# What Does the `window.api` Object Expose in the OpenWhispr Renderer Process?

> Explore the OpenWhispr window api object, a secure IPC bridge exposing over 50 methods for audio capture, AI management, clipboard, and GPU config in the Electron renderer.

- Repository: [OpenWhispr/openwhispr](https://github.com/OpenWhispr/openwhispr)
- Tags: api-reference
- Published: 2026-09-06

---

**The `window.api` object (modernly exposed as `window.electronAPI`) is a secure IPC bridge that exposes over 50 methods across twelve categories—including audio capture, AI model management, clipboard operations, and GPU configuration—allowing the sandboxed Electron renderer to request privileged main-process actions without direct Node.js access.**

OpenWhispr is an Electron-based voice dictation and AI assistant application that runs its UI in a sandboxed renderer process. Because the renderer cannot directly access Node.js APIs or system resources, the application uses a preload script to safely expose controlled functionality via the `window.api` object. This architecture ensures security while enabling complex features like real-time speech-to-text and local GPU inference.

## How `window.api` Works: The Preload Script Architecture

OpenWhispr implements the **Context Isolation** security model required by modern Electron applications. In [[`preload.js`](https://github.com/OpenWhispr/openwhispr/blob/main/preload.js)](https://github.com/OpenWhispr/openwhispr/blob/main/preload.js), the script uses `contextBridge.exposeInMainWorld` to publish a single object onto the global `window` scope.

The exposed object is named `electronAPI` in the current codebase, though legacy references may still use `window.api`. All methods are thin wrappers around Electron's `ipcRenderer` module, invoking `ipcRenderer.invoke`, `ipcRenderer.send`, or `ipcRenderer.on` to communicate with handlers defined in [[`src/helpers/ipcHandlers.js`](https://github.com/OpenWhispr/openwhispr/blob/main/src/helpers/ipcHandlers.js)](https://github.com/OpenWhispr/openwhispr/blob/main/src/helpers/ipcHandlers.js).

Because the preload runs in an isolated context, renderer code cannot require Node modules directly. Every filesystem operation, network request, or hardware access must route through these typed IPC bridges.

## Core API Categories Exposed to the Renderer

The `window.electronAPI` object organizes functionality into distinct domains. Each category wraps specific IPC channels registered in the main process.

### Audio Capture and Dictation Control

The renderer initiates and monitors dictation sessions through methods that manage microphone access and audio streaming:

- **`captureDictationTarget`** – Identifies the active input field before recording begins
- **`dictationAudioLevelChanged`** – Receives real-time microphone amplitude for UI visualization
- **`dictationRealtimeStart`** / **`dictationRealtimeStop`** – Controls streaming transcription sessions
- **`meetingTranscriptionStart`** / **`meetingTranscriptionStop`** – Manages multi-speaker meeting mode
- **`micWarmHoldChanged`** – Signals microphone pre-warming status

### Local AI Model and Inference Management

OpenWhispr supports both local and cloud AI providers. The API exposes methods to list, download, and invoke models:

- **`modelGetAll`** – Lists available models and their download status
- **`modelDownload`** / **`modelDelete`** – Manages local model binaries
- **`processLocalReasoning`** – Invokes local LLaMA or similar models for post-processing
- **`processAnthropicReasoning`** / **`processEnterpriseReasoning`** – Routes requests to cloud or self-hosted endpoints

### Whisper and Parakeet Speech-to-Text

For on-device transcription, the API interfaces with Whisper.cpp and NVIDIA Parakeet:

- **`transcribeLocalWhisper`** – Sends audio blobs for local Whisper inference
- **`downloadWhisperModel`** / **`listWhisperModels`** – Manages Whisper model files
- **`transcribeLocalParakeet`** – Runs NVIDIA Parakeet for GPU-accelerated transcription
- **`downloadParakeetModel`** – Fetches Parakeet model binaries

### GPU Acceleration and Hardware Detection

The renderer can query and configure GPU resources for inference:

- **`listGpus`** – Enumerates available CUDA or Vulkan devices
- **`setGpuDeviceIndex`** – Selects specific GPU for computation
- **`detectGpu`** – Probes hardware capabilities on startup
- **`downloadCudaWhisperBinary`** / **`downloadVulkanWhisperBinary`** – Fetches GPU-optimized inference engines

### Clipboard and Text Insertion

Secure clipboard access enables the automatic paste features:

- **`readClipboard`** / **`writeClipboard`** – Standard clipboard operations
- **`captureSelectedText`** – Grabs highlighted text before dictation
- **`pasteText`** / **`replaceSelectedText`** – Inserts transcription at cursor or replaces selection
- **`pasteAtCapturedTarget`** – Pastes into previously identified input field
- **`checkPasteTools`** – Verifies accessibility permissions required for programmatic paste

### Database and Persistence Operations

The renderer performs CRUD operations on user data through the following methods:

- **`saveTranscription`** / **`getTranscriptions`** / **`deleteTranscription`** – Manages dictation history
- **`saveNote`** / **`getNotes`** / **`searchNotes`** / **`semanticSearchNotes`** – Personal knowledge base operations
- **`getDictionary`** / **`setDictionary`** – Custom vocabulary management

### Global Hotkey and Window Management

System-level shortcuts and window state are controlled via:

- **`onToggleDictation`** / **`onToggleVoiceAgent`** – Registers listeners for global hotkeys
- **`updateHotkey`** / **`setHotkeyListeningMode`** / **`getHotkeyModeInfo`** – Configures shortcut combinations
- **`windowMinimize`** / **`windowMaximize`** / **`windowClose`** – Standard window controls
- **`snapToMeetingMode`** / **`restoreFromMeetingMode`** – Transitions to dedicated transcription layouts

### System Integration and Permissions

The API provides helpers to open OS-specific settings for required permissions:

- **`openMicrophoneSettings`** / **`openSoundInputSettings`**
- **`openAccessibilitySettings`** – Required for global hotkeys on macOS
- **`openLoginItemsSettings`** – Manages startup behavior
- **`checkScreenRecordingAccess`** – Verifies permissions for screen capture features

### BYOK Enterprise Key Management

Dynamic methods are generated from the `BYOK_KEY_BRIDGES` list defined in [[`src/config/secretKeys.js`](https://github.com/OpenWhispr/openwhispr/blob/main/src/config/secretKeys.js)](https://github.com/OpenWhispr/openwhispr/blob/main/src/config/secretKeys.js). These include:

- **`getOpenAIKey`** / **`saveOpenAIKey`**
- **`getAnthropicKey`** / **`saveAnthropicKey`**

These methods securely store API keys in the system keychain rather than localStorage.

## Practical Usage Examples

### React Hook for Dictation Start

```typescript
useEffect(() => {
  const unsubscribe = window.electronAPI.onStartDictation(() => {
    // Tell the main process to begin capturing audio
    window.electronAPI.captureDictationTarget();
  });
  return unsubscribe;
}, []);

```

### Local Whisper Transcription

```typescript
async function transcribe(blob: Blob) {
  const result = await window.electronAPI.transcribeLocalWhisper(blob, {
    language: "en",
    prompt: "custom dictionary words"
  });
  console.log("Transcription:", result.text);
}

```

### Platform Detection for UI Styling

```typescript
const platform = await window.electronAPI.getPlatform();
if (platform === "darwin") {
  // macOS-specific UI adjustments
}

```

## Summary

- The **`window.electronAPI`** object (legacy alias `window.api`) is the sole secure bridge between OpenWhispr's sandboxed renderer and the privileged main process.
- It exposes **50+ methods** defined in [[`preload.js`](https://github.com/OpenWhispr/openwhispr/blob/main/preload.js)](https://github.com/OpenWhispr/openwhispr/blob/main/preload.js), organized into categories including dictation, AI inference, GPU management, and clipboard operations.
- All methods are **IPC wrappers** that communicate with handlers in [[`src/helpers/ipcHandlers.js`](https://github.com/OpenWhispr/openwhispr/blob/main/src/helpers/ipcHandlers.js)](https://github.com/OpenWhispr/openwhispr/blob/main/src/helpers/ipcHandlers.js).
- **Dynamic enterprise key methods** are generated at runtime from [[`src/config/secretKeys.js`](https://github.com/OpenWhispr/openwhispr/blob/main/src/config/secretKeys.js)](https://github.com/OpenWhispr/openwhispr/blob/main/src/config/secretKeys.js).
- This architecture maintains **Context Isolation** security while enabling complex system integrations.

## Frequently Asked Questions

### Is it `window.api` or `window.electronAPI`?

The modern codebase exposes the object as `window.electronAPI` in [[`preload.js`](https://github.com/OpenWhispr/openwhispr/blob/main/preload.js)](https://github.com/OpenWhispr/openwhispr/blob/main/preload.js). Legacy code or documentation may reference `window.api`, but both point to the same `contextBridge` exposure. You should use `window.electronAPI` for current development.

### How does the renderer access system clipboard or GPU hardware without `nodeIntegration`?

OpenWhispr disables `nodeIntegration` and enables `contextIsolation` for security. The renderer cannot directly access Node.js modules. Instead, it calls methods like `window.electronAPI.readClipboard` or `window.electronAPI.listGpus`, which internally use `ipcRenderer.invoke` to request the main process perform these privileged operations and return the results.

### Where are the IPC handlers that respond to these API calls defined?

The main-process implementations corresponding to the renderer's `window.electronAPI` calls are located in [[`src/helpers/ipcHandlers.js`](https://github.com/OpenWhispr/openwhispr/blob/main/src/helpers/ipcHandlers.js)](https://github.com/OpenWhispr/openwhispr/blob/main/src/helpers/ipcHandlers.js). This file registers listeners using `ipcMain.handle` and `ipcMain.on` to execute the actual system calls, database queries, and AI inference.

### How does OpenWhispr securely handle enterprise API keys through the window API?

Enterprise API keys are managed through dynamically generated methods (e.g., `saveOpenAIKey`, `getAnthropicKey`) defined in [[`src/config/secretKeys.js`](https://github.com/OpenWhispr/openwhispr/blob/main/src/config/secretKeys.js)](https://github.com/OpenWhispr/openwhispr/blob/main/src/config/secretKeys.js). When called, these methods route to the main process, which stores credentials in the OS keychain (Keychain on macOS, Credential Manager on Windows) rather than in renderer-accessible storage like `localStorage`.