Skip to content

Where the key lives

Your API key never leaves your browser except to reach the provider that issued it.

When TabOasis runs an AI action, the request goes from your browser straight to OpenAI or to Google with your key. Our servers never see the key, never see the prompt, and never see the answer.

Two consequences follow:

  • Nothing works without your key, including offline or if the provider is down. There is no fallback and no shared quota.
  • The usage on your provider’s dashboard is the whole picture. If it shows a request, TabOasis made it from your machine.
  • Not in Cloud sync. The upload carries your profiles, focus data and settings. AI settings live elsewhere on the device and never go with it.
  • Not in Export JSON or a profile export. Neither format has a field for it, so a backup you hand to someone else does not carry your key.
  • Not in usage statistics or a bug report.

Once saved, the AI panel shows AI configured with encrypted key storage. The key is encrypted before it is written to browser storage. Treat that as protection against a file being read, not against someone who can run code in your browser. So:

  • Give it the smallest scope and lowest spending cap your provider allows.
  • Do not use a key that also runs something important elsewhere.
  • If a machine is lost or shared, revoke the key at the provider. Removing it in TabOasis only removes this copy.

A browser update can make the stored key unreadable. When that happens, the AI panel reads Not configured even though you have not touched anything. Paste the key in again; nothing else is affected.

The remove button on the API key field deletes this browser’s copy. It does not revoke the key (only your provider can do that), and it does not touch the key stored for the other provider.

Uninstalling the extension removes it along with everything else.