GitHub - TinySuiteHQ/TinyWebUI: A small, local-first, cache efficient chat workspace for any OpenAI-compatible model, with MCP tools.

GitHub

4 min read Original article ↗

TinyWebUI is the chat interface of TinySuite, a set of small, local-first tools for AI agents. Bring an endpoint (OpenRouter, OpenAI, Groq, Ollama, vLLM, LM Studio, or anything else that speaks the OpenAI API), pick a model and a system prompt, and start working. Chats, documents and tool output stay in one SQLite file on your machine. There is no hosted backend, no account to create, no build step and no frontend framework.

It comes pre-loaded with two TinySuite MCP servers, so a new install can already search the web and remember things:

  • TinySearch searches, reads and reranks the web locally. It doesn't need a search API key.
  • TinyContext is a local long-term memory that recalls only what fits the token budget.

Highlights

  • Durable conversations. Edit, retry, rewind, folders and full-text search. A running turn belongs to the server, so you can reload and come back to it.
  • Steer a turn while it runs. Press Enter to reach the model at the next safe point, or Alt+Enter to hold a follow-up.
  • MCP over stdio, Streamable HTTP or SSE. Calls that can change something wait for your approval.
  • Attachments. Text and source files, PDFs, DOCX and images.
  • Hybrid local search (BM25 plus a small on-device embedding model) over documents and past chats.
  • Long chats that stay affordable. Cache-friendly prefixes, one-time compaction of large tool results, and per-round token statistics.
  • Automations. Cron-scheduled prompts that run in a chat of your choice.
  • Private by default. Local starts sign in with a one-time link from the terminal, network binds need a password, and a team can use an SSO gateway with roles and an admin panel.
  • Managed from files. Version-controlled config that hot-reloads, refuses typos and has a fingerprint you can check against a running instance.
  • Themes. Fall Fairy and Cyber Grid are included. See theme authoring to write your own.

Quick start

Requires Node.js 22.13 or later. The bundled TinySearch and TinyContext servers also need uv, which fetches them the first time they start.

There is no password to set up. The terminal prints a sign-in link (http://127.0.0.1:7777/#token=…); open it and the browser stays signed in. Only someone who can read that terminal gets in. Then connect a model. Put an endpoint and key in tinywebui.config.json (start from example.tinywebui.config.json) or use the Settings panel:

{
  "baseUrl": "https://openrouter.ai/api/v1",
  "apiKey": "sk-or-...",
  "model": "deepseek/deepseek-v4.1-flash"
}

tinywebui.config.json holds your API keys (and password hash, if you set one) and is gitignored. Keep it that way. Run npx tinywebui set-password to sign in with a password instead of the link; you need one to listen on anything other than loopback.

npx tinywebui uses keyword search until you run npx tinywebui models pull fast (about 90 MB) to enable hybrid search.

From a clone, run npm install && npm start. With Docker, create the owner password in the persistent volume before starting the service:

docker compose build
docker compose run --rm -it tinywebui set-password
docker compose up -d

The Compose example publishes port 7777 on the host's loopback interface. The Docker image also accepts TINYWEBUI_PASSWORD for a headless first start; use a password of at least 15 characters and keep the container's data volume. Without credentials, a headless start exits before opening a port. The runtime images contain Node.js but no npm/npx; connect MCP servers over HTTP or include their executables in a custom image.

The Compose example now stores config in its named data volume. If you used the previous bind-mounted tinywebui.config.json, copy its settings into the volume before starting, then run set-password there.

Documentation

The full reference lives at tinysuite.dev/docs/tinywebui:

Topic Covers
Quick start npx, clone, Docker
Configuration Environment variables, every setting, the model catalog
MCP tools Adding servers, tool approval, built-in tools
Chats and attachments Documents, images, steering a turn
Search Hybrid retrieval, embedding models, tuning
Automations Scheduled prompts
Long chats Caching and compaction
Usage statistics Token use and attribution
Access Just you, a password, or a team behind SSO
Deployment as code JavaScript config, locked settings, roles and features
CLI Every command
Security and limits Exposure, MCP trust, what isn't included

In this repository: docs/deploy.md is a scripted container deployment, and docs/config.schema.json is the config schema (also tinywebui schema).

Development

npm test        # the whole suite, about 10 seconds
npm run dev     # restart on changes in src/ and bin/

AGENTS.md maps the codebase and says where new code goes. npm run eval runs model-behaviour evals from evals/tasks/ and makes real API calls, so it costs money.

License

GNU Affero General Public License v3.0 or later. If you run a modified version for users over a network, you must offer them the corresponding source code for that version.