NVIDIA / NVIDIA/Personal-AI-Router

[Feature]: Allow authenticated opt-in LAN access to local compatibility endpoints

Open
#28 7 comments 0 reactions 1 assignee View on GitHub

@sherief-nv is already working on this.

Since Sep 9, 2026.

Dominant language
Go
Stars
1.4k
Forks
250
Avg merge
23h 27m
Merged PRs (30d)
1

Description

Feature request

Please provide a supported, explicit opt-in way to expose PAIR's OpenAI-compatible local endpoint to trusted LAN clients.

Current behavior

PAIR 0.91.7 on Windows 11 binds the LM Studio-compatible proxy on port 1234, but rejects a request arriving through an established firewall/NAT path:

{"code":"loopback-only","error":"plaintext requests are accepted only from loopback; cluster peers must use the mTLS ingress"}

Changing the proxy port preserves the port number but does not change this policy.

Use case

A dedicated Windows GPU workstation already serves:

  • automation clients on another workstation;
  • Kubernetes workloads;
  • an existing firewall-restricted tunnel/NAT endpoint;
  • standard OpenAI-compatible SDKs that cannot run PAIR themselves.

Installing and pairing PAIR inside every client, pod, or workload is substantially more operationally complex than exposing one authenticated endpoint.

Security expectations

I understand why unrestricted plaintext LAN exposure is disabled and am not asking for an insecure default. A secure opt-in mode could require some combination of:

  • an explicit bind address such as 0.0.0.0;
  • API-key authentication or client certificates;
  • source CIDR allowlisting;
  • a prominent warning when enabled.
Requested outcome

Provide a documented, supported mechanism for ordinary OpenAI-compatible clients on trusted networks to access a PAIR endpoint without running a PAIR node locally. The existing loopback-only behavior should remain the default.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.