Nakama

Outbound connections

Nakama is self-hosted, but self-hosted does not mean offline. A model request, channel worker, connected mailbox, network tool, plugin, or update check can send data to another service.

The base server does not send telemetry. It contacts an external service only after a feature is configured or invoked. The packaged desktop app is the one default exception: it checks the Nakama GitHub release feed for updates.

This inventory lets operators answer two questions before enabling a feature:

  1. Which destination must the deployment be allowed to reach?
  2. Which user or organization data can cross that boundary?

How to read the inventory

ModeMeaning
Always onThe installed component contacts the destination without a user invoking that feature.
ConfiguredNo call occurs until an operator supplies credentials or enables the integration. Once running, the integration may keep a connection open or retry automatically.
Opt-inA user, admin, agent, or automation explicitly starts the operation.

A row can have two modes. For example, enabling a channel is an operator choice, then its worker keeps a connection open without another click.

Inventory

FeatureModeDestinationData that can leave Nakama
Packaged desktop updatesAlways onNakama releases on GitHubUpdate metadata request, desktop version, platform, and normal HTTP metadata. The check runs at startup and every six hours; Windows Store builds are excluded.
LLM chat and text generationConfigured, then opt-in or automation-drivenThe selected provider or custom base URLSystem prompt, conversation history, tool definitions, tool results, selected files or images, model settings, and generated output. Automations and coding-agent helper calls use the same provider boundary.
ChatGPT subscription connectionOpt-in, then configuredOpenAI device authorization, token, Codex model, and Codex inference endpointsDevice authorization state, OAuth tokens, model requests, prompts, history, tools, attachments, and responses.
xAI subscription connectionOpt-in, then configuredxAI device authorization, token, model, and inference endpointsDevice authorization state, OAuth tokens, model requests, prompts, history, tools, attachments, and responses.
Public model catalogsOpt-inmodels.dev, OpenRouter, or Cerebras public catalog endpointsIP address and normal HTTP metadata. These catalog calls do not include a saved provider API key. Results are cached in memory for 30 minutes.
Provider model discoveryOpt-inThe selected provider's /models endpoint, including custom and local URLsProvider API key when one is configured, requested endpoint, and normal HTTP metadata. Discovered model IDs are stored in the provider configuration.
Audio transcriptionConfigured, then opt-inThe configured OpenAI provider's transcription base URLRaw audio bytes, filename, media type, selected model, and API key.
Image generationConfigured, then opt-inOpenAI Images APIImage prompt, requested size and model, API key, and the generated image response.
Hosted model web searchConfigured, then opt-inThe active LLM providerSearch query and the surrounding model request. Provider-hosted search follows that provider's retention and browsing rules.
Custom web searchConfigured, then opt-inExa, Firecrawl, or the operator-supplied search endpointSearch query and API key. Search results return to the model as tool output.
web_fetchOpt-inAny public HTTP or HTTPS URL selected by the user or agentRequested URL, normal HTTP metadata, and any information encoded in that URL. The tool blocks private and reserved destinations and revalidates redirects, but it intentionally has broad public-web egress.
Remote images rendered in chatOpt-in when a chat view loads a remote Markdown imageThe image's public HTTPS URL, fetched through the Nakama serverRequested URL, server IP address, normal HTTP metadata, and any information encoded in the URL. The proxy blocks private/reserved destinations, revalidates redirects and DNS, accepts only HTTPS on port 443, and validates bounded raster-image responses. This path does not require web_fetch to be assigned.
Agent-browser installationOpt-in, platform admin onlyThe npm registry and the browser download destinations used by agent-browser installPackage and browser version, host platform, IP address, and normal download metadata.
Browser automationOpt-inSites selected by the user or agent, plus any subresources those sites loadPage requests, browser storage, uploaded content, typed data, and credentials entered in that browser session. Browser traffic is not limited to hosts visible in a prompt.
Coding agents and host bashOpt-inDestinations contacted by Codex, Claude Code, OpenCode, pi, Cursor Agent, package managers, git, or invoked commandsRepository content, prompts, provider credentials passed to the selected harness, command arguments, and anything the spawned process reads and transmits. This egress is not statically enumerable.
Telegram managed-bot pairingOpt-in, org admin or platform adminThe configured manager service or getnakama.cloud; the Telegram Bot API when a self-hosted manager token is usedPairing action and identifier, short-lived pairing bearer secret, suggested bot username, and resulting user/bot identifiers and token. Pairing starts before a channel token is configured.
Telegram channelConfigured, then continuously connected or polledTelegram Bot API and Telegram file endpointsBot token, chat and user identifiers, messages, files, typing state, and delivery results.
Discord channelConfigured, then continuously connectedDiscord gateway, REST API, and Discord-hosted attachment URLsBot token, server/channel/user identifiers, messages, commands, files, typing state, and delivery results.
Slack channelConfigured, then continuously connectedSlack Web API at slack.com/api and the Socket Mode WebSocket URL returned by SlackBot and app tokens, workspace/channel/member identifiers, message text, thread IDs, reactions, pairing checks, and delivery results. The current bridge sends text only; it does not transfer files or images.
WhatsApp channelConfigured, then continuously connectedWhatsApp Web endpoints selected by BaileysLinked-device credentials, account and chat identifiers, messages, media, receipts, and protocol metadata. The worker also retrieves compatible WhatsApp Web version information when it starts.
NotificationsConfigured, then opt-in or automation-drivenThe configured Telegram, Discord, WhatsApp, or email destinationNotification text, artifact link or attachment, destination identifiers, and delivery metadata.
ComposioConfigured, then opt-inComposio's API, OAuth destination, and the session MCP URL returned by ComposioAPI key, Nakama user identifier, toolkit and connected-account identifiers, OAuth state and callback URL, tool arguments, and tool results. The connected SaaS may receive the action data through Composio.
HTTP MCP serversConfigured, then opt-inThe exact URL configured by an admin; preinstalled choices include Exa, Firecrawl, and Currency MCPConfigured headers, tool discovery requests, tool name, tool arguments, and returned content. MCP OAuth can also contact authorization and token endpoints discovered for that server.
Stdio MCP serversConfigured, then opt-inA local child process; that process may contact any destination allowed by the hostTool arguments and results, plus any files, environment values, or network data the configured process accesses. Nakama cannot inventory a child process's own egress.
Email tool and email notificationsConfigured, then opt-inOperator-supplied IMAP and SMTP serversMailbox credentials, folder and search operations, message bodies and attachments, recipients, subjects, and sent content. TLS certificate verification is enabled.
Error trackingConfiguredThe ingest endpoint encoded in the saved Sentry-compatible DSNScrubbed error name, message and stack, process, Bun version, platform, and architecture. Request bodies and prompts are not intentionally attached, and HTTP 4xx responses and cancelled turns are excluded. Error messages or stacks can still contain user-derived or operational text that the scrubber does not recognize, so treat the sink as sensitive; see Error tracking.
API reference UIOpt-in when /docs is openedjsDelivr, Scalar fonts, and Scalar's vector registryViewer IP address, browser metadata, referrer allowed by browser policy, and API-reference search requests. The OpenAPI document itself is served by the local Nakama server.
Chat YouTube embedsOpt-in when a rendered chat message contains a recognized YouTube URLyoutube-nocookie.com and media subresources selected by YouTubeVideo identifier, viewer IP address, browser metadata, and referrer allowed by browser policy. The iframe is lazy-loaded but does not require a separate click.
GitHub skill installationOpt-inGitHub archive or git endpoints for the selected public repositoryRepository owner, name, ref, and normal download metadata. The downloaded skill content is stored locally.
npm plugin package installationOpt-in, platform admin onlyregistry.npmjs.org metadata and tarball endpointsExact package name and version plus normal HTTP metadata. Nakama requires an HTTPS registry tarball, verifies its published integrity, and does not run package install scripts.
Token optimiser runtime installOpt-inThe pinned omni release and checksum on GitHubRequested Nakama-supported platform target, pinned version, and normal HTTP metadata. The download occurs only when the binary is absent, the feature is enabled, and automatic install is allowed.
Supermemory pluginConfigured, then used with memory or knowledge searchA local or operator-supplied Supermemory endpoint; an automatic worker can also download its pinned server from GitHub and use the configured OpenAI-compatible providerMemory and knowledge-base text, semantic queries, document identifiers, provider key, and content sent for extraction or embedding.
Google MeetConfigured, then opt-inGoogle Meet in the browser, the configured capture WebSocket, and OpenAI transcription and chat endpointsMeeting audio chunks, transcript text, meeting metadata, OpenAI key, and summary prompts and responses.
Skill scripts, custom tools, and pluginsConfigured, then opt-inAny destination implemented by the installed JavaScript, TypeScript, Python, worker, or action codeAny tool input, workspace data, credentials, and environment values that code can read. Declared skill scripts and tool modules can run as host code after the applicable review and assignment; this egress is not statically enumerable.
CLI remote-server connectionConfiguredThe operator-selected Nakama server URLLogin credentials, session token, org context, chat requests, files, and API responses. The CLI refuses to send its saved session to a different origin.
Desktop remote-server connectionConfigured with NAKAMA_DESKTOP_URLThe operator-selected Nakama web originNormal browser traffic to that Nakama deployment, including login, org context, chat requests, files, and API responses.

Built-in model destinations

The LLM row above resolves to one configured provider at a time. Built-in defaults cover:

  • OpenAI, Anthropic, Gemini, OpenRouter, DeepSeek, Together AI, Mistral, Perplexity, xAI, Cerebras, Fireworks, Cloudflare Workers AI, OpenCode Go, Vercel AI Gateway, Xiaomi MiMo, and Volcengine Doubao
  • Qwen/DashScope, MiniMax, Moonshot, and Zhipu in their configured global or China-region variants
  • Ollama on localhost, Ollama Cloud, or an operator-supplied base URL
  • any operator-supplied OpenAI-compatible endpoint

An overridden base URL replaces the default destination for providers that support overrides. Build an egress rule from the saved configuration, not only from this list.

What is not a fixed destination

Some features are deliberately programmable. A truthful inventory cannot turn them into a short host allowlist:

  • public URLs requested through web_fetch
  • remote image URLs rendered in chat
  • sites and subresources opened by browser automation
  • operator-supplied HTTP MCP and provider URLs
  • network clients started by stdio MCP, skill scripts, custom tools, plugins, bash, or coding agents
  • IMAP and SMTP hosts supplied by an operator
  • subresources loaded by browsed sites or embedded third-party content

If your environment requires fixed egress, leave those capabilities unassigned or run Nakama behind a policy-enforcing proxy or firewall. Application settings are not a substitute for a network boundary around child processes.

What stays local by default

  • The server does not send product analytics or usage telemetry.
  • HTTP metrics remain local until NAKAMA_METRICS=true, and Nakama does not push them to a collector.
  • Session history, SQLite data, profile workspaces, org memory, attachments, and plugin data remain in the configured data root unless a configured provider, tool, channel, plugin, share, export, or user action sends them elsewhere.
  • Automation and channel workers call the local Nakama API over loopback. Those internal calls are not third-party egress.

Audit basis

This inventory was verified against 1a1113fc. The review followed production network call sites and the clients they construct, including raw HTTP, provider SDKs, WebSockets, MCP transports, IMAP/SMTP, channel libraries, plugin downloads, spawned coding harnesses, and the desktop updater. It did not treat a search for literal https:// strings as an inventory.

Recheck the inventory whenever a provider, channel, plugin, tool, MCP transport, desktop updater, or network-capable dependency changes. A useful review compares new production fetch calls and network-client construction with every row above, then follows wrappers until the trigger and transmitted data are known.

On this page