Workspace tools · Browser capture and the Go Tap
Browser capture and the Go Tap
Two optional collectors add evidence the session logs do not hold. The browser extension reads ChatGPT, Claude and Gemini chat tabs and hands records to the desktop app through native messaging; every one of those hosts is still unverified and reads not claimed. The Go Tap is an unsupported beta proxy on loopback that copies API call metadata and counts every copy it drops.
For: the developer who wants chat-tab usage or direct API calls in the evidence, and the lead who has to know how far to trust it
What it does, and why it helps
Browser capture is optional session evidence, not production browser monitoring. The RepoOps browser capture extension (Chrome 111 or later, loaded unpacked; there is no store listing yet) watches chatgpt.com, chat.openai.com, claude.ai and gemini.google.com. It sends records only to the desktop app, through the native messaging host ai.repoops.capture that the app registers for your user each time it starts. There is no port and no fallback to a server on localhost. By default it sends metadata only: counts, timings and the model. Include prompt text is a separate choice, and answer text is never sent.
No browser adapter has been verified against live traffic. In the capture catalog all three hosts read Not claimed (RepoOps does not read this tool today and does not pretend to) and Lower trust (read off a chat page, not a record the tool wrote). Gemini is the weakest: its request has no field names, so the adapter returns nothing rather than guess. Token counts are estimated from the shape of the text, with a stated band of about 30 percent, and cost reads zero, never a list price. Each host also reports its own health: Reading this host, Not reading this host, Not enough seen yet, or Turned off.
A chat tab has no repository behind it, so RepoOps does not invent one. Answer fingerprints that name no repository are kept unassigned, stored on this machine outside every repository and never matched against a repository's commits. Name a tracked repository in the extension's settings to link the next ones; a name that is not tracked is refused, not filed under another repository. Browser sessions themselves carry no repository.
The Go Tap is an optional, unsupported beta. It is a reverse proxy for the Anthropic and OpenAI APIs that listens on 127.0.0.1:8788 and refuses to start without --i-understand-beta. It forwards each request and copies metadata (status, sizes, model, request id, token counts when the response carries them) to the local RepoOps server. Authorization headers, API keys and request or response bodies never enter the copy. A copy that cannot be delivered is dropped and counted by reason while the request itself still goes through. A Tap process that is not running is a different failure: a client pointed at it gets a refused connection until you point the client back.
Connections shows where both stand. The Browser capture section lists whether the native host is registered with Chrome and Edge, the extension ids on record, each host's health and its catalog claim, when a session, a fingerprint and a health report last arrived, the capture mode of the newest session, and whether the newest fingerprints went to a repository or stayed unassigned. The Tap section says whether the binary is built, whether the beta is opted into, and whether a Tap answers its status read on 127.0.0.1 (port 8788, or the one Claude Code's settings point at). A running Tap adds its four drop counters and the receiver's last error; the last copied record comes from the tap-egress files. Anything RepoOps could not read says not reported.
The pain. Chat tabs and direct API calls happen outside the session logs, and a collector that guesses fills the gap with numbers nobody should trust: a traffic spike read as a transcript, an estimate read as a bill, a chat filed under whichever repository was first.
The point of view. An optional collector should say what it cannot prove. An unverified host reads not claimed, an estimate reads as an estimate, an unassigned chat stays unassigned, and a dropped copy is counted even when the request succeeded.
What gets easier. Deciding how far to trust a browser figure. The trust label, the per-host health and the estimate band travel with every number.
When it helps. When your team uses AI chat in the browser or calls provider APIs directly, and you want those sessions visible next to the coding sessions, with their limits stated.
Its limits. No browser host is verified. The extension is loaded unpacked. Connections shows status only: capture mode, hosts and the repository are set in the extension. The Tap keeps its drop counts in memory, so they show on Connections only while it runs. A refused fingerprint batch stores nothing, so Connections cannot count refusals. The Tap is beta, covers only Anthropic and OpenAI, and has one recorded live run.
Understand it in 30 seconds
Read the narration
- 0:00 A browser chat has no repository behind it.
- 0:03 A guess would be worse than none.
- 0:06 RepoOps keeps it unassigned,
- 0:08 and the extension talks only through native messaging.
- 0:13 All three browser adapters are unverified against live traffic.
- 0:17 Token counts are estimates, never a bill.
- 0:23 The optional Tap counts each dropped copy,
- 0:26 while the request still goes through.
Synthetic example. Read the guide
Where to find it
- Desktop: The Browser capture and Tap sections on Connections; the Browser sessions page and Today's Browser capture and Source support lines; the extension's own popup and settings; the Tap from the repoops tap command.
- Hosted: None. Browser capture and the Tap are desktop collectors; nothing on the hosted app controls them.
- API:
/api/connections/capture, /api/browser-sessions, /api/browser-capture/health, the Tap's own /_repoops/tap/status
When to use it
Chat usage with no repository named
Situation. A developer installs the extension and uses Claude in the browser all week without setting a repository.
What you do. Open the extension's settings and read the line under Repository for answer fingerprints. Open Browser sessions in the app.
What you see. The settings read N fingerprints kept unassigned: stored on this machine outside every repository, and never matched against a repository's commits. Browser sessions shows the sessions with Estimated tokens as about N and the note that the counts are not spend.
What it establishes. The week's chat is visible as lower-trust usage and is attributed to no repository. Naming one links only the fingerprints sent after that.
A Tap copy that did not arrive
Situation. The Tap runs in front of Claude Code while the RepoOps desktop app is closed for an hour.
What you do. Open Connections and read the Tap section, or the Tap's own status at http://127.0.0.1:8788/_repoops/tap/status.
What you see. The Tap section reads running, and Receiver unreachable shows the number of copies lost; Queue full, Receiver refused and Body too large stay at zero. Claude Code's requests all succeeded.
What it establishes. You know that hour's egress record is incomplete and by how much. Nothing retries those copies.
Before you start
- Supported versions
- Read against origin/main at ddbee985c. Extension version 0.2.0, native contract 1. The Tap is built from tap/ with npm run build:tap, or from a tap release.
- Where it runs
- Desktop only, Chrome or Edge for the extension. The desktop app registers the native host at every start; a source install runs repoops native-host register --extension-id <id> once.
- Permissions
- The extension asks for storage, alarms and native messaging, and host access to the four chat sites. Registration is per user and needs no elevation.
- Connections
- The desktop app installed and started once. For the Tap, a RepoOps server on this machine: a running lean service on its own port, found through its lean-service.json with the launch value sent as a header, or else the server on 127.0.0.1:4000. The Tap refuses a receiver that is not on loopback.
- Plan
- No plan gate on either collector.
Configure it
- Load the extension.
Download it from Browser sessions (Get the browser capture extension), open chrome://extensions, turn on Developer mode, choose Load unpacked and select the unpacked folder.
- Check the connection in the popup and on Connections.
Who this browser is talking to names the receiver and the connection mode, Native messaging. If the host is missing the popup says no RepoOps desktop app is registered with this browser and how to register it. Connections lists the registration for Chrome and Edge and the extension ids on record.
- Choose what is sent.
Capture mode is Metadata only by default. Include prompt text sends your prompts to the local receiver so RepoOps can link an answer to a commit; answer text is never sent.
- Name a repository, or leave it unassigned.
Repository for answer fingerprints takes a tracked repository id. Blank keeps fingerprints unassigned and outside every repository.
- Start the Tap only if you need API egress.
repoops tap --i-understand-beta starts it on 127.0.0.1:8788 and prints the line that points your client at it. tap configure --client claude-code --on writes that into Claude Code's settings and keeps a backup.
| Setting | Where | A sensible choice | Why it matters |
|---|---|---|---|
Capture | extension settings | on | Clear it to stop recording on every host without uninstalling. The popup then reads Capture paused. |
Which hosts to capture | extension settings | the hosts you use | Clearing a host stops capture there; it does not revoke Chrome's site permission. |
--provider | the Tap command line | anthropic (the default) or openai | The Tap forwards to one provider per process. |
--repo and --repo-root | the Tap command line | the tracked repository id, and that repository's folder | --repo tags each copy sent to the RepoOps server; --repo-root (the current folder by default) decides whose .claude/brain/tap-egress gets the daily file. |
REPOOPS_TAP_BETA | the environment | 1, or pass --i-understand-beta | Without one of the two the Tap refuses to start. |
--sensor-url | the Tap command line | leave it unset | Unset, repoops tap sends the copies where the CLI and hooks send their requests: a running lean service with its launch value, else port 4000. It hands the address and value to the Tap in its environment, never its command line, and never prints the value. A URL you type gets the value only when it is the lean service's own port. |
What you should see
A host the extension is reading
Configuration. Extension loaded, desktop app running, a few ChatGPT turns in a tab.
Expect. The popup reads Local capture active, or Capture active with Saved here. Delivered to your team. when team delivery is on. The host reads Reading this host once enough traffic was seen.
Verify. Browser sessions lists the session with Estimated tokens and a band, and the catalog still reads Not claimed and Lower trust for the host. Reading is not verification.
The desktop app is closed
Configuration. Extension loaded, desktop app not running.
Expect. The popup reads Receiver unreachable, Safely queued on this machine. What is waiting here counts the records waiting to send.
Verify. Start the desktop app; Check again moves the state back and Waiting to send falls.
The Tap stops while a client points at it
Configuration. tap configure --on wrote the base URL, then the Tap process exits.
Expect. Every request from that client fails with a refused connection. This is not a dropped copy; nothing was forwarded.
Verify. Run tap configure --client claude-code --off, or start the Tap again. The client's requests succeed.
Data and cost
- What is captured
- Extension: per-turn metadata (counts, timings, model), prompt text only in Include prompt text mode, and answer fingerprints, never answer text. Tap: request metadata and token counts; never keys, headers or bodies.
- Who can see it
- Records stay on this machine unless team delivery is on for the desktop app. There is no team-upload switch in the extension itself.
- How long it is kept
- Accepted browser records live on this machine: unassigned fingerprints in the data directory's browser-capture-unassigned folder, assigned ones in the named repository's brain. Tap egress records are one file per day under the repository's brain, tap-egress/YYYY-MM-DD.jsonl.
- What leaves the machine
- The extension talks only to the native host on this machine. The Tap forwards your requests to the provider you chose and sends its copies only to the loopback RepoOps server.
- What it costs
- No RepoOps spend. Browser records carry an estimated token count and a cost of zero; the cost normalizer refuses to price them. Tap token counts are what the provider's response reported.
When the result differs
| Symptom | Likely cause | Next action |
|---|---|---|
| The popup says no RepoOps desktop app is registered with this browser. | The native host is not registered for this browser, or not for this extension id. | Start the desktop app once, or run repoops native-host register --extension-id <id> from a source install, then reload the extension. |
| The popup reads Coverage degraded. | A host reads Not reading this host: its page format changed or the adapter returned nothing. | Expect gaps for that host. Gemini is the weakest adapter. |
| Fingerprints were refused. | The repository named in settings is not tracked on this machine. | Use the id the app lists for a tracked repository, or clear the field. |
| Connections reads the Tap as armed but not running. | The beta is opted into and nothing answered the status read on that port. | Start it with repoops tap --i-understand-beta, or point any client that uses it back with tap configure --off. |
| repoops tap refuses to start. | No beta opt-in, or a non-loopback --host or --sensor-url. | Pass --i-understand-beta or set REPOOPS_TAP_BETA=1, and keep both addresses on loopback. |
| A request through the Tap returns a bare 502. | The provider could not be reached; the Tap fails open to the client with the error. | Check the network to the provider, or bypass the Tap with tap configure --off. |
- Disable
- Clear Capture in the extension; stop the Tap and run tap configure --off.
- Roll back
- tap configure --off restores the client's settings from the backup --on wrote. The extension has nothing to roll back.
- Revoke access
- Remove the extension, or run repoops native-host unregister to remove the native host registration.
- Delete
- Delete what is waiting, in the popup or settings, removes records not yet sent. Nothing in the extension deletes records the desktop app already accepted.
Related tasks
Maintenance evidence
- Feature id
browser-capture(spine leaffirst-run)- Owner
- Browser capture (LDG-0968, LDG-0959) and the Go Tap. Connections status: LDG-0983. Guide: LDG-0981.
- Supported product version
- RepoOps main at ddbee985c (after v0.3.2)
- Last verified
- 2026-09-26, read against origin/main at ddbee985c; labels read from lib/capture-tiers.mjs, the extension's options.html, popup.js and capture-status.js, scripts/native-host.mjs, tap/main.go, tap/diag.go, tap/proxy.go and tap/README.md. The Connections sections were added and read on 2026-09-26 against the LDG-0983 branch: lib/connections-capture.mjs, lib/tap-status.mjs and public/first-run.html, with the Tap section checked against a locally built Tap on loopback.
- Example fixtures
- extensions/repoops-browser-capture/test/fixtures/{chatgpt,claude,gemini}/ (synthetic request and stream frames, not recorded traffic); inline cases in lib/capture-tiers.test.mjs, lib/native-host/serve.test.mjs, test/browser-capture-contract.test.mjs, tap/diag_test.go, tap/proxy_resilience_test.go and tap/configure_test.go; the Connections readers in lib/connections-capture.test.mjs, lib/tap-status.test.mjs and lib/routes/connections-capture.test.mjs.
- Source references
lib/capture-tiers.mjs,lib/connections-capture.mjs,lib/tap-status.mjs,extensions/repoops-browser-capture/src/options/options.html,extensions/repoops-browser-capture/src/popup/popup.js,extensions/repoops-browser-capture/src/lib/capture-status.js,extensions/repoops-browser-capture/src/lib/native-transport.js,scripts/native-host.mjs,lib/native-host/register.mjs,lib/browser-estimate.mjs,tap/main.go,tap/tee.go,tap/diag.go,tap/configure.go,tap/README.md- Documentation review
- Written by the authoring agent against the code; independent review not yet recorded.
- Video review
- Narrated story rendered and published 2026-09-26; six frames, captions and transcript reviewed by the authoring agent, not an independent reviewer. No host is shown as verified; the story is a labeled synthetic explanation.
Last updated