What Does the `window.api` Object Expose in the OpenWhispr Renderer Process?

The window.api object (modernly exposed as window.electronAPI) is a secure IPC bridge that exposes over 50 methods across twelve categories—including audio capture, AI model management, clipboard operations, and GPU configuration—allowing the sandboxed Electron renderer to request privileged main-process actions without direct Node.js access.

OpenWhispr is an Electron-based voice dictation and AI assistant application that runs its UI in a sandboxed renderer process. Because the renderer cannot directly access Node.js APIs or system resources, the application uses a preload script to safely expose controlled functionality via the window.api object. This architecture ensures security while enabling complex features like real-time speech-to-text and local GPU inference.

How window.api Works: The Preload Script Architecture

OpenWhispr implements the Context Isolation security model required by modern Electron applications. In [preload.js](https://github.com/OpenWhispr/openwhispr/blob/main/preload.js), the script uses contextBridge.exposeInMainWorld to publish a single object onto the global window scope.

The exposed object is named electronAPI in the current codebase, though legacy references may still use window.api. All methods are thin wrappers around Electron's ipcRenderer module, invoking ipcRenderer.invoke, ipcRenderer.send, or ipcRenderer.on to communicate with handlers defined in [src/helpers/ipcHandlers.js](https://github.com/OpenWhispr/openwhispr/blob/main/src/helpers/ipcHandlers.js).

Because the preload runs in an isolated context, renderer code cannot require Node modules directly. Every filesystem operation, network request, or hardware access must route through these typed IPC bridges.

Core API Categories Exposed to the Renderer

The window.electronAPI object organizes functionality into distinct domains. Each category wraps specific IPC channels registered in the main process.

Audio Capture and Dictation Control

The renderer initiates and monitors dictation sessions through methods that manage microphone access and audio streaming:

  • captureDictationTarget – Identifies the active input field before recording begins
  • dictationAudioLevelChanged – Receives real-time microphone amplitude for UI visualization
  • dictationRealtimeStart / dictationRealtimeStop – Controls streaming transcription sessions
  • meetingTranscriptionStart / meetingTranscriptionStop – Manages multi-speaker meeting mode
  • micWarmHoldChanged – Signals microphone pre-warming status

Local AI Model and Inference Management

OpenWhispr supports both local and cloud AI providers. The API exposes methods to list, download, and invoke models:

  • modelGetAll – Lists available models and their download status
  • modelDownload / modelDelete – Manages local model binaries
  • processLocalReasoning – Invokes local LLaMA or similar models for post-processing
  • processAnthropicReasoning / processEnterpriseReasoning – Routes requests to cloud or self-hosted endpoints

Whisper and Parakeet Speech-to-Text

For on-device transcription, the API interfaces with Whisper.cpp and NVIDIA Parakeet:

  • transcribeLocalWhisper – Sends audio blobs for local Whisper inference
  • downloadWhisperModel / listWhisperModels – Manages Whisper model files
  • transcribeLocalParakeet – Runs NVIDIA Parakeet for GPU-accelerated transcription
  • downloadParakeetModel – Fetches Parakeet model binaries

GPU Acceleration and Hardware Detection

The renderer can query and configure GPU resources for inference:

  • listGpus – Enumerates available CUDA or Vulkan devices
  • setGpuDeviceIndex – Selects specific GPU for computation
  • detectGpu – Probes hardware capabilities on startup
  • downloadCudaWhisperBinary / downloadVulkanWhisperBinary – Fetches GPU-optimized inference engines

Clipboard and Text Insertion

Secure clipboard access enables the automatic paste features:

  • readClipboard / writeClipboard – Standard clipboard operations
  • captureSelectedText – Grabs highlighted text before dictation
  • pasteText / replaceSelectedText – Inserts transcription at cursor or replaces selection
  • pasteAtCapturedTarget – Pastes into previously identified input field
  • checkPasteTools – Verifies accessibility permissions required for programmatic paste

Database and Persistence Operations

The renderer performs CRUD operations on user data through the following methods:

  • saveTranscription / getTranscriptions / deleteTranscription – Manages dictation history
  • saveNote / getNotes / searchNotes / semanticSearchNotes – Personal knowledge base operations
  • getDictionary / setDictionary – Custom vocabulary management

Global Hotkey and Window Management

System-level shortcuts and window state are controlled via:

  • onToggleDictation / onToggleVoiceAgent – Registers listeners for global hotkeys
  • updateHotkey / setHotkeyListeningMode / getHotkeyModeInfo – Configures shortcut combinations
  • windowMinimize / windowMaximize / windowClose – Standard window controls
  • snapToMeetingMode / restoreFromMeetingMode – Transitions to dedicated transcription layouts

System Integration and Permissions

The API provides helpers to open OS-specific settings for required permissions:

  • openMicrophoneSettings / openSoundInputSettings
  • openAccessibilitySettings – Required for global hotkeys on macOS
  • openLoginItemsSettings – Manages startup behavior
  • checkScreenRecordingAccess – Verifies permissions for screen capture features

BYOK Enterprise Key Management

Dynamic methods are generated from the BYOK_KEY_BRIDGES list defined in [src/config/secretKeys.js](https://github.com/OpenWhispr/openwhispr/blob/main/src/config/secretKeys.js). These include:

  • getOpenAIKey / saveOpenAIKey
  • getAnthropicKey / saveAnthropicKey

These methods securely store API keys in the system keychain rather than localStorage.

Practical Usage Examples

React Hook for Dictation Start

useEffect(() => {
  const unsubscribe = window.electronAPI.onStartDictation(() => {
    // Tell the main process to begin capturing audio
    window.electronAPI.captureDictationTarget();
  });
  return unsubscribe;
}, []);

Local Whisper Transcription

async function transcribe(blob: Blob) {
  const result = await window.electronAPI.transcribeLocalWhisper(blob, {
    language: "en",
    prompt: "custom dictionary words"
  });
  console.log("Transcription:", result.text);
}

Platform Detection for UI Styling

const platform = await window.electronAPI.getPlatform();
if (platform === "darwin") {
  // macOS-specific UI adjustments
}

Summary

Frequently Asked Questions

Is it window.api or window.electronAPI?

The modern codebase exposes the object as window.electronAPI in [preload.js](https://github.com/OpenWhispr/openwhispr/blob/main/preload.js). Legacy code or documentation may reference window.api, but both point to the same contextBridge exposure. You should use window.electronAPI for current development.

How does the renderer access system clipboard or GPU hardware without nodeIntegration?

OpenWhispr disables nodeIntegration and enables contextIsolation for security. The renderer cannot directly access Node.js modules. Instead, it calls methods like window.electronAPI.readClipboard or window.electronAPI.listGpus, which internally use ipcRenderer.invoke to request the main process perform these privileged operations and return the results.

Where are the IPC handlers that respond to these API calls defined?

The main-process implementations corresponding to the renderer's window.electronAPI calls are located in [src/helpers/ipcHandlers.js](https://github.com/OpenWhispr/openwhispr/blob/main/src/helpers/ipcHandlers.js). This file registers listeners using ipcMain.handle and ipcMain.on to execute the actual system calls, database queries, and AI inference.

How does OpenWhispr securely handle enterprise API keys through the window API?

Enterprise API keys are managed through dynamically generated methods (e.g., saveOpenAIKey, getAnthropicKey) defined in [src/config/secretKeys.js](https://github.com/OpenWhispr/openwhispr/blob/main/src/config/secretKeys.js). When called, these methods route to the main process, which stores credentials in the OS keychain (Keychain on macOS, Credential Manager on Windows) rather than in renderer-accessible storage like localStorage.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →