Pricing
Free and open source under the MIT license, with no pricing tiers or premium features. Users bring their own AI provider subscriptions.
Learn moreOpen-source browser extension that keeps your AI keys off web apps

Arlopass is a free, open-source browser extension and SDK that lets web apps use a person's own AI providers, including Claude, GPT, Gemini, Bedrock and Ollama, while API keys stay in an encrypted local vault.
Arlopass is a free, MIT-licensed browser extension paired with a developer SDK. It sits between web apps and the AI providers a person already pays for, so an app can use Claude, GPT, Gemini, Bedrock, Ollama and others without ever receiving the underlying API key. Credentials are kept in an encrypted vault on the user's own machine, protected with AES-256-GCM and unlocked through a master password or the operating system keychain. The tool serves two audiences. End users get a permission layer: when a site asks for AI access, a prompt shows what the app wants, lets the user pick providers and models, and records the connection. Afterward each app can be managed individually, with toggles for providers, an option to ask before every request or run consecutive calls in an autopilot mode, and daily token limits. Developers get a small integration surface. They install the @arlopass/web-sdk package, call connect() to open a session with the user's extension, create a chat, and stream or send messages. The homepage puts the whole integration at roughly ten lines, with TypeScript types, Zod-validated schemas and async iterator streaming, and no backend proxy or environment files to maintain. In practice the request flow runs through a native bridge on the user's device, which injects credentials at the last moment and returns only the model's response to the page. Local runtimes such as Ollama and LM Studio are supported for setups where prompts never leave the machine. Teams with stricter needs can apply signed policy bundles that restrict providers and models, with JSONL audit trails. New providers can be added by writing a single TypeScript adapter. Compared with pasting keys into apps, routing through an AI gateway or embedding a vendor SDK, Arlopass shifts the cost and the trust decision to the user: the app owner runs no inference infrastructure and handles no secrets, while the user decides who gets access. The trade-off is that the app's audience must install the extension first, which makes it a better fit for tools aimed at technical or privacy-minded users than for mass-market products.


Free and open source under the MIT license, with no pricing tiers or premium features. Users bring their own AI provider subscriptions.
Learn moreSupports Ollama, Anthropic Claude, OpenAI, Google Gemini, Amazon Bedrock, Google Vertex AI, Perplexity, LM Studio, Grok and Microsoft Foundry. New providers can be added with a single TypeScript adapter.
Encrypted local credential vault, 10-line SDK integration, per-app permission prompts, provider and model switching, token limits, autopilot mode, local model support via Ollama and LM Studio, signed policy bundles with JSONL audit trails, and open adapters.





