What Does the `window.api` Object Expose in the OpenWhispr Renderer Process?
The window.api object (modernly exposed as window.electronAPI) is a secure IPC bridge that exposes over 50 methods across twelve categories—including audio capture, AI model management, clipboard operations, and GPU configuration—allowing the sandboxed Electron renderer to request privileged main-process actions without direct Node.js access.
OpenWhispr is an Electron-based voice dictation and AI assistant application that runs its UI in a sandboxed renderer process. Because the renderer cannot directly access Node.js APIs or system resources, the application uses a preload script to safely expose controlled functionality via the window.api object. This architecture ensures security while enabling complex features like real-time speech-to-text and local GPU inference.
How window.api Works: The Preload Script Architecture
OpenWhispr implements the Context Isolation security model required by modern Electron applications. In [preload.js](https://github.com/OpenWhispr/openwhispr/blob/main/preload.js), the script uses contextBridge.exposeInMainWorld to publish a single object onto the global window scope.
The exposed object is named electronAPI in the current codebase, though legacy references may still use window.api. All methods are thin wrappers around Electron's ipcRenderer module, invoking ipcRenderer.invoke, ipcRenderer.send, or ipcRenderer.on to communicate with handlers defined in [src/helpers/ipcHandlers.js](https://github.com/OpenWhispr/openwhispr/blob/main/src/helpers/ipcHandlers.js).
Because the preload runs in an isolated context, renderer code cannot require Node modules directly. Every filesystem operation, network request, or hardware access must route through these typed IPC bridges.
Core API Categories Exposed to the Renderer
The window.electronAPI object organizes functionality into distinct domains. Each category wraps specific IPC channels registered in the main process.
Audio Capture and Dictation Control
The renderer initiates and monitors dictation sessions through methods that manage microphone access and audio streaming:
captureDictationTarget– Identifies the active input field before recording beginsdictationAudioLevelChanged– Receives real-time microphone amplitude for UI visualizationdictationRealtimeStart/dictationRealtimeStop– Controls streaming transcription sessionsmeetingTranscriptionStart/meetingTranscriptionStop– Manages multi-speaker meeting modemicWarmHoldChanged– Signals microphone pre-warming status
Local AI Model and Inference Management
OpenWhispr supports both local and cloud AI providers. The API exposes methods to list, download, and invoke models:
modelGetAll– Lists available models and their download statusmodelDownload/modelDelete– Manages local model binariesprocessLocalReasoning– Invokes local LLaMA or similar models for post-processingprocessAnthropicReasoning/processEnterpriseReasoning– Routes requests to cloud or self-hosted endpoints
Whisper and Parakeet Speech-to-Text
For on-device transcription, the API interfaces with Whisper.cpp and NVIDIA Parakeet:
transcribeLocalWhisper– Sends audio blobs for local Whisper inferencedownloadWhisperModel/listWhisperModels– Manages Whisper model filestranscribeLocalParakeet– Runs NVIDIA Parakeet for GPU-accelerated transcriptiondownloadParakeetModel– Fetches Parakeet model binaries
GPU Acceleration and Hardware Detection
The renderer can query and configure GPU resources for inference:
listGpus– Enumerates available CUDA or Vulkan devicessetGpuDeviceIndex– Selects specific GPU for computationdetectGpu– Probes hardware capabilities on startupdownloadCudaWhisperBinary/downloadVulkanWhisperBinary– Fetches GPU-optimized inference engines
Clipboard and Text Insertion
Secure clipboard access enables the automatic paste features:
readClipboard/writeClipboard– Standard clipboard operationscaptureSelectedText– Grabs highlighted text before dictationpasteText/replaceSelectedText– Inserts transcription at cursor or replaces selectionpasteAtCapturedTarget– Pastes into previously identified input fieldcheckPasteTools– Verifies accessibility permissions required for programmatic paste
Database and Persistence Operations
The renderer performs CRUD operations on user data through the following methods:
saveTranscription/getTranscriptions/deleteTranscription– Manages dictation historysaveNote/getNotes/searchNotes/semanticSearchNotes– Personal knowledge base operationsgetDictionary/setDictionary– Custom vocabulary management
Global Hotkey and Window Management
System-level shortcuts and window state are controlled via:
onToggleDictation/onToggleVoiceAgent– Registers listeners for global hotkeysupdateHotkey/setHotkeyListeningMode/getHotkeyModeInfo– Configures shortcut combinationswindowMinimize/windowMaximize/windowClose– Standard window controlssnapToMeetingMode/restoreFromMeetingMode– Transitions to dedicated transcription layouts
System Integration and Permissions
The API provides helpers to open OS-specific settings for required permissions:
openMicrophoneSettings/openSoundInputSettingsopenAccessibilitySettings– Required for global hotkeys on macOSopenLoginItemsSettings– Manages startup behaviorcheckScreenRecordingAccess– Verifies permissions for screen capture features
BYOK Enterprise Key Management
Dynamic methods are generated from the BYOK_KEY_BRIDGES list defined in [src/config/secretKeys.js](https://github.com/OpenWhispr/openwhispr/blob/main/src/config/secretKeys.js). These include:
getOpenAIKey/saveOpenAIKeygetAnthropicKey/saveAnthropicKey
These methods securely store API keys in the system keychain rather than localStorage.
Practical Usage Examples
React Hook for Dictation Start
useEffect(() => {
const unsubscribe = window.electronAPI.onStartDictation(() => {
// Tell the main process to begin capturing audio
window.electronAPI.captureDictationTarget();
});
return unsubscribe;
}, []);
Local Whisper Transcription
async function transcribe(blob: Blob) {
const result = await window.electronAPI.transcribeLocalWhisper(blob, {
language: "en",
prompt: "custom dictionary words"
});
console.log("Transcription:", result.text);
}
Platform Detection for UI Styling
const platform = await window.electronAPI.getPlatform();
if (platform === "darwin") {
// macOS-specific UI adjustments
}
Summary
- The
window.electronAPIobject (legacy aliaswindow.api) is the sole secure bridge between OpenWhispr's sandboxed renderer and the privileged main process. - It exposes 50+ methods defined in [
preload.js](https://github.com/OpenWhispr/openwhispr/blob/main/preload.js), organized into categories including dictation, AI inference, GPU management, and clipboard operations. - All methods are IPC wrappers that communicate with handlers in [
src/helpers/ipcHandlers.js](https://github.com/OpenWhispr/openwhispr/blob/main/src/helpers/ipcHandlers.js). - Dynamic enterprise key methods are generated at runtime from [
src/config/secretKeys.js](https://github.com/OpenWhispr/openwhispr/blob/main/src/config/secretKeys.js). - This architecture maintains Context Isolation security while enabling complex system integrations.
Frequently Asked Questions
Is it window.api or window.electronAPI?
The modern codebase exposes the object as window.electronAPI in [preload.js](https://github.com/OpenWhispr/openwhispr/blob/main/preload.js). Legacy code or documentation may reference window.api, but both point to the same contextBridge exposure. You should use window.electronAPI for current development.
How does the renderer access system clipboard or GPU hardware without nodeIntegration?
OpenWhispr disables nodeIntegration and enables contextIsolation for security. The renderer cannot directly access Node.js modules. Instead, it calls methods like window.electronAPI.readClipboard or window.electronAPI.listGpus, which internally use ipcRenderer.invoke to request the main process perform these privileged operations and return the results.
Where are the IPC handlers that respond to these API calls defined?
The main-process implementations corresponding to the renderer's window.electronAPI calls are located in [src/helpers/ipcHandlers.js](https://github.com/OpenWhispr/openwhispr/blob/main/src/helpers/ipcHandlers.js). This file registers listeners using ipcMain.handle and ipcMain.on to execute the actual system calls, database queries, and AI inference.
How does OpenWhispr securely handle enterprise API keys through the window API?
Enterprise API keys are managed through dynamically generated methods (e.g., saveOpenAIKey, getAnthropicKey) defined in [src/config/secretKeys.js](https://github.com/OpenWhispr/openwhispr/blob/main/src/config/secretKeys.js). When called, these methods route to the main process, which stores credentials in the OS keychain (Keychain on macOS, Credential Manager on Windows) rather than in renderer-accessible storage like localStorage.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →