Browser access and allowed addresses
The OpenRig daemon answers its API only when a request is addressed to this machine and, if it comes from a web page, only when that page is the OpenRig UI or a page you allowed.
What works with no setup
- The CLI, the TUI and agents on this machine, addressing the daemon by
localhostor an IP address. - Other OpenRig hosts and clients that reach this daemon by its IP address, its own hostname, or
its own Tailscale name (for example
my-machine.your-tailnet.ts.net, or the shortmy-machine). The daemon learns its own Tailscale name automatically from Tailscale on this machine. - The web UI, when it is turned on (
rig config set ui.enabled true, then restart the daemon) and opened overhttpon the daemon's own port at any address the daemon accepts, including its Tailscale name. A UI page served any other way, such as overhttpsthrough your own domain, also needs its exact origin inOPENRIG_ALLOWED_ORIGINS, then a daemon restart.
When you see a refusal
The daemon answers 403 with a sentence that says what to do. There are two kinds:
- The address is not recognized (
untrusted_host). You reached the daemon by a name it does not know as its own, such as a custom DNS name, an alias in/etc/hosts, or a reverse proxy domain. Uselocalhost, an IP address or the machine's own name instead, or list the name you use:OPENRIG_ALLOWED_HOSTS=rig.example.comin the daemon's environment, then restart the daemon. A client that presents the daemon's configured bearer token is not refused for its address (it still needs whatever access each route requires). - The web page is not allowed (
browser_origin_refused). A browser page that is not the OpenRig UI at the daemon's own address called the API. This includes another local app or development server on a different port. To allow a page, list its exact origin:OPENRIG_ALLOWED_ORIGINS=http://localhost:5173in the daemon's environment, then restart the daemon. A bearer token does not override this.
OPENRIG_ALLOWED_HOSTS lists names you use to reach the daemon. OPENRIG_ALLOWED_ORIGINS lists
web pages allowed to call it. They are separate: a UI served through your own domain usually needs
both. Separate several entries with commas. Pages on other origins cannot read the refusal; the
message is for you, the CLI and agents.
Limits
- If you rename the machine in Tailscale, the daemon keeps accepting its previous name until it restarts or until it next looks its name up after seeing an unrecognized one.
- If the daemon has not reached Tailscale's resolver since it started, its Tailscale name is
refused until a lookup succeeds. A later failed lookup keeps the name it already learned.
localhostand IP addresses keep working. - This protects against unknown web pages and unknown names. It is not complete browser isolation: a page on another site can still cause a simple read request to an address the daemon accepts, although it cannot read the answer. Keep the daemon on loopback or your tailnet.