Deploy Tapicker Bridge Remotely

Use a remote Bridge when the Extension, an AI agent, or both run on different machines. Remote connections must use TLS and an HTTP Bearer Token.

When to Deploy Remotely

For a single computer, keep Bridge bound to its default loopback address (127.0.0.1). Do not expose it to a network unless remote access is needed and you can secure the connection.

Before continuing, obtain a DNS name, a TLS certificate and private key, and a long random Bearer Token. Keep the private key and token out of source control and shared logs.

Start a Secured Bridge

On the server, run:

tapicker bridge start \
  --host 0.0.0.0 \
  --port 9520 \
  --token "$TAPICKER_BRIDGE_TOKEN" \
  --tls-key ./server.key \
  --tls-cert ./server.crt

Set TAPICKER_BRIDGE_TOKEN in the server environment before starting the process. Bridge refuses non-loopback binding unless a Token and both TLS files are provided.

Connect the Extension

In Settings > General > Bridge in the Tapicker Extension, enter the secure WebSocket endpoint:

wss://bridge.example.com:9520/ws

Click Connect, then enter the current four-digit pairing code from the Bridge server. Pairing establishes the Extension’s own saved credential; the HTTP Bearer Token is not the pairing code.

Connect an Agent

For remote Streamable HTTP MCP, configure the agent with:

https://bridge.example.com:9520/mcp

Configure the same Bearer Token as an Authorization: Bearer <token> request header. For HTTP commands, use https://bridge.example.com:9520/v1/... and send the same header.

Security Notes

  • Keep the TLS private key, pairing data directory, and Bearer Token private.
  • The token protects HTTP commands, /v1/extensions, MCP, and Workflow status WebSocket subscriptions. It does not replace Extension pairing on /ws.
  • /v1/health, /v1/discovery, and /v1/capabilities are public endpoints.
  • CORS controls browser access; it is not authentication. Use --cors-origin to allow only the web origins you need.
  • Bridge does not provide Tapicker account authentication or a centralized user/Extension access system.

See the API Reference for the available endpoints and Getting Started for local setup.