FAQ

Straight answers,
no hedging

The questions that come up most — about privacy, architecture, the AI assistant, and where everything lives.

Does OpenDoc UI require a backend server?
No. The documentation browser, the Runner, the schema explorer, notes, theming and code generation all run entirely in the browser. The only optional server components are the AI gateway (for teams that want provider keys server-side) and the proxy agent (for fetching remote specifications across restrictive networks, and for executing Runner requests server-side when APIs send no CORS headers) — both are opt-in.
Are my specifications uploaded anywhere?
Never. Local files are parsed in the browser and stored only in your browser's local history. Nothing is uploaded, and the original document is never modified. When you load a remote URL, the browser fetches it directly (or through a proxy you configured) — no third party is involved.
Which OpenAPI versions are supported?
OpenAPI 3.0, 3.1 and 3.2, plus Swagger 2.0, in YAML or JSON. Modern 3.1/3.2 keywords — const, prefixItems, unevaluatedProperties, if/then/else, type unions, webhooks — are rendered and handled explicitly. OAS 3.2 QUERY (RFC 10008) is first-class in documentation and the Runner. Multi-file reference graphs resolve in memory; experimental YAML auto-repair can open some generator mistakes that omit flow-sequence brackets.
Does the Runner send requests from my browser?
Yes — that is the point. Requests are composed from the specification and executed with the browser's fetch API against the server you select, so you can test real authentication, parameters and bodies without leaving the documentation. The same CORS rules that apply to any web application apply here, and the Runner Compatibility report states what the browser can and cannot do for a given API.
How does the AI assistant work, and where do my keys go?
The assistant receives redacted endpoint and schema context from your open specification and answers with citations. In direct mode, your browser talks to the provider you configure (OpenAI, Anthropic, Ollama, OpenRouter or any compatible endpoint). In gateway mode, a hardened server gateway owns the provider credentials and enforces token authentication, origin allowlists, rate limits and timeouts — the browser never sees the provider key.
Can I run it on an internal network without internet access?
Yes. The application is fully static — copy dist/ to an internal nginx or Apache host, or use the Docker image, and it works offline. Configured specifications can be baked in through config.json or window.INITIAL_CONFIG, and local files always work. The only components that need the internet are the optional AI providers and remote URL loading.
Where are my notes and history stored?
In your browser — IndexedDB first, with a localStorage fallback. Notes, response history, opened-file history, themes and workspace state never leave your machine. Notes export/import as JSON if you want to move or back them up.
How do oneOf / anyOf / allOf work in the UI?
Request bodies, responses and the schema modal share one SchemaViewer. Body-level rails pick root branches; field-level menus reach nested properties — exclusive oneOf, multi-select anyOf (empty All is none), allOf focus with dimming, and inspection-only not. Generated examples and the property table follow the active selection across formats.
Is it really free?
Yes — MIT licensed, no tiers, no telemetry, no account. The source is on GitHub; stars are the only currency accepted.