Local-first AI gatewayOpen source

Connect ChatGPT
to your local projects

Work from the chat you already use

Read and edit files, run commands and review real project work from your regular ChatGPT Web conversation. RepoTunnel connects the local projects you approve through MCP.

No account required Linux, Windows & macOS
Access pathLocal and authenticated
01AI client

Requests a capability through MCP

02
RepoTunnel

Authenticates the request, checks scope and applies the capability policy

IdentityWorkspacePolicy
03Approved capability

Runs only inside the local boundary you selected

01

Unlimited Direct HTTPS connection usage

No monthly tunnel request quota from RepoTunnel

Direct HTTPS connects ChatGPT to your own running RepoTunnel endpoint. Keep working on successive project tasks without a tunnel provider’s monthly request allowance.

Use your existing ChatGPT Web conversation, with no separate OpenAI API key or API token purchases for those chats.

Explore Direct HTTPS
01Approve the workspace

AI receives only the project roots you explicitly share.

02Choose the policy

Read-only, review-first or supported automatic edits.

03Keep the evidence

Changes, process state and Git activity remain inspectable.

From installation to a real task in three decisions

Start small. Approve one project, make one connection and expand only when you need another capability.

01

Install RepoTunnel

Choose the official package for your operating system.

Installation
02

Approve a workspace

Select a project root and the access policy it can use.

First project
03

Connect an AI client

Authenticate the connection and make a real MCP request.

Connection guide
Security by boundary

The permission model is the product

RepoTunnel does not turn AI Auto into unrestricted host access. Every capability keeps its own scope, validation and approval rules.

Explore security
01Workspace-scoped paths

Relative paths, approved roots and protected-file rules stay in force.

02Fail-closed execution

Unsupported sandbox paths do not silently fall back to unrestricted execution.

03Separate device access

Browser, desktop and Android capabilities have independent permission surfaces.

04Explicit publishing

Local edit permission never becomes standing permission to publish Git history.

More in the docs

Before you connect

A few things worth knowing before giving an AI client access to a local machine.

Does RepoTunnel upload my project to its own cloud?

RepoTunnel runs locally and exposes approved capabilities to the AI client. Content retrieved by the client may be processed by your AI provider, so review that provider's terms separately.

Is a RepoTunnel subscription required?

No. RepoTunnel is MIT-licensed and does not require its own account. AI models, tunnels and third-party platforms can have separate costs.

Can AI modify any file it finds?

No. Access is limited to approved workspace roots and protected paths are blocked. Device and desktop capabilities have their own permission controls.

Do all features work identically on every OS?

No. Linux is the primary validated platform. Windows and macOS have native-specific limits documented in the platform reference.

Start typing to search.