How to Access the Local HTTP API of LLM Wiki: A Developer's Integration Guide

LLM Wiki exposes a local HTTP API at http://127.0.0.1:19828 that enables external tools, scripts, and MCP clients to interact with wiki projects, pages, and knowledge graphs while the desktop application is running.

The open-source nashsu/llm_wiki repository includes a built-in REST server that runs inside the Tauri desktop process. This local API allows developers to programmatically manage wiki content, query project metadata, and integrate with external workflows without requiring direct GUI interaction.

API Base URL and Default Configuration

The API base URL is hardcoded in src/lib/api-server-constants.ts and defaults to the loopback interface on port 19828:

export const API_SERVER_PORT = 19828
export const API_SERVER_BASE_URL = `http://127.0.0.1:${API_SERVER_PORT}`
export const API_SERVER_HEALTH_URL = `${API_SERVER_BASE_URL}/api/v1/health`

As shown in the source, the base URL is http://127.0.0.1:19828, and all endpoints are prefixed with /api/v1. The health check endpoint provides a simple way to verify the server is running before making subsequent requests.

Localhost Security Binding

The Tauri backend explicitly binds the HTTP server to 127.0.0.1 to prevent external network exposure. In src-tauri/src/server_bind.rs, the binding host is defined as a constant:

const DEFAULT_BIND_HOST: &str = "127.0.0.1";

Cross-origin resource sharing (CORS) is strictly enforced in src-tauri/src/cors.rs, which validates that all requests originate from the local machine:

|| origin == "http://127.0.0.1"
|| origin.starts_with("http://127.0.0.1:")

This security model ensures that only processes running on the same host can access the API, protecting wiki data from remote network attacks.

Core API Endpoints

The REST API exposes a hierarchical structure under /api/v1. The following endpoints handle primary wiki operations:

  • /api/v1/health (GET) — Returns {"status":"ok"} to confirm server availability.
  • /api/v1/projects (GET) — Lists all known wiki projects with metadata.
  • /api/v1/projects/:id (GET) — Retrieves details for a specific project.
  • /api/v1/pages/:projectId/:pageId (GET) — Fetches markdown source for a specific page.
  • /api/v1/pages/:projectId/:pageId (POST) — Creates or updates a page; accepts JSON body with content.
  • /api/v1/graph/:projectId (GET) — Returns the knowledge graph structure for a project.

These routes are implemented in the Tauri commands directory (src-tauri/src/commands/), with each endpoint checking host validation to enforce the localhost-only policy.

Code Examples

Health Check with cURL

Verify the API is running before integration:

curl http://127.0.0.1:19828/api/v1/health

# → {"status":"ok"}

Fetching Pages with JavaScript

Use standard fetch in browser extensions or Node.js scripts:

const base = "http://127.0.0.1:19828";
fetch(`${base}/api/v1/pages/myProjectId/myPageId`)
  .then(r => r.json())
  .then(data => console.log(data.content));

The front-end implementation in src/App.tsx (line 519) follows this same pattern for internal communication.

MCP Server Client Integration

The MCP (Multi-Client Proxy) server reuses these endpoints for external tooling. In mcp-server/src/api-client.ts, the default base URL is imported for programmatic access:

import { DEFAULT_API_BASE_URL } from "./api-client";

async function listProjects() {
  const resp = await fetch(`${DEFAULT_API_BASE_URL}/api/v1/projects`);
  return resp.json();
}

LLM Wiki Skill (Claude Code)

When using the optional Claude Code skill, authenticate requests with your wiki token:

curl -H "Authorization: Bearer $LLM_WIKI_TOKEN" \
     http://127.0.0.1:19828/api/v1/projects

Authentication and Security Model

While the health endpoint is public, all operational endpoints require token-based authentication. The API automatically respects the same permission model used by the desktop GUI, ensuring that external scripts cannot bypass project-level access controls. The combination of loopback-only binding (enforced in src-tauri/src/commands/search.rs at line 1423) and token validation creates a secure local-only surface area suitable for CI pipelines and local development tools.

Key Source Files

Understanding these files helps when debugging connectivity issues or extending the API:

File Role
src/lib/api-server-constants.ts Defines API_SERVER_PORT (19828), base URL, and health endpoint constants.
src-tauri/src/server_bind.rs Rust implementation that binds the HTTP listener to 127.0.0.1.
src-tauri/src/cors.rs CORS middleware restricting origins to http://127.0.0.1 variants.
src-tauri/src/commands/*.rs Concrete endpoint implementations for projects, pages, graphs, and search.
mcp-server/src/api-client.ts Client wrapper using DEFAULT_API_BASE_URL = "http://127.0.0.1:19828".
extension/manifest.json Browser extension manifest listing fallback URLs including http://127.0.0.1:19828/*.

Summary

  • Localhost binding: The API binds exclusively to 127.0.0.1:19828 as defined in api-server-constants.ts and server_bind.rs.
  • Security first: CORS restrictions and host validation ensure only local processes can connect.
  • RESTful endpoints: Standard CRUD operations available under /api/v1 for projects, pages, and knowledge graphs.
  • Integration ready: Works with cURL, JavaScript fetch, MCP clients, and the Claude Code skill.
  • Authentication required: Token-based auth protects all non-health endpoints.

Frequently Asked Questions

How do I change the default API port from 19828?

To modify the port, edit the API_SERVER_PORT constant in src/lib/api-server-constants.ts and rebuild the application. You must also update the corresponding port in src-tauri/src/server_bind.rs and any client configurations (such as the extension manifest or MCP server settings) to maintain connectivity.

Can I access the LLM Wiki API from another computer on my network?

No. According to the source code in src-tauri/src/cors.rs and src-tauri/src/server_bind.rs, the server explicitly binds to 127.0.0.1 and rejects CORS origins that do not match the localhost pattern. This design prevents remote access for security reasons.

Where do I find my authentication token for API requests?

The LLM Wiki application generates a token during setup that is stored in your local configuration. When using the Claude Code skill or custom scripts, export the token as LLM_WIKI_TOKEN and include it in the Authorization: Bearer header. The desktop app manages these tokens internally; consult the application's settings panel to regenerate or copy your current token.

What is the difference between the API server and the Clip server?

LLM Wiki runs two distinct local services: the API server on port 19828 (REST endpoints for wiki data) and the Clip server on port 19827 (browser extension content capture). The Clip server handles web page clipping and content extraction, while the API server manages project persistence and knowledge graph operations. Both bind to 127.0.0.1 and are referenced in extension/manifest.json.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →