How to Set Up the Browser Extension API Endpoints for AnythingLLM

AnythingLLM exposes authenticated HTTP endpoints under /browser-extension/* that allow the Chrome/Firefox extension to embed content, upload raw text, and manage API keys through the Express server in server/endpoints/browserExtension.js.

The browser extension API in AnythingLLM enables direct integration between your local or hosted instance and the official Chrome/Firefox extension. This guide explains how to configure the browser extension API endpoints for AnythingLLM, covering the server-side registration, authentication middleware, and key management flows as implemented in the Mintplex-Labs/anything-llm repository.

Understanding the Browser Extension Architecture

The browser extension integration relies on four core components that handle routing, authentication, data persistence, and text processing:

Enabling the Browser Extension API Endpoints

The server automatically loads the browser extension routes during startup. No additional configuration is required beyond the default CORS setup.

In server/index.js, the Express application registers the endpoints via the browserExtensionEndpoints function:

// server/index.js (lines 84-89)
const { browserExtensionEndpoints } = require("./endpoints/browserExtension");
// ...
browserExtensionEndpoints(apiRouter);   // Registers /browser-extension/*

The default CORS configuration (app.use(cors({ origin: true }))) already permits cross-origin requests from browser extensions.

Generating and Managing Browser Extension API Keys

Only users with admin or manager roles can create browser extension API keys. The system generates keys with the prefix brx- followed by a unique identifier.

Creating Keys via the API

Admin users generate keys by sending a POST request to the key creation endpoint:

curl -X POST https://your-host/api/browser-extension/api-keys/new \
     -H "Authorization: Bearer <admin-token>"

The endpoint returns a JSON object containing the new key:

{ "apiKey": "brx-xxxx" }

Source: /browser-extension/api-keys/new

Alternatively, administrators can create keys through the web interface at Settings → Browser Extension, which calls the same backend endpoint via the frontend model.

Revoking and Listing Keys

The API supports full lifecycle management of browser extension keys:

  • List keys: GET /browser-extension/api-keys returns all visible keys (admin sees all keys; managers see only their own).
  • Revoke specific key: DELETE /browser-extension/api-keys/:id permanently removes the specified key.
  • Self-revoke session: DELETE /browser-extension/disconnect revokes the key currently used for authentication.

Authenticating Requests from the Extension

All browser extension endpoints require Bearer token authentication in the HTTP headers. The validBrowserExtensionApiKey middleware enforces this on every request.

Include the following header in all extension requests:


Authorization: Bearer <brx-your-key>

The middleware extracts the token, validates it against the BrowserExtensionApiKey database model, and either populates response.locals.apiKey with the key record or aborts with 403 Forbidden if invalid. In multi-user mode, the middleware also attaches the associated user object to locals.

Source: validBrowserExtensionApiKey middleware implementation

Core API Endpoints for Browser Extension Integration

The browser extension API provides endpoints for health checks, workspace discovery, and content ingestion.

Health Check and Workspace Discovery

  • GET /browser-extension/check – Validates the API key and returns connection status, the key's database ID, and accessible workspaces.
  • GET /browser-extension/workspaces – Returns the list of workspaces available to the authenticated key holder, used by the extension UI for selection.

Example health check request:

curl -H "Authorization: Bearer brx-..." \
     https://host/api/browser-extension/check

Content Ingestion Endpoints

The extension can send webpage content to AnythingLLM through two distinct endpoints:

Embed Content (Persistent Storage) POST /browser-extension/embed-content accepts raw text, processes it through the collector pipeline, and persists it as a document within the specified workspace.

curl -X POST https://host/api/browser-extension/embed-content \
     -H "Authorization: Bearer brx-..." \
     -H "Content-Type: application/json" \
     -d '{
       "workspaceId": "workspace-uuid",
       "textContent": "Raw text to embed...",
       "metadata": {"title": "Page Title", "url": "https://example.com"}
     }'

Upload Content (Transient Processing) POST /browser-extension/upload-content performs the same text processing but does not persist a document, making it suitable for one-off summarization tasks without cluttering the workspace.

Session Management

The disconnect endpoint provides a convenience method for the extension to revoke its own key:

curl -X DELETE -H "Authorization: Bearer brx-..." \
     https://host/api/browser-extension/disconnect

All route definitions are located in server/endpoints/browserExtension.js, with embed/upload logic spanning lines 81-152.

How Content Embedding Works Under the Hood

When the extension calls /browser-extension/embed-content, the server executes a four-stage pipeline:

  1. Workspace Resolution – The endpoint fetches the target workspace using Workspace.getWithUser (multi-user mode) or Workspace.get (single-user mode), verifying the API key holder has access.

  2. Text Processing – The CollectorApi class processes the raw text through processRawText(), handling chunking and metadata extraction.

  3. Document Creation – The system calls Document.addDocuments to store the processed content, linking the first chunk's location to the workspace.

  4. Telemetry – An analytics event browser_extension_embed_content is dispatched to track usage.

Relevant implementation details appear in server/endpoints/browserExtension.js lines 87-122, where the Collector processes input and Document.addDocuments handles persistence.

Frontend Integration for API Key Management

The React frontend provides a management interface through components in frontend/src/pages/GeneralSettings/BrowserExtensionApiKey/. The frontend model abstracts the REST calls:

// frontend/src/models/browserExtensionApiKey.js
export async function createKey() {
  return await fetch(`${API_BASE}/browser-extension/api-keys/new`, {
    method: "POST",
    headers: { Authorization: `Bearer ${userToken}` },
  });
}

This model mirrors the backend endpoints, allowing administrators to generate keys through the UI while the actual cryptographic generation and storage occur in the BrowserExtensionApiKey Prisma model on the server.

Summary

  • Automatic Registration: The server loads browser extension endpoints via browserExtensionEndpoints(apiRouter) in server/index.js without additional configuration.
  • Authentication: All routes require Authorization: Bearer <brx-key> headers validated by validBrowserExtensionApiKey middleware.
  • Key Management: Admin users create keys via POST /browser-extension/api-keys/new; keys can be listed and revoked through standard REST operations.
  • Content Flow: The CollectorApi processes raw text from the extension before Document.addDocuments persists chunks to the selected workspace.
  • Dual Modes: Use /embed-content to save webpage content permanently, or /upload-content for transient processing without storage.

Frequently Asked Questions

Do I need to configure CORS manually for the browser extension?

No. The default Express configuration in server/index.js includes app.use(cors({ origin: true })), which permits cross-origin requests from browser extensions. The browser extension API endpoints inherit this CORS policy automatically.

What permission level is required to create browser extension API keys?

Only admin or manager users can create browser extension API keys. The POST /browser-extension/api-keys/new endpoint validates the requester's role before invoking the BrowserExtensionApiKey model to generate the brx- prefixed token.

How does the embed-content endpoint differ from upload-content?

The /embed-content endpoint persists processed text as a document within the specified workspace using Document.addDocuments, making the content available for future queries. The /upload-content endpoint processes text through the same CollectorApi pipeline but does not create a persistent document, serving transient summarization needs without storage overhead.

Where is the API key validation logic located in the source code?

The validation middleware resides in server/utils/middleware/validBrowserExtensionApiKey.js (lines 7-34). This middleware extracts the Bearer token from the Authorization header, validates it against the BrowserExtensionApiKey Prisma model, and attaches the key record to response.locals.apiKey for downstream route handlers.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →