Hmbown/CodeWhale · error

Refusing insecure base URL

Error message

Refusing insecure base URL '{display_base_url}'.

Loopback hosts (localhost, 127.0.0.1, [::1]) are auto-allowed.
For one trusted local provider (LAN, llama.cpp on a private IP, etc.) set
`allow_insecure_http = true` under its `[providers.<name>]` table in config.toml.
To allow it for every provider in this shell instead, set the env var
{ALLOW_INSECURE_HTTP_ENV}=1 and re-run.

What it means

The client refuses plain-HTTP base URLs by default to prevent credentials and chat content from being sent unencrypted. Loopback hosts (localhost, 127.0.0.1, [::1]) are exempted. The error explains the three sanctioned opt-outs: per-provider allow_insecure_http in config.toml, or the shell-wide env var.

Solutions

  1. Use https:// in the provider's base_url if the server supports TLS.
  2. Set allow_insecure_http = true under [providers.<name>] in config.toml for that one trusted local provider.
  3. Set the ALLOW_INSECURE_HTTP env var to 1 to allow HTTP for every provider in this shell session.
  4. If the host is loopback, switch to http://localhost/... so it is auto-allowed.

Example fix

// before (config.toml)
[providers.llamacpp]
base_url = "http://192.168.1.10:8080"
// after
[providers.llamacpp]
base_url = "http://192.168.1.10:8080"
allow_insecure_http = true
Defensive patterns

Strategy: validation

Validate before calling

let url = reqwest::Url::parse(base_url)?;
let loopback = matches!(url.host_str(), Some(h) if h == "localhost" || h.starts_with("127.") || h == "[::1]");
if url.scheme() == "http" && !loopback && !allow_insecure_http {
    return Err("http base URL requires allow_insecure_http or a loopback host");
}

Try / catch

match client_err {
    e if e.to_string().contains("Refusing insecure base URL") => {
        // switch to https or set allow_insecure_http for this provider
    }
    other => return Err(other),
}

Prevention

When it happens

Trigger: Configuring a provider's base_url with an http:// scheme pointing at a non-loopback host (e.g. http://192.168.1.10:8080) without allow_insecure_http=true for that provider and without ALLOW_INSECURE_HTTP_ENV=1 set.

Common situations: Pointing at a LAN llama.cpp/llama-server or other local inference server on a private IP; copying a provider config written for a local HTTP endpoint; typos like http:// when the provider actually serves HTTPS.

Understand the failure class

Background: "Invalid URL" / "URL cannot be empty": fix the malformed or missing URL behind request-construction failures — this error's family across 50 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@433685b202 (2026-09-15). Data as JSON: /api/errors/1cbd9982083db6e2. Report an issue: GitHub.

Appendix: source

Thrown at crates/tui/src/client.rs:1028

        );
        return Ok(());
    }

    if parsed.scheme() == "http"
        && std::env::var(ALLOW_INSECURE_HTTP_ENV)
            .or_else(|_| std::env::var(LEGACY_ALLOW_INSECURE_HTTP_ENV))
            .ok()
            .as_deref()
            .is_some_and(|v| v == "1" || v.eq_ignore_ascii_case("true"))
    {
        logging::warn(format!(
            "Using insecure HTTP base URL because {ALLOW_INSECURE_HTTP_ENV} is set"
        ));
        return Ok(());
    }

    if parsed.scheme() == "http" {
        anyhow::bail!(
            "Refusing insecure base URL '{display_base_url}'.\n\
             \n\
             Loopback hosts (localhost, 127.0.0.1, [::1]) are auto-allowed.\n\
             For one trusted local provider (LAN, llama.cpp on a private IP, etc.) set\n\
             `allow_insecure_http = true` under its `[providers.<name>]` table in config.toml.\n\
             To allow it for every provider in this shell instead, set the env var\n\
             `{ALLOW_INSECURE_HTTP_ENV}=1` and re-run.",
        );
    }

    anyhow::bail!(
        "Refusing base URL '{display_base_url}': only HTTPS (or explicitly allowed HTTP) URLs are supported.",
    )
}

pub(crate) fn redact_url_for_display(url: &str) -> String {
    let Ok(mut parsed) = reqwest::Url::parse(url) else {
        return url.to_string();

View on GitHub (pinned to 433685b202)