# How to Set Up the Browser Extension API Endpoints for AnythingLLM

> Learn how to set up browser extension API endpoints for AnythingLLM. Integrate seamlessly by accessing authenticated HTTP endpoints for embedding content uploading text and managing API keys.

- Repository: [Mintplex Labs/anything-llm](https://github.com/Mintplex-Labs/anything-llm)
- Tags: how-to-guide
- Published: 2026-03-07

---

**AnythingLLM exposes authenticated HTTP endpoints under `/browser-extension/*` that allow the Chrome/Firefox extension to embed content, upload raw text, and manage API keys through the Express server in [`server/endpoints/browserExtension.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/endpoints/browserExtension.js).**

The browser extension API in AnythingLLM enables direct integration between your local or hosted instance and the official Chrome/Firefox extension. This guide explains how to configure the browser extension API endpoints for AnythingLLM, covering the server-side registration, authentication middleware, and key management flows as implemented in the Mintplex-Labs/anything-llm repository.

## Understanding the Browser Extension Architecture

The browser extension integration relies on four core components that handle routing, authentication, data persistence, and text processing:

- **`browserExtensionEndpoints`** – Registers all public routes (`/browser-extension/*`) in [`server/endpoints/browserExtension.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/endpoints/browserExtension.js) (lines 16-87).
- **`validBrowserExtensionApiKey`** – Express middleware that validates the `Authorization: Bearer <key>` header and populates `response.locals.apiKey` (located in [`server/utils/middleware/validBrowserExtensionApiKey.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/utils/middleware/validBrowserExtensionApiKey.js), lines 7-34).
- **`BrowserExtensionApiKey`** – Prisma model for creating, validating, listing, and revoking keys (defined in [`server/models/browserExtensionApiKey.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/models/browserExtensionApiKey.js), lines 5-30).
- **`CollectorApi`** – Utility class that processes raw text through splitting, chunking, and embedding before storage (referenced in [`server/utils/collectorApi/index.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/utils/collectorApi/index.js)).

## Enabling the Browser Extension API Endpoints

The server automatically loads the browser extension routes during startup. No additional configuration is required beyond the default CORS setup.

In [`server/index.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/index.js), the Express application registers the endpoints via the `browserExtensionEndpoints` function:

```javascript
// server/index.js (lines 84-89)
const { browserExtensionEndpoints } = require("./endpoints/browserExtension");
// ...
browserExtensionEndpoints(apiRouter);   // Registers /browser-extension/*

```

The default CORS configuration (`app.use(cors({ origin: true }))`) already permits cross-origin requests from browser extensions.

## Generating and Managing Browser Extension API Keys

Only users with **admin** or **manager** roles can create browser extension API keys. The system generates keys with the prefix `brx-` followed by a unique identifier.

### Creating Keys via the API

Admin users generate keys by sending a POST request to the key creation endpoint:

```bash
curl -X POST https://your-host/api/browser-extension/api-keys/new \
     -H "Authorization: Bearer <admin-token>"

```

The endpoint returns a JSON object containing the new key:

```json
{ "apiKey": "brx-xxxx" }

```

Source: [`/browser-extension/api-keys/new`](https://github.com/Mintplex-Labs/anything-llm/blob/master/server/endpoints/browserExtension.js#L75-L88)

Alternatively, administrators can create keys through the web interface at **Settings → Browser Extension**, which calls the same backend endpoint via the frontend model.

### Revoking and Listing Keys

The API supports full lifecycle management of browser extension keys:

- **List keys**: `GET /browser-extension/api-keys` returns all visible keys (admin sees all keys; managers see only their own).
- **Revoke specific key**: `DELETE /browser-extension/api-keys/:id` permanently removes the specified key.
- **Self-revoke session**: `DELETE /browser-extension/disconnect` revokes the key currently used for authentication.

## Authenticating Requests from the Extension

All browser extension endpoints require Bearer token authentication in the HTTP headers. The `validBrowserExtensionApiKey` middleware enforces this on every request.

Include the following header in all extension requests:

```

Authorization: Bearer <brx-your-key>

```

The middleware extracts the token, validates it against the `BrowserExtensionApiKey` database model, and either populates `response.locals.apiKey` with the key record or aborts with **403 Forbidden** if invalid. In multi-user mode, the middleware also attaches the associated `user` object to locals.

Source: [`validBrowserExtensionApiKey` middleware implementation](https://github.com/Mintplex-Labs/anything-llm/blob/master/server/utils/middleware/validBrowserExtensionApiKey.js#L11-L33)

## Core API Endpoints for Browser Extension Integration

The browser extension API provides endpoints for health checks, workspace discovery, and content ingestion.

### Health Check and Workspace Discovery

- **`GET /browser-extension/check`** – Validates the API key and returns connection status, the key's database ID, and accessible workspaces.
- **`GET /browser-extension/workspaces`** – Returns the list of workspaces available to the authenticated key holder, used by the extension UI for selection.

Example health check request:

```bash
curl -H "Authorization: Bearer brx-..." \
     https://host/api/browser-extension/check

```

### Content Ingestion Endpoints

The extension can send webpage content to AnythingLLM through two distinct endpoints:

**Embed Content (Persistent Storage)**
`POST /browser-extension/embed-content` accepts raw text, processes it through the collector pipeline, and persists it as a document within the specified workspace.

```bash
curl -X POST https://host/api/browser-extension/embed-content \
     -H "Authorization: Bearer brx-..." \
     -H "Content-Type: application/json" \
     -d '{
       "workspaceId": "workspace-uuid",
       "textContent": "Raw text to embed...",
       "metadata": {"title": "Page Title", "url": "https://example.com"}
     }'

```

**Upload Content (Transient Processing)**
`POST /browser-extension/upload-content` performs the same text processing but does **not** persist a document, making it suitable for one-off summarization tasks without cluttering the workspace.

### Session Management

The disconnect endpoint provides a convenience method for the extension to revoke its own key:

```bash
curl -X DELETE -H "Authorization: Bearer brx-..." \
     https://host/api/browser-extension/disconnect

```

All route definitions are located in [`server/endpoints/browserExtension.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/endpoints/browserExtension.js), with embed/upload logic spanning lines 81-152.

## How Content Embedding Works Under the Hood

When the extension calls `/browser-extension/embed-content`, the server executes a four-stage pipeline:

1. **Workspace Resolution** – The endpoint fetches the target workspace using `Workspace.getWithUser` (multi-user mode) or `Workspace.get` (single-user mode), verifying the API key holder has access.

2. **Text Processing** – The `CollectorApi` class processes the raw text through `processRawText()`, handling chunking and metadata extraction.

3. **Document Creation** – The system calls `Document.addDocuments` to store the processed content, linking the first chunk's location to the workspace.

4. **Telemetry** – An analytics event `browser_extension_embed_content` is dispatched to track usage.

Relevant implementation details appear in [`server/endpoints/browserExtension.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/endpoints/browserExtension.js) lines 87-122, where the `Collector` processes input and `Document.addDocuments` handles persistence.

## Frontend Integration for API Key Management

The React frontend provides a management interface through components in `frontend/src/pages/GeneralSettings/BrowserExtensionApiKey/`. The frontend model abstracts the REST calls:

```javascript
// frontend/src/models/browserExtensionApiKey.js
export async function createKey() {
  return await fetch(`${API_BASE}/browser-extension/api-keys/new`, {
    method: "POST",
    headers: { Authorization: `Bearer ${userToken}` },
  });
}

```

This model mirrors the backend endpoints, allowing administrators to generate keys through the UI while the actual cryptographic generation and storage occur in the `BrowserExtensionApiKey` Prisma model on the server.

## Summary

- **Automatic Registration**: The server loads browser extension endpoints via `browserExtensionEndpoints(apiRouter)` in [`server/index.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/index.js) without additional configuration.
- **Authentication**: All routes require `Authorization: Bearer <brx-key>` headers validated by `validBrowserExtensionApiKey` middleware.
- **Key Management**: Admin users create keys via `POST /browser-extension/api-keys/new`; keys can be listed and revoked through standard REST operations.
- **Content Flow**: The `CollectorApi` processes raw text from the extension before `Document.addDocuments` persists chunks to the selected workspace.
- **Dual Modes**: Use `/embed-content` to save webpage content permanently, or `/upload-content` for transient processing without storage.

## Frequently Asked Questions

### Do I need to configure CORS manually for the browser extension?

No. The default Express configuration in [`server/index.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/index.js) includes `app.use(cors({ origin: true }))`, which permits cross-origin requests from browser extensions. The browser extension API endpoints inherit this CORS policy automatically.

### What permission level is required to create browser extension API keys?

Only **admin** or **manager** users can create browser extension API keys. The `POST /browser-extension/api-keys/new` endpoint validates the requester's role before invoking the `BrowserExtensionApiKey` model to generate the `brx-` prefixed token.

### How does the embed-content endpoint differ from upload-content?

The **`/embed-content`** endpoint persists processed text as a document within the specified workspace using `Document.addDocuments`, making the content available for future queries. The **`/upload-content`** endpoint processes text through the same `CollectorApi` pipeline but does not create a persistent document, serving transient summarization needs without storage overhead.

### Where is the API key validation logic located in the source code?

The validation middleware resides in [`server/utils/middleware/validBrowserExtensionApiKey.js`](https://github.com/Mintplex-Labs/anything-llm/blob/main/server/utils/middleware/validBrowserExtensionApiKey.js) (lines 7-34). This middleware extracts the Bearer token from the `Authorization` header, validates it against the `BrowserExtensionApiKey` Prisma model, and attaches the key record to `response.locals.apiKey` for downstream route handlers.