Skip to content

Connect your own Ollama

Chatty runs in Cloudflare’s network. That has a consequence worth stating plainly: the backend cannot reach a private address. http://localhost:11434, 192.168.x.x and anything behind your router are unreachable from where Chatty lives, no matter how the URL is typed into Settings.

The tunnel agent solves it by reversing the direction. Instead of Chatty dialling into your machine, a small process on your machine dials out to Chatty and keeps the connection open. Requests for your models travel back down that same connection.

Terminal window
npx @chatty-lab/tunnel

That is the whole command. It checks your Ollama, links itself to your account through the browser, registers the server in Settings and stays running.

  • Node.js 22 or newer. The agent has no dependencies — it uses the fetch and WebSocket built into modern Node — so there is nothing to install beyond Node itself.
  • Ollama running, with at least one model pulled. Check with ollama list.
  • An account on Chatty, signed in on a browser on some machine (not necessarily this one).
  1. Check Ollama is answering.

    Terminal window
    ollama list

    If the list is empty, pull something first — a tunnel to a server with no models exposes nothing useful.

    Terminal window
    ollama pull llama3.2
  2. Pick the right workspace in the browser.

    The tunnel is granted to whichever workspace is active when you approve it, so switch workspace before the next step if this server belongs to a team rather than to you. See Workspaces & Teams.

  3. Run the agent on the machine where Ollama lives.

    Terminal window
    npx @chatty-lab/tunnel

    It first probes your Ollama and reports what it found:

    chatty-tunnel
    ✓ Ollama at http://localhost:11434 — 7 models

    If instead you see ! No Ollama at http://localhost:11434 yet, the agent carries on and links anyway — a machine that starts the tunnel before Ollama recovers by itself — but nothing will answer until Ollama is up. Start it, or point the agent elsewhere with --ollama.

  4. Approve the machine.

    The agent prints a short code and opens your browser at the approval page:

    Approve this machine at: https://chatty-lab.com/link?code=K7Q2-9F4M
    Code: K7Q2-9F4M
    Waiting for approval… (it will be called "lab-gpu-1" unless you rename it there)

    If no browser opens — common over SSH — open that URL yourself, on any device. The code is valid for 10 minutes.

    On that page, confirm the workspace shown and approve. The name box is optional: left empty, the machine’s own name is used — its hostname, or whatever you passed to --name — and that is what appears in Settings. The agent is polling and picks it up within a couple of seconds.

  5. Done — the server registers itself.

    ✓ Linked
    ✓ Connected — exposing http://localhost:11434

    Go to Settings → Ollama & embeddings and your machine is listed, marked tunnel. You do not add it by hand: the agent creates the entry on connect. If it is the first Ollama server in the workspace, it also becomes the default.

  6. Use the models. Open a chat and the model picker now includes everything ollama list showed. Nothing else to configure.

OptionWhat it doesDefault
--ollama <url>The Ollama to expose.http://localhost:11434
--name <label>What this machine is called in Settings. The approval page can override it.this machine’s hostname
--token <token>Skip the browser approval entirely. For servers and CI.—
--api <url>Point at a different Chatty backend, e.g. a self-hosted one.https://api.chatty-lab.com
--help, -hPrint the options and exit.—

Ollama on another box on the same LAN, tunnelled from this one:

Terminal window
npx @chatty-lab/tunnel --ollama http://192.168.1.40:11434

The agent reconnects on its own. A closed laptop lid, a Wi-Fi change or a backend deploy all end the connection, and it retries with a widening delay — one second, then two, then four, up to thirty — until it is back. You do not need to touch the terminal.

For a machine that should serve permanently, run it as a service rather than in a shell. A minimal systemd unit:

/etc/systemd/system/chatty-tunnel.service
[Unit]
Description=Chatty tunnel for local Ollama
After=network-online.target
[Service]
ExecStart=/usr/bin/npx --yes @chatty-lab/tunnel
Environment=CHATTY_TUNNEL_TOKEN=paste-token-here
Restart=always
RestartSec=5
User=YOUR_USER
[Install]
WantedBy=multi-user.target
Terminal window
sudo systemctl enable --now chatty-tunnel

The browser step needs a browser somewhere, but not on the server. Two ways round it:

  • Approve from your phone or laptop. The code is just text — read it off the SSH session and open https://chatty-lab.com/link anywhere.

  • Reuse a token. Once a machine is linked, the same token can be passed directly, which skips the approval entirely:

    Terminal window
    CHATTY_TUNNEL_TOKEN=<token> npx @chatty-lab/tunnel

    --token <token> does the same thing. Treat it like a password: it grants access to the workspace it was approved for.

✗ Needs Node 22 or newer (or, on agent 0.1.0, ReferenceError: WebSocket is not defined) The agent uses the WebSocket built into Node, which only exists from Node 22. Older versions get as far as linking — fetch has been there since Node 18 — and then fail on the first dial. Check with node -v, then install Node 22 (nvm install 22 && nvm use 22) and run the command again.

! No Ollama at http://localhost:11434 yet Ollama isn’t running, or it listens somewhere else. The agent carries on and connects anyway, so a machine that starts the tunnel before Ollama recovers on its own; requests arriving meanwhile are answered with the error. Confirm with curl http://localhost:11434/api/tags, then pass --ollama if the address differs.

✗ the server rejected this token — link the machine again The token was revoked from Settings → Ollama servers, or belongs to a workspace that is gone. Run the agent without --token to link the machine afresh.

the code expired before it was approved Codes last 10 minutes. Run the command again to get a fresh one.

That code is unknown, already used, or expired. Each code is good for exactly one approval. Get a new one rather than reusing the old.

“The tunnel for this Ollama server is not connected.” The server is registered but nothing is serving it: the agent isn’t running on that machine, or it lost its connection. Start it again and the same entry comes back to life.

The models don’t appear in the picker. The model list is cached briefly per workspace. Reload the page; if it is still empty, check that you approved into the workspace you are currently viewing.

  • The agent only forwards requests to the Ollama address you gave it. It opens no port and exposes nothing else on your machine.
  • The token belongs to the workspace that approved it. In a team, that means teammates can use your models — which is the point, but worth knowing before you approve into a shared workspace.
  • Revoke at any time from Settings → Ollama & embeddings, with the revoke button on the tunnelled server. The running agent stops serving immediately.