ShroomPenAdd to Chrome

Set OLLAMA_ORIGINS for a Chrome extension

Ollama answers 403 Forbidden to a Chrome extension because the extension’s requests carry the origin chrome-extension://<extension id>, and Ollama’s default allow list doesn’t include browser extensions. Fix it by setting the OLLAMA_ORIGINS environment variable to that one origin, chrome-extension:// followed by the extension’s ID, and restarting Ollama. Avoid OLLAMA_ORIGINS=*, which lets every website and extension in your browser use your Ollama API.

Published

Why the 403 happens

Ollama’s server checks the Origin header on requests that come from a browser. If the origin is on its allow list, it answers normally and adds an Access-Control-Allow-Origin header. If it isn’t, it stops the request with 403 Forbidden and an empty body.

The built-in list (see envconfig/config.go) covers http and https on localhost, 127.0.0.1 and 0.0.0.0 on any port, plus the app://, file://, tauri://, vscode-webview:// and vscode-file:// schemes. Browser extensions are not on it. Ollama’s FAQ says so directly: for browser extensions you need to allow the extension’s origin yourself.

We checked what Chrome actually sends with a test extension that has host permission for localhost (Ollama 0.10.1, Chrome 147):

Request from the extensionOrigin headerDefault OllamaOLLAMA_ORIGINS set to the extension
GET /v1/models (model list)None200 OK200 OK
POST /v1/chat/completions (chat)chrome-extension://<id>403 ForbiddenWorks

That is why an extension can list your models and still fail the moment it sends a prompt. The fix is on Ollama’s side, not in the extension’s settings.

The fix

  1. Find the extension’s ID

    Open chrome://extensions, switch on Developer mode and copy the ID shown on the extension’s card. The ID is also the last part of its Chrome Web Store address. ShroomPen’s ID is shown below.

    ghigbnpoahodgnhlgbggjphpflkofgfn
  2. Set OLLAMA_ORIGINS to the extension’s origin

    Set the environment variable OLLAMA_ORIGINS to chrome-extension:// followed by the ID. For ShroomPen the line is shown below. Separate several origins with commas.

    OLLAMA_ORIGINS=chrome-extension://ghigbnpoahodgnhlgbggjphpflkofgfn
  3. Restart Ollama

    Quit Ollama completely and start it again. It reads OLLAMA_ORIGINS only when it starts.

  4. Check the origin is allowed

    Send a request with that Origin header using curl. The answer should be 200 OK with an Access-Control-Allow-Origin header naming the extension, not 403 Forbidden.

    curl -i -H "Origin: chrome-extension://ghigbnpoahodgnhlgbggjphpflkofgfn" http://localhost:11434/api/version

    Look for HTTP/1.1 200 OK and an Access-Control-Allow-Origin header that repeats the extension’s origin. If you still see 403 Forbidden, Ollama is running without the new setting. In Windows PowerShell 5, type curl.exe instead of curl.

How to set OLLAMA_ORIGINS on each system

Replace the origin below with your extension’s if you are not using ShroomPen. These steps follow Ollama’s FAQ on configuring the server.

Windows

Ollama on Windows reads your user and system environment variables when it starts.

  1. Quit Ollama from its icon in the taskbar notification area.
  2. Open Settings and search for “environment variables”, then choose “Edit environment variables for your account”.
  3. Add a new user variable named OLLAMA_ORIGINS. For the value, paste the extension’s origin (the part after OLLAMA_ORIGINS= in step 2 above), then click OK.
  4. Start Ollama again from the Start menu.

Or set the same user variable from a terminal, then quit and restart Ollama:

setx OLLAMA_ORIGINS "chrome-extension://ghigbnpoahodgnhlgbggjphpflkofgfn"

macOS (Ollama app)

The Ollama app doesn’t read your shell profile, so set the variable with launchctl, then quit Ollama from the menu bar and open it again:

launchctl setenv OLLAMA_ORIGINS "chrome-extension://ghigbnpoahodgnhlgbggjphpflkofgfn"

A value set with launchctl setenv does not survive a restart of the Mac. Run the command again after a restart, or add it to a login script.

Linux (systemd service)

The install script sets Ollama up as a systemd service. Run sudo systemctl edit ollama and add these lines:

[Service]
Environment="OLLAMA_ORIGINS=chrome-extension://ghigbnpoahodgnhlgbggjphpflkofgfn"

Then reload and restart:

sudo systemctl daemon-reload
sudo systemctl restart ollama

Running ollama serve by hand

If you start the server yourself in a terminal (macOS or Linux), set the variable on the same line:

OLLAMA_ORIGINS=chrome-extension://ghigbnpoahodgnhlgbggjphpflkofgfn ollama serve

Why not OLLAMA_ORIGINS=*

A lot of guides tell you to set OLLAMA_ORIGINS=*. It works, but it tells Ollama to answer browser requests from any origin at all. Any website open in your browser, and any extension you have installed, could then send prompts to your local models, see which models you have, and read the answers. The same goes for chrome-extension://*, which the Ollama FAQ offers as the “allow all extensions” option.

Naming the one extension you use costs nothing extra and keeps everything else out. We tested it: with OLLAMA_ORIGINS set to one extension’s origin, requests from that extension succeed and requests carrying any other extension’s origin still get 403.

Using Ollama from ShroomPen

ShroomPen is a free Chrome extension that puts a local model’s draft straight into the text field you are writing in. It sends requests from its background worker, so it needs the OLLAMA_ORIGINS entry above. Page Assist, an open-source sidebar extension, rewrites headers for localhost addresses and usually works without it.

The rest of the setup, from pulling a model to the first draft, is in Use Ollama in Chrome. Or add ShroomPen to Chrome and choose Local server in its settings.

Related

Questions

Why does Ollama return 403 Forbidden to my Chrome extension?

Ollama checks the Origin header of browser requests against an allow list. By default the list covers http and https on localhost, 127.0.0.1 and 0.0.0.0 plus a few desktop app schemes, but not chrome-extension:// origins, so Ollama rejects the request with 403 and an empty body.

Should I set OLLAMA_ORIGINS to *?

Better not. With * Ollama answers browser requests from any origin, so any website you visit and any extension you have installed could send prompts to your models or read the answers. Allow the one extension you use instead.

Why does the model list load but chat still fails with 403?

Chrome leaves the Origin header off simple GET requests that an extension with host permission makes, such as the model list, but adds it to POST requests, such as chat. Ollama only checks requests that carry an Origin, so the list works and chat is rejected until the extension’s origin is allowed.

Can I allow several extensions?

Yes. OLLAMA_ORIGINS takes a comma-separated list, for example two chrome-extension:// origins separated by a comma, with no spaces.

Does OLLAMA_ORIGINS replace the default origins?

No. Ollama adds your origins to its built-in list, so localhost pages and desktop apps that worked before keep working.

Is the extension ID the same on every computer?

For an extension installed from the Chrome Web Store, yes. An unpacked copy loaded in developer mode gets a different ID, so check chrome://extensions if you use one.

I set OLLAMA_ORIGINS and still get 403. What now?

Usually Ollama was not fully restarted, or the variable was set somewhere the Ollama process does not read it. Quit Ollama from the tray or menu bar icon, start it again, and run the curl check. Also check for a typo or a trailing slash in the origin.