--- name: slm-web-access description: Set up and troubleshoot SuperLocalMemory Web access, the optional link that lets web apps (ChatGPT, Claude on the web, Muse, Composio, other remote MCP clients) use the memory on this computer. Covers turning it on from the dashboard, adding and removing apps, read/save/session permissions, renewal, the connection states, the errors a web app can see, and the copy-paste instructions for web agents. when_to_use: "web access, connected apps, connect chatgpt, connect claude web, connect muse, connect composio, remote mcp, mcp.superlocalmemory.com, connector_asleep, DAILY_LIMIT_REACHED, web app cannot reach memory, instructions for web agent" allowed-tools: get_status, Read, Bash --- # slm-web-access — Web apps and bots ## What it is Web access is optional. Without it, SuperLocalMemory works fully on this computer. With it, web apps reach the same memory through SuperLocalMemory's connection gateway: the app signs in with OAuth, the gateway relays each tool call to this computer over an outbound link, and the memory database never leaves the computer. Nobody configures Cloudflare, DNS or a tunnel. Web access is not `slm remote`. `slm remote` is direct access over TLS with named keys, for tools on another computer in your own network. ## Turning it on (the owner does this, in the dashboard) 1. Open the dashboard (`slm dashboard`, default `http://localhost:8765`) and go to **Connected apps**. 2. Under **Add an app**, choose the app: ChatGPT, Claude (web), Claude Code (web), Composio, Muse, or **Other app (MCP)** for any client that supports remote MCP with OAuth. 3. Under **What this app can do**, tick **Turn on internet access for this app** (reading is always included). **Allow saving memories** adds the `remember` tool and **Allow session tools** adds `session_init`, `close_session`, `report_feedback` and `report_outcome`; both are separate opt-ins. 4. Select **Link this computer with GitHub** and finish sign-in in the page that opens. Wait until the row reads "On. Apps you approve can reach your memory while this computer is online." 5. In the app, add a remote MCP connector with the **MCP server URL** `https://mcp.superlocalmemory.com/mcp` and OAuth. Some apps (Composio, Muse) also want the **OAuth metadata URL** `https://auth.superlocalmemory.com/.well-known/oauth-authorization-server`. Both are under **Technical details** with copy buttons. 6. Approve the same GitHub account and profile in the app, then test one recall from the app. An agent cannot do steps 3–6 for the owner: they need the owner's consent and sign-in. Point the owner to the dashboard; never ask for tokens or codes. ## What a web app can call `recall`, `search`, `fetch`, `get_status`; `remember` only with Save; the four session tools only with session tools. It reaches only the profile chosen at setup. `scope` must be personal, `shared_with` is refused, and `replaces` is refused (`CORRECTION_DENIED`): corrections, deletes and sharing stay on this computer. ## Instructions for the web agent The app also needs to know when to use the tools. Give the owner `docs/web-agents/instructions.md` (full and short blocks) or the Agent Skill folder `docs/web-agents/superlocalmemory-web/`. The dashboard's **How to add an app** panel has a **Copy instructions** button with the short block. Exact per-app steps (ChatGPT, ChatGPT dots, Grok Bot, Composio, Muse) are in `docs/remote-access/hosts.md`. ## Renewal The link renews its own credential while the computer is online; the row says **Renews automatically**. If the computer stays offline for weeks, the row warns before access ends ("Web access ends on unless this computer reconnects"). After it ends, or if sign-in is needed again, the row says so and the owner turns Web access on again or signs in again. Local memory is never affected. ## When a web app reports an error | What the app sees | Meaning | What to do | |---|---|---| | `connector_asleep` | This computer was silent for 45 seconds (usually asleep) | Wake the computer; the link reconnects by itself | | `connector_offline`, `connector_unavailable`, `relay_timeout` | The link is down or the call took too long | Check the computer is online and SLM is running (`slm status`) | | `relay_busy` | Too many calls in flight at once | Make calls one at a time | | `DAILY_LIMIT_REACHED` (HTTP 429) | The free daily allowance is used up | Resets at midnight UTC (`Retry-After` says when) | | `TOOL_DENIED`, `INSUFFICIENT_SCOPE` | The app was not given that permission | Remove its access and add it again with the permission ticked | | `CORRECTION_DENIED`, `SHARING_DENIED`, `PROFILE_DENIED` | The app tried something only this computer may do | Do it locally | | `REVOKED` | The owner removed the app | Add it again if wanted | | `ENTITLEMENT_REQUIRED` | Web access has ended | Turn it on again in **Connected apps** | To check from this computer, call `get_status` and run `slm status`; the **Connected apps** page shows each connection's state and access date. ## Removing an app **Connected apps** → the app's row → **Remove access**. The gateway refuses its next call. Memory and local configuration are kept.