Arlopass

Open-source browser extension that keeps your AI keys off web apps

Intermediate API
Screenshot of Arlopass, Open-source browser extension that keeps your AI keys off web apps

What is Arlopass?

Arlopass is a free, open-source browser extension and SDK that lets web apps use a person's own AI providers, including Claude, GPT, Gemini, Bedrock and Ollama, while API keys stay in an encrypted local vault.

Arlopass is a free, MIT-licensed browser extension paired with a developer SDK. It sits between web apps and the AI providers a person already pays for, so an app can use Claude, GPT, Gemini, Bedrock, Ollama and others without ever receiving the underlying API key. Credentials are kept in an encrypted vault on the user's own machine, protected with AES-256-GCM and unlocked through a master password or the operating system keychain. The tool serves two audiences. End users get a permission layer: when a site asks for AI access, a prompt shows what the app wants, lets the user pick providers and models, and records the connection. Afterward each app can be managed individually, with toggles for providers, an option to ask before every request or run consecutive calls in an autopilot mode, and daily token limits. Developers get a small integration surface. They install the @arlopass/web-sdk package, call connect() to open a session with the user's extension, create a chat, and stream or send messages. The homepage puts the whole integration at roughly ten lines, with TypeScript types, Zod-validated schemas and async iterator streaming, and no backend proxy or environment files to maintain. In practice the request flow runs through a native bridge on the user's device, which injects credentials at the last moment and returns only the model's response to the page. Local runtimes such as Ollama and LM Studio are supported for setups where prompts never leave the machine. Teams with stricter needs can apply signed policy bundles that restrict providers and models, with JSONL audit trails. New providers can be added by writing a single TypeScript adapter. Compared with pasting keys into apps, routing through an AI gateway or embedding a vendor SDK, Arlopass shifts the cost and the trust decision to the user: the app owner runs no inference infrastructure and handles no secrets, while the user decides who gets access. The trade-off is that the app's audience must install the extension first, which makes it a better fit for tools aimed at technical or privacy-minded users than for mass-market products.

How do you use Arlopass?

  1. 1Install the extension
    Add Arlopass from the Chrome Web Store. No account or sign-up is needed.
    Arlopass — Install the extension
  2. 2Connect your AI providers
    Link providers such as Claude, OpenAI or Ollama. Credentials are encrypted in a local vault, protected by a master password or the OS keychain.
  3. 3Add the SDK to your app
    Developers install @arlopass/web-sdk and follow the quickstart to call connect() and create a chat.
    Arlopass — Add the SDK to your app
  4. 4Stream a chat response
    Use chat.stream() or chat.send() to exchange messages. The user's chosen provider and model handle the request.
  5. 5Approve the connection
    When an app requests access, pick the allowed providers and models, then confirm the connection.
  6. 6Set rules and limits
    Open the app's permissions to toggle providers, require approval per request, enable autopilot or set a daily token limit.

Pros and cons

Pros

  • Keys stay in an encrypted local vault (AES-256-GCM) and are never exposed to the web appAI
  • Developer integration is about ten lines with no backend proxy or key managementAI
  • Per-app permissions, model selection, token limits and autopilot controls give users fine controlAI
  • Supports local models through Ollama and LM Studio for fully offline useAI
  • Free and MIT licensed, including the protocol, SDK, extension and adaptersAI

Cons

  • Every end user must install the browser extension before an app can use itAI
  • Only Chrome installation is offered on the homepage, so other browsers are not clearly coveredAI
  • Apps need to add the SDK, so only Arlopass-enabled sites benefitAI
  • Users must supply their own provider subscriptions and API keysAI
  • Native bridge and local vault setup adds some friction compared with a hosted gatewayAI

How much does Arlopass cost?

Pricing

Free and open source under the MIT license, with no pricing tiers or premium features. Users bring their own AI provider subscriptions.

Learn more

Integrations

Supports Ollama, Anthropic Claude, OpenAI, Google Gemini, Amazon Bedrock, Google Vertex AI, Perplexity, LM Studio, Grok and Microsoft Foundry. New providers can be added with a single TypeScript adapter.

Features

Encrypted local credential vault, 10-line SDK integration, per-app permission prompts, provider and model switching, token limits, autopilot mode, local model support via Ollama and LM Studio, signed policy bundles with JSONL audit trails, and open adapters.

Frequently asked questions about Arlopass

  • How much does Arlopass cost?
    Free and open source under the MIT license, with no pricing tiers or premium features. Users bring their own AI provider subscriptions.
  • Does Arlopass have an API?
    Yes, Arlopass offers an API.
  • How do you use Arlopass?
    The walkthrough on this page covers 6 steps: 1. Install the extension 2. Connect your AI providers 3. Add the SDK to your app 4. Stream a chat response 5. Approve the connection 6. Set rules and limits.
  • What platforms does Arlopass support?
    Arlopass is available on Browser extension.
  • What does Arlopass integrate with?
    Supports Ollama, Anthropic Claude, OpenAI, Google Gemini, Amazon Bedrock, Google Vertex AI, Perplexity, LM Studio, Grok and Microsoft Foundry. New providers can be added with a single TypeScript adapter.
  • What are the limitations of Arlopass?
    Every end user must install the browser extension before an app can use it. Only Chrome installation is offered on the homepage, so other browsers are not clearly covered. Apps need to add the SDK, so only Arlopass-enabled sites benefit.

Status

StatusActive
Views0
Outbound clicks0
Added10/8/2026

Platforms

Browser extension

Pricing

Free