Connect your own Ollama
Chatty runs in Cloudflare’s network. That has a consequence worth stating plainly: the backend
cannot reach a private address. http://localhost:11434, 192.168.x.x and anything behind your
router are unreachable from where Chatty lives, no matter how the URL is typed into Settings.
The tunnel agent solves it by reversing the direction. Instead of Chatty dialling into your machine, a small process on your machine dials out to Chatty and keeps the connection open. Requests for your models travel back down that same connection.
npx @chatty-lab/tunnelThat is the whole command. It checks your Ollama, links itself to your account through the browser, registers the server in Settings and stays running.
Before you start
Section titled “Before you start”- Node.js 22 or newer. The agent has no dependencies — it uses the
fetchandWebSocketbuilt into modern Node — so there is nothing to install beyond Node itself. - Ollama running, with at least one model pulled. Check with
ollama list. - An account on Chatty, signed in on a browser on some machine (not necessarily this one).
Connect it
Section titled “Connect it”-
Check Ollama is answering.
Terminal window ollama listIf the list is empty, pull something first — a tunnel to a server with no models exposes nothing useful.
Terminal window ollama pull llama3.2 -
Pick the right workspace in the browser.
The tunnel is granted to whichever workspace is active when you approve it, so switch workspace before the next step if this server belongs to a team rather than to you. See Workspaces & Teams.
-
Run the agent on the machine where Ollama lives.
Terminal window npx @chatty-lab/tunnelIt first probes your Ollama and reports what it found:
chatty-tunnel✓ Ollama at http://localhost:11434 — 7 modelsIf instead you see
! No Ollama at http://localhost:11434 yet, the agent carries on and links anyway — a machine that starts the tunnel before Ollama recovers by itself — but nothing will answer until Ollama is up. Start it, or point the agent elsewhere with--ollama. -
Approve the machine.
The agent prints a short code and opens your browser at the approval page:
Approve this machine at: https://chatty-lab.com/link?code=K7Q2-9F4MCode: K7Q2-9F4MWaiting for approval… (it will be called "lab-gpu-1" unless you rename it there)If no browser opens — common over SSH — open that URL yourself, on any device. The code is valid for 10 minutes.
On that page, confirm the workspace shown and approve. The name box is optional: left empty, the machine’s own name is used — its hostname, or whatever you passed to
--name— and that is what appears in Settings. The agent is polling and picks it up within a couple of seconds. -
Done — the server registers itself.
✓ Linked✓ Connected — exposing http://localhost:11434Go to Settings → Ollama & embeddings and your machine is listed, marked tunnel. You do not add it by hand: the agent creates the entry on connect. If it is the first Ollama server in the workspace, it also becomes the default.
-
Use the models. Open a chat and the model picker now includes everything
ollama listshowed. Nothing else to configure.
Command-line options
Section titled “Command-line options”| Option | What it does | Default |
|---|---|---|
--ollama <url> | The Ollama to expose. | http://localhost:11434 |
--name <label> | What this machine is called in Settings. The approval page can override it. | this machine’s hostname |
--token <token> | Skip the browser approval entirely. For servers and CI. | — |
--api <url> | Point at a different Chatty backend, e.g. a self-hosted one. | https://api.chatty-lab.com |
--help, -h | Print the options and exit. | — |
Ollama on another box on the same LAN, tunnelled from this one:
npx @chatty-lab/tunnel --ollama http://192.168.1.40:11434Keeping it up
Section titled “Keeping it up”The agent reconnects on its own. A closed laptop lid, a Wi-Fi change or a backend deploy all end the connection, and it retries with a widening delay — one second, then two, then four, up to thirty — until it is back. You do not need to touch the terminal.
For a machine that should serve permanently, run it as a service rather than in a shell. A minimal systemd unit:
[Unit]Description=Chatty tunnel for local OllamaAfter=network-online.target
[Service]ExecStart=/usr/bin/npx --yes @chatty-lab/tunnelEnvironment=CHATTY_TUNNEL_TOKEN=paste-token-hereRestart=alwaysRestartSec=5User=YOUR_USER
[Install]WantedBy=multi-user.targetsudo systemctl enable --now chatty-tunnelHeadless machines
Section titled “Headless machines”The browser step needs a browser somewhere, but not on the server. Two ways round it:
-
Approve from your phone or laptop. The code is just text — read it off the SSH session and open
https://chatty-lab.com/linkanywhere. -
Reuse a token. Once a machine is linked, the same token can be passed directly, which skips the approval entirely:
Terminal window CHATTY_TUNNEL_TOKEN=<token> npx @chatty-lab/tunnel--token <token>does the same thing. Treat it like a password: it grants access to the workspace it was approved for.
Troubleshooting
Section titled “Troubleshooting”✗ Needs Node 22 or newer (or, on agent 0.1.0, ReferenceError: WebSocket is not defined)
The agent uses the WebSocket built into Node, which only exists from Node 22. Older versions get
as far as linking — fetch has been there since Node 18 — and then fail on the first dial. Check
with node -v, then install Node 22 (nvm install 22 && nvm use 22) and run the command again.
! No Ollama at http://localhost:11434 yet
Ollama isn’t running, or it listens somewhere else. The agent carries on and connects anyway, so a
machine that starts the tunnel before Ollama recovers on its own; requests arriving meanwhile are
answered with the error. Confirm with curl http://localhost:11434/api/tags, then pass --ollama
if the address differs.
✗ the server rejected this token — link the machine again
The token was revoked from Settings → Ollama servers, or belongs to a workspace that is gone.
Run the agent without --token to link the machine afresh.
the code expired before it was approved
Codes last 10 minutes. Run the command again to get a fresh one.
That code is unknown, already used, or expired.
Each code is good for exactly one approval. Get a new one rather than reusing the old.
“The tunnel for this Ollama server is not connected.” The server is registered but nothing is serving it: the agent isn’t running on that machine, or it lost its connection. Start it again and the same entry comes back to life.
The models don’t appear in the picker. The model list is cached briefly per workspace. Reload the page; if it is still empty, check that you approved into the workspace you are currently viewing.
Security
Section titled “Security”- The agent only forwards requests to the Ollama address you gave it. It opens no port and exposes nothing else on your machine.
- The token belongs to the workspace that approved it. In a team, that means teammates can use your models — which is the point, but worth knowing before you approve into a shared workspace.
- Revoke at any time from Settings → Ollama & embeddings, with the revoke button on the tunnelled server. The running agent stops serving immediately.