Hmbown/CodeWhale · error
Refusing insecure base URL
Error message
Refusing insecure base URL '{display_base_url}'.
Loopback hosts (localhost, 127.0.0.1, [::1]) are auto-allowed.
For one trusted local provider (LAN, llama.cpp on a private IP, etc.) set
`allow_insecure_http = true` under its `[providers.<name>]` table in config.toml.
To allow it for every provider in this shell instead, set the env var
{ALLOW_INSECURE_HTTP_ENV}=1 and re-run. What it means
The client refuses plain-HTTP base URLs by default to prevent credentials and chat content from being sent unencrypted. Loopback hosts (localhost, 127.0.0.1, [::1]) are exempted. The error explains the three sanctioned opt-outs: per-provider allow_insecure_http in config.toml, or the shell-wide env var.
Solutions
- Use https:// in the provider's base_url if the server supports TLS.
- Set allow_insecure_http = true under [providers.<name>] in config.toml for that one trusted local provider.
- Set the ALLOW_INSECURE_HTTP env var to 1 to allow HTTP for every provider in this shell session.
- If the host is loopback, switch to http://localhost/... so it is auto-allowed.
Example fix
// before (config.toml) [providers.llamacpp] base_url = "http://192.168.1.10:8080" // after [providers.llamacpp] base_url = "http://192.168.1.10:8080" allow_insecure_http = true
Defensive patterns
Strategy: validation
Validate before calling
let url = reqwest::Url::parse(base_url)?;
let loopback = matches!(url.host_str(), Some(h) if h == "localhost" || h.starts_with("127.") || h == "[::1]");
if url.scheme() == "http" && !loopback && !allow_insecure_http {
return Err("http base URL requires allow_insecure_http or a loopback host");
} Try / catch
match client_err {
e if e.to_string().contains("Refusing insecure base URL") => {
// switch to https or set allow_insecure_http for this provider
}
other => return Err(other),
} Prevention
- Default all provider base_urls to https://.
- Only enable allow_insecure_http for loopback/LAN dev servers you control.
- Never set the shell-wide insecure HTTP env var in production shells.
- Audit config.toml for http:// URLs before deploying.
When it happens
Trigger: Configuring a provider's base_url with an http:// scheme pointing at a non-loopback host (e.g. http://192.168.1.10:8080) without allow_insecure_http=true for that provider and without ALLOW_INSECURE_HTTP_ENV=1 set.
Common situations: Pointing at a LAN llama.cpp/llama-server or other local inference server on a private IP; copying a provider config written for a local HTTP endpoint; typos like http:// when the provider actually serves HTTPS.
Understand the failure class
Background: "Invalid URL" / "URL cannot be empty": fix the malformed or missing URL behind request-construction failures — this error's family across 50 libraries.
Related errors
- Refusing insecure base URL
- building bundle fetch client failed
- bundle redirects may not change URL scheme
- Codewhale web is loopback-only and must bind to 127.0.0.1
- returned an untrusted verification URI
AI-assisted analysis of Hmbown/CodeWhale@433685b202 (2026-09-15).
Data as JSON: /api/errors/1cbd9982083db6e2.
Report an issue: GitHub.
Appendix: source
Thrown at crates/tui/src/client.rs:1028
);
return Ok(());
}
if parsed.scheme() == "http"
&& std::env::var(ALLOW_INSECURE_HTTP_ENV)
.or_else(|_| std::env::var(LEGACY_ALLOW_INSECURE_HTTP_ENV))
.ok()
.as_deref()
.is_some_and(|v| v == "1" || v.eq_ignore_ascii_case("true"))
{
logging::warn(format!(
"Using insecure HTTP base URL because {ALLOW_INSECURE_HTTP_ENV} is set"
));
return Ok(());
}
if parsed.scheme() == "http" {
anyhow::bail!(
"Refusing insecure base URL '{display_base_url}'.\n\
\n\
Loopback hosts (localhost, 127.0.0.1, [::1]) are auto-allowed.\n\
For one trusted local provider (LAN, llama.cpp on a private IP, etc.) set\n\
`allow_insecure_http = true` under its `[providers.<name>]` table in config.toml.\n\
To allow it for every provider in this shell instead, set the env var\n\
`{ALLOW_INSECURE_HTTP_ENV}=1` and re-run.",
);
}
anyhow::bail!(
"Refusing base URL '{display_base_url}': only HTTPS (or explicitly allowed HTTP) URLs are supported.",
)
}
pub(crate) fn redact_url_for_display(url: &str) -> String {
let Ok(mut parsed) = reqwest::Url::parse(url) else {
return url.to_string();View on GitHub (pinned to 433685b202)