Getting started
Use the address and a dedicated token from API & MCP in the running desktop application. Sign in to the desktop first; local requests use their own API token, never your website password.
Requirements
- A running TabGecko desktop instance signed in to a server-confirmed account. The Local API does not launch the application or sign you in.
- A local HTTP client such as curl, Node.js or Postman. The downloadable CLI and stdio bridge require Node.js 22 or newer.
- A matching installed browser kernel is required for profile starts and page tools, but not for listing profiles.
Public installer availability is shown on the website download page; these API examples do not imply availability for every platform.
Address and token
- Open API & MCP. Copy the current native address. The default is http://127.0.0.1:47300; if occupied, the native service can use ports 47301–47399. Do not hard-code a port discovered on a different machine.
- Create a named token. Begin with profiles:read, select an expiry and save the one-time token value in your client’s protected local configuration.
- Set ADBR_API_URL to that address and ADBR_API_TOKEN to your token in your local process environment. Example placeholders below must be replaced locally; do not publish the values.
ADBR_API_URL=http://127.0.0.1:47300
ADBR_API_TOKEN=<LOCAL_API_TOKEN>Verify the connection
curl --fail-with-body "$ADBR_API_URL/status"
curl --fail-with-body "$ADBR_API_URL/api/v1/profiles?limit=1" \
-H "Authorization: Bearer $ADBR_API_TOKEN"node tabgecko.mjs status
node tabgecko.mjs profiles --limit 1/status is public and only confirms reachability. The second request verifies authentication and profiles:read. A successful app-side MCP test uses the app session and does not validate the rights of a separately configured client token.
Local transport boundary
The native service binds to loopback. Web pages with an Origin header and cross-site browser requests are rejected; these docs do not send requests to your local application. Use a local process, not JavaScript embedded in a public website. Keep the desktop running, do not publish the port through a proxy or tunnel, and update the client address after a port change.