Network and API key

By default only this Mac can reach Quail's server, and every request needs its API key.

Reachable from

On the Server page, Network → Reachable from sets who can connect:

This Mac onlyThe default. The server listens on 127.0.0.1; nothing else can connect.
Local networkThe server listens on every network interface (0.0.0.0), so your other computers and phones can use it.
CustomOne address you type, such as a VPN address. Press Return to save it.

The first time you start the server with it reachable from the network, Quail asks once, and offers to keep it to this Mac instead.

The address to use

The Server page shows the addresses that work, each with a Copy button:

Change the port on the same page. The address, port, API key and models loaded at once apply when the server restarts; the page and the menu say when a restart is needed.

The API key

Require API key is on from the start, with a random key kept in your Keychain. Clients send it as Authorization: Bearer <key> or x-api-key: <key>; the Connect page fills it in for you.

Leave the key on. Without one, any web page you open could send requests to the server on this Mac, and anyone on your network could use your models when it's reachable from the network. The Server page warns you in red when that's the case.

Web pages

Quail server refuses requests from other web pages and from pages that pretend to be it (a “DNS rebinding” attack). Its own chat page, opened from the menu, signs in with a one-time ticket, so the key never appears in a URL.