-available (under PolyForm Shield). What we publish instead is a set of guarantees you can check yourself, without trusting us or reading anything:

If any of these is ever untrue on your machine, that is a security bug: [email protected].

What protections does the bridge have against malicious web pages?

The bridge runs a tiny server on your own computer, so it's built to ignore anything that isn't really you:

And remember: your chats never go through us. The bridge only talks to the agents and model endpoints you choose.

How do I install or update the bridge?

Install it once from the ChatPanel Install section; it runs quietly in the background and the extension detects it automatically. To use only cloud/API models, you can skip the bridge entirely.

How do I configure a model provider?

Open Settings → API, then configure an endpoint. You can use a provider preset for common services, or choose Custom / self-hosted for a private gateway, local server, or any OpenAI- or Anthropic-compatible endpoint.

  1. Choose a provider. Presets fill the base URL, API style, setup links, and common headers.
  2. Choose the auth method. Some providers use API keys; some support OAuth sign-in; Hugging Face can use either depending on how you set it up.
  3. Add credentials. API keys and OAuth tokens are stored in your browser storage, not sent to ChatPanel's servers.
  4. Load models. This fetches the provider's model catalog so you can search or pick a model ID.
  5. Click Test. This sends a tiny chat request and is the real check that auth, model ID, and max-token settings work.
  6. Save. The endpoint then appears in ChatPanel as a chat target.

Supported presets include OpenAI, Anthropic, OpenRouter, Hugging Face Router, Google AI Studio / Gemini, NVIDIA NIM, Groq, Mistral, Cohere, Cerebras, DeepInfra, Fireworks, Together AI, xAI, Vercel AI Gateway, GitHub Models, Cloudflare Workers AI, Ollama, LM Studio, llama.cpp, and vLLM.

Custom configuration is supported. You can set the base URL, OpenAI vs Anthropic API style, extra headers, extra request JSON, temperature, max tokens, model ID, and a separate fast autocomplete model. Use this for local servers, internal gateways, proxy services, or any provider that exposes a compatible chat-completions API.

Why did Load models work but Test failed?

A model-list request is not always the same as a chat request. Some providers expose a public or less-restricted model catalog, then require stricter auth, billing, quota, or parameter limits for /chat/completions. In ChatPanel, Load models only proves the catalog endpoint responded; Test proves the selected model can actually answer.

Why does Hugging Face sign-in fail in the downloaded extension?

Hugging Face OAuth needs an exact redirect URI. The official Chrome Web Store and Microsoft Edge Add-ons versions of ChatPanel each have a stable extension ID, so their redirect URIs are registered and the built-in Sign in with Hugging Face button works without extra setup.

If you download the zip and load it manually with Developer mode, Chrome may give that unpacked copy a different extension ID. That also changes the OAuth redirect URI, so Hugging Face can reject the login page with an authorization/403 error.

For a downloaded or unpacked build, either use the official store version or create your own Hugging Face OAuth app as a public client with no client secret. In ChatPanel, open Settings → Endpoints, choose Sign in with Hugging Face, copy the displayed redirect URI into the Hugging Face app, enable the inference-api scope, then paste that app's client ID into ChatPanel's optional Hugging Face client ID field. The token stays in your browser storage; it is not sent to ChatPanel's servers.

Does ChatPanel support MCP? Can it act as an MCP server?

Yes — and because ChatPanel is two pieces (the extension and the local bridge), together they cover every role in the Model Context Protocol:

Every MCP connection runs on your machine — the bridge listens only on 127.0.0.1, and nothing is brokered through ChatPanel's cloud. Free includes one MCP tool server; Pro is unlimited.

Want your history, memory and skills inside Codex or Claude Code instead? That's a separate, read-only server, and it takes two commands — see Use ChatPanel from Codex, Claude Code & other CLI agents.

How does ChatPanel turn my browser into an MCP server?

This is the part people find surprising. A command-line agent like Claude Code or Codex has no idea what a browser is — it runs in a terminal. ChatPanel bridges that gap by making your real, logged-in browser tab look like an MCP server the agent can call tools on. Ask the agent to "read this page and click the top result," and under the hood it's just calling inspect_page and click_element — MCP tools that happen to run on your actual Chrome tab.

Three pieces play three roles, and none of them does the others' job:

YOUR COMPUTER · 127.0.0.1 only · nothing leaves it CLI agent Claude Code · Codex MCP client tools/call ChatPanel bridge MCP server (relay) :4319/mcp · no browser relay Your browser tab extension executes real, logged-in page Tools exist only while a chat turn is running — the session is created when you send and destroyed when the reply ends.

Your browser becomes a tool the agent can call — but only for the moment it's working. Ephemeral by design

Why is it ephemeral — and is that a security feature?

Yes, deliberately. Unlike a normal MCP server that stays on as long as it's connected, ChatPanel's browser tools only exist during an active chat turn. The instant the agent finishes replying, the session is torn down and the endpoint advertises zero tools again. There's no always-on, remotely controllable surface sitting on your machine waiting to drive your browser.

Combined with the fact that the bridge listens on 127.0.0.1 only (never the network), this shrinks the attack surface to a sliver: the tools are reachable only in the brief window when you started a chat with Act on page on. Outside that window, even a program already running on your computer finds nothing to call. It's defense-in-depth, not a login — but it means your real, logged-in tabs aren't permanently exposed just because the helper app is running.

Can I use my own command-line agent (OpenCode, Pi, …)? Pro

GitHub Copilot, DeepSeek Harness, OpenCode, Kiro and Pi now ship as built-in presets — just pick them in Settings → Agents and connect a model. No commands or flags to figure out; ChatPanel already knows how to talk to each one (including the small details that used to trip people up, like OpenCode needing its non-interactive run mode).

Want to use a different tool? With Pro you can point ChatPanel at any command-line agent — Ollama, a script of your own, anything that runs in a terminal. Add an agent, choose “custom — bring your own Agent”, and fill in three fields:

Everything stays on your machine — the command runs locally and your chats never route through our cloud.

How do the live meeting notes work? Free · first 10

On Zoom, Google Meet, Microsoft Teams, and Webex, ChatPanel reads the meeting's live captions and turns them into running notes — key points, decisions, and action items that refresh as the conversation goes. Afterward you get a full transcript you can search, or ask questions about (“what did we decide on pricing?”).

It all happens inside your browser — no bot joins the call and nothing is uploaded. It only ever reads the captions the meeting platform already shows — never your microphone, camera, or screen. Turn on captions in your meeting app and ChatPanel does the rest. You can save the notes or transcript to a file when you're done.

Free captures your first 10 meetings; Pro is unlimited.

ChatPanel's meeting panel with a searchable list of past meeting transcripts.
Meeting transcripts are saved and searchable.

Are my chats saved? Can I search them?

Yes. Every conversation is saved on your computer and is instantly searchable — search by what you said, by title, or by topic. Nothing is uploaded; your history lives in your browser.

There's also a topic map: a visual layout of everything you've discussed, grouped into clusters by subject. Click a point to jump back into that chat, or to filter down to one topic. It's an easy way to rediscover something you talked about weeks ago.

ChatPanel's chat history with a topic map grouping past conversations by subject.
Search every past chat, or browse the topic map.

Can ChatPanel fill in forms and click for me?

Yes — turn on Act on Page and ask in plain words. ChatPanel can read a form on the current tab and fill in fields, choose options, and click buttons on your behalf, so you can hand off repetitive web tasks.

It only acts when you switch the feature on, and only on the tab you're working in. Everything runs locally in your browser. This works with any chat model you've connected.

Can ChatPanel search the web?

Yes — web search is built in. Type /search <query> anywhere in a message, or just ask a question that needs current information, and ChatPanel fetches live results, reads the most relevant pages, ranks them against your question, and feeds them in as context — with clickable source links right in the answer. It works with every model and agent you've connected, even ones that don't support tools, because the results ride along as context.

Searches run quietly in the background — no browser tabs pop open — and your query goes only to the search engines you pick. Capable models can also decide to search on their own mid-conversation, so a follow-up like “how about the other one?” triggers a fresh lookup automatically. Choose your engines, result counts, and an optional clean reader under Settings → Tools → Web search.

Can I get every answer back in a specific language?

Yes. Set Settings → Preferences → Response language and ChatPanel enforces it across every model — replies come back in your chosen language no matter what language you type in, unless you explicitly ask for another. Leave it on Auto to match each message. ChatPanel also quietly tells every model today's date, so answers about “now” and recent events aren't stuck behind an old training cutoff.

Can it draw diagrams on Excalidraw, draw.io or tldraw? Pro

Yes. On Excalidraw, draw.io, and tldraw, ChatPanel recognizes the canvas and lets your agent build the drawing as structured data — every shape placed at exact coordinates in a single pass, using each app's own scene format — instead of dragging the mouse pixel by pixel. Flowcharts, architecture diagrams, and wireframes come out clean and aligned, and the agent can read what's already on the canvas to add to it without overlapping.

This structured-insert path is a Pro feature. On Free, ChatPanel falls back to the universal pixel-drawing tools, which are far slower and less precise on these apps.

Can I export or back up my chats? Pro

Yes. From Settings → Account you can export a complete snapshot of everything to a single file — your settings, connected models, agents, tools, skills, web-search and privacy/redaction preferences, all chat history, and all captured meetings (transcripts, summaries, and topics) — plus your endpoint sign-ins so you don't have to re-connect. Restore it on another computer to move your whole setup across, or just keep it as a backup.

Optional password protection. Type a password in the export box and the file is encrypted (AES-256) on your device — useless to anyone without it. You'll need the same password to restore. There's no recovery, so if you forget it the data is gone — that's the trade-off for a zero-knowledge file only you can open. Leave the box blank to export a plain, browsable .zip instead.

The file contains your API keys and sign-ins, so keep it somewhere safe (or use a password). Your Pro license isn't part of the export — it re-activates from your purchase email.

Can ChatPanel back up my data automatically? Pro

Yes — turn on daily automatic backup to disk in Settings → Account. Once a day, whenever something has changed, ChatPanel writes the full backup into your Downloads → ChatPanel Backups folder, rotating by weekday so the last seven days are always kept. It runs in the background — no prompts, no clicking.

This is your safety net for reinstalls. Your data normally lives inside the extension, which the browser ties to the extension's identity — so a manual reinstall can sometimes leave the old data stranded. Because the daily backup sits on your disk, outside the extension, it survives that: after reinstalling, just Restore from file with the newest backup. You can also give the daily files a password so they're encrypted at rest, which is worth doing if your Downloads folder syncs to the cloud or you share the machine.

Everything stays on your device — automatic backups are written to your local disk and are never uploaded to ChatPanel.

How do I reset my skills to the latest defaults?

Your skills are saved in your browser the first time ChatPanel runs. After that, ChatPanel keeps your copy — so if a new version ships improved built-in prompts (Summarize, Explain, Extract, Code review…), simply refreshing won't overwrite the ones you already have. That's deliberate: it protects any edits you've made. To pull in the newest defaults, clear the saved skills once and they'll re-seed from the current version.

  1. Open the ChatPanel Settings page, right-click anywhere on it and choose Inspect, then click the Console tab.
  2. Paste this and press Enter:
const k = 'chatpanel:settings';
const s = (await chrome.storage.local.get(k))[k] || {};
delete s.skills;                 // drop saved skills → re-seed defaults
await chrome.storage.local.set({ [k]: s });
location.reload();

That resets only your skills — endpoints, agents, history, and your license are left untouched. (Custom skills you created will be removed too, since they live in the same list, so copy any prompts you want to keep first.)

What can I do with Notes?

Notes is a local notebook your AI writes with you. Capture anything — a chat reply, a page, a meeting takeaway — into notes that link to each other with [[wiki-links]], so your workspace becomes a connected graph you can browse and search.

Inside a note you can: co-write with your model (it edits alongside you, with authorship tracked so you can see who wrote what); research across your own notes, chats and meetings and the web; and turn a selection into a plan — ChatPanel spins up a linked plan note and drops a link back in place. Everything is stored on your machine and encrypted at rest.

Free keeps your first 10 notes (the count in the header shows current(deleted)/10 — deleting doesn't free a slot, since the cap is on notes ever created). Pro is unlimited notes, plus the co-writer model router and automatic backups.

Can I talk instead of type? Is speech-to-text private?

Yes. With the Gateway installed, ChatPanel transcribes your voice with a speech-to-text model that runs entirely on your own machine — dictate a chat, a note, or a question, and it's turned into text locally. Your audio never leaves your computer, and no cloud speech API or key is involved.

The Gateway runs the model in-process (no Python, no second app to babysit) and downloads a small Whisper model on first use, then works offline. It auto-detects your language, and — because it's the same local pipeline as redaction — recognized text can be PII-scrubbed before it ever reaches a cloud model. This is separate from meeting transcripts, which read a call's live captions (never its audio) and don't need the Gateway.