TabGeckoDocs
Website
Documentation / Getting started

Getting started

Use the address and a dedicated token from API & MCP in the running desktop application. Sign in to the desktop first; local requests use their own API token, never your website password.

Requirements

  • A running TabGecko desktop instance signed in to a server-confirmed account. The Local API does not launch the application or sign you in.
  • A local HTTP client such as curl, Node.js or Postman. The downloadable CLI and stdio bridge require Node.js 22 or newer.
  • A matching installed browser kernel is required for profile starts and page tools, but not for listing profiles.

Public installer availability is shown on the website download page; these API examples do not imply availability for every platform.

Address and token

  • Open API & MCP. Copy the current native address. The default is http://127.0.0.1:47300; if occupied, the native service can use ports 47301–47399. Do not hard-code a port discovered on a different machine.
  • Create a named token. Begin with profiles:read, select an expiry and save the one-time token value in your client’s protected local configuration.
  • Set ADBR_API_URL to that address and ADBR_API_TOKEN to your token in your local process environment. Example placeholders below must be replaced locally; do not publish the values.
Environment values (not a shell script)
ADBR_API_URL=http://127.0.0.1:47300
ADBR_API_TOKEN=<LOCAL_API_TOKEN>

Verify the connection

POSIX shell · curl
curl --fail-with-body "$ADBR_API_URL/status"
curl --fail-with-body "$ADBR_API_URL/api/v1/profiles?limit=1" \
  -H "Authorization: Bearer $ADBR_API_TOKEN"
Node.js CLI
node tabgecko.mjs status
node tabgecko.mjs profiles --limit 1

/status is public and only confirms reachability. The second request verifies authentication and profiles:read. A successful app-side MCP test uses the app session and does not validate the rights of a separately configured client token.

Local transport boundary

The native service binds to loopback. Web pages with an Origin header and cross-site browser requests are rejected; these docs do not send requests to your local application. Use a local process, not JavaScript embedded in a public website. Keep the desktop running, do not publish the port through a proxy or tunnel, and update the client address after a port change.