How to Set Up the Browser Extension API Endpoints for AnythingLLM
AnythingLLM exposes authenticated HTTP endpoints under /browser-extension/* that allow the Chrome/Firefox extension to embed content, upload raw text, and manage API keys through the Express server in server/endpoints/browserExtension.js.
The browser extension API in AnythingLLM enables direct integration between your local or hosted instance and the official Chrome/Firefox extension. This guide explains how to configure the browser extension API endpoints for AnythingLLM, covering the server-side registration, authentication middleware, and key management flows as implemented in the Mintplex-Labs/anything-llm repository.
Understanding the Browser Extension Architecture
The browser extension integration relies on four core components that handle routing, authentication, data persistence, and text processing:
browserExtensionEndpoints– Registers all public routes (/browser-extension/*) inserver/endpoints/browserExtension.js(lines 16-87).validBrowserExtensionApiKey– Express middleware that validates theAuthorization: Bearer <key>header and populatesresponse.locals.apiKey(located inserver/utils/middleware/validBrowserExtensionApiKey.js, lines 7-34).BrowserExtensionApiKey– Prisma model for creating, validating, listing, and revoking keys (defined inserver/models/browserExtensionApiKey.js, lines 5-30).CollectorApi– Utility class that processes raw text through splitting, chunking, and embedding before storage (referenced inserver/utils/collectorApi/index.js).
Enabling the Browser Extension API Endpoints
The server automatically loads the browser extension routes during startup. No additional configuration is required beyond the default CORS setup.
In server/index.js, the Express application registers the endpoints via the browserExtensionEndpoints function:
// server/index.js (lines 84-89)
const { browserExtensionEndpoints } = require("./endpoints/browserExtension");
// ...
browserExtensionEndpoints(apiRouter); // Registers /browser-extension/*
The default CORS configuration (app.use(cors({ origin: true }))) already permits cross-origin requests from browser extensions.
Generating and Managing Browser Extension API Keys
Only users with admin or manager roles can create browser extension API keys. The system generates keys with the prefix brx- followed by a unique identifier.
Creating Keys via the API
Admin users generate keys by sending a POST request to the key creation endpoint:
curl -X POST https://your-host/api/browser-extension/api-keys/new \
-H "Authorization: Bearer <admin-token>"
The endpoint returns a JSON object containing the new key:
{ "apiKey": "brx-xxxx" }
Source: /browser-extension/api-keys/new
Alternatively, administrators can create keys through the web interface at Settings → Browser Extension, which calls the same backend endpoint via the frontend model.
Revoking and Listing Keys
The API supports full lifecycle management of browser extension keys:
- List keys:
GET /browser-extension/api-keysreturns all visible keys (admin sees all keys; managers see only their own). - Revoke specific key:
DELETE /browser-extension/api-keys/:idpermanently removes the specified key. - Self-revoke session:
DELETE /browser-extension/disconnectrevokes the key currently used for authentication.
Authenticating Requests from the Extension
All browser extension endpoints require Bearer token authentication in the HTTP headers. The validBrowserExtensionApiKey middleware enforces this on every request.
Include the following header in all extension requests:
Authorization: Bearer <brx-your-key>
The middleware extracts the token, validates it against the BrowserExtensionApiKey database model, and either populates response.locals.apiKey with the key record or aborts with 403 Forbidden if invalid. In multi-user mode, the middleware also attaches the associated user object to locals.
Source: validBrowserExtensionApiKey middleware implementation
Core API Endpoints for Browser Extension Integration
The browser extension API provides endpoints for health checks, workspace discovery, and content ingestion.
Health Check and Workspace Discovery
GET /browser-extension/check– Validates the API key and returns connection status, the key's database ID, and accessible workspaces.GET /browser-extension/workspaces– Returns the list of workspaces available to the authenticated key holder, used by the extension UI for selection.
Example health check request:
curl -H "Authorization: Bearer brx-..." \
https://host/api/browser-extension/check
Content Ingestion Endpoints
The extension can send webpage content to AnythingLLM through two distinct endpoints:
Embed Content (Persistent Storage)
POST /browser-extension/embed-content accepts raw text, processes it through the collector pipeline, and persists it as a document within the specified workspace.
curl -X POST https://host/api/browser-extension/embed-content \
-H "Authorization: Bearer brx-..." \
-H "Content-Type: application/json" \
-d '{
"workspaceId": "workspace-uuid",
"textContent": "Raw text to embed...",
"metadata": {"title": "Page Title", "url": "https://example.com"}
}'
Upload Content (Transient Processing)
POST /browser-extension/upload-content performs the same text processing but does not persist a document, making it suitable for one-off summarization tasks without cluttering the workspace.
Session Management
The disconnect endpoint provides a convenience method for the extension to revoke its own key:
curl -X DELETE -H "Authorization: Bearer brx-..." \
https://host/api/browser-extension/disconnect
All route definitions are located in server/endpoints/browserExtension.js, with embed/upload logic spanning lines 81-152.
How Content Embedding Works Under the Hood
When the extension calls /browser-extension/embed-content, the server executes a four-stage pipeline:
-
Workspace Resolution – The endpoint fetches the target workspace using
Workspace.getWithUser(multi-user mode) orWorkspace.get(single-user mode), verifying the API key holder has access. -
Text Processing – The
CollectorApiclass processes the raw text throughprocessRawText(), handling chunking and metadata extraction. -
Document Creation – The system calls
Document.addDocumentsto store the processed content, linking the first chunk's location to the workspace. -
Telemetry – An analytics event
browser_extension_embed_contentis dispatched to track usage.
Relevant implementation details appear in server/endpoints/browserExtension.js lines 87-122, where the Collector processes input and Document.addDocuments handles persistence.
Frontend Integration for API Key Management
The React frontend provides a management interface through components in frontend/src/pages/GeneralSettings/BrowserExtensionApiKey/. The frontend model abstracts the REST calls:
// frontend/src/models/browserExtensionApiKey.js
export async function createKey() {
return await fetch(`${API_BASE}/browser-extension/api-keys/new`, {
method: "POST",
headers: { Authorization: `Bearer ${userToken}` },
});
}
This model mirrors the backend endpoints, allowing administrators to generate keys through the UI while the actual cryptographic generation and storage occur in the BrowserExtensionApiKey Prisma model on the server.
Summary
- Automatic Registration: The server loads browser extension endpoints via
browserExtensionEndpoints(apiRouter)inserver/index.jswithout additional configuration. - Authentication: All routes require
Authorization: Bearer <brx-key>headers validated byvalidBrowserExtensionApiKeymiddleware. - Key Management: Admin users create keys via
POST /browser-extension/api-keys/new; keys can be listed and revoked through standard REST operations. - Content Flow: The
CollectorApiprocesses raw text from the extension beforeDocument.addDocumentspersists chunks to the selected workspace. - Dual Modes: Use
/embed-contentto save webpage content permanently, or/upload-contentfor transient processing without storage.
Frequently Asked Questions
Do I need to configure CORS manually for the browser extension?
No. The default Express configuration in server/index.js includes app.use(cors({ origin: true })), which permits cross-origin requests from browser extensions. The browser extension API endpoints inherit this CORS policy automatically.
What permission level is required to create browser extension API keys?
Only admin or manager users can create browser extension API keys. The POST /browser-extension/api-keys/new endpoint validates the requester's role before invoking the BrowserExtensionApiKey model to generate the brx- prefixed token.
How does the embed-content endpoint differ from upload-content?
The /embed-content endpoint persists processed text as a document within the specified workspace using Document.addDocuments, making the content available for future queries. The /upload-content endpoint processes text through the same CollectorApi pipeline but does not create a persistent document, serving transient summarization needs without storage overhead.
Where is the API key validation logic located in the source code?
The validation middleware resides in server/utils/middleware/validBrowserExtensionApiKey.js (lines 7-34). This middleware extracts the Bearer token from the Authorization header, validates it against the BrowserExtensionApiKey Prisma model, and attaches the key record to response.locals.apiKey for downstream route handlers.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →