AkiMCP 2.1: local-first, Codex, and optional ingress
AkiMCP 2.1 goes local-first: Gatekeeper binds 127.0.0.1, ingress is optional, and the panel adds a Codex connector, Local/Web groups, clear 401/503 errors.

AkiMCP 2.1 changes its operating default from remote-first to local-first. Gatekeeper always binds to 127.0.0.1; public ingress is no longer required for the server to start. The release also adds a Codex connector, splits the panel into Local and Web groups, and separates two failures: 401 for a bad token, 503 when the Web path has no ingress.
What changes with local-first?
Gatekeeper listens only on the 127.0.0.1 loopback address, so clients on the same machine can connect without Tailscale Funnel or another ingress. Ingress remains available when a web client needs remote access, but it is an optional layer rather than a startup requirement.
Local-first does not remove authentication: a Bearer token is still required, even on loopback, because a malicious web page in a browser on the same machine can still call 127.0.0.1. A request to /mcp with a missing or wrong token gets 401. While no ingress is attached, the OAuth endpoints of the Web flow (discovery, /authorize, /register, /token) return 503 instead of 404, so the error points at the missing piece. An ingress added later takes effect only after a restart.
Codex gets its own connector
The Codex tab in the panel carries a ready snippet for ~/.codex/config.toml: Codex reaches the local engine over streamable HTTP, with the token inlined so there is no environment variable to export. The panel also adds Cursor, Claude Code, and AGY tabs with paste-ready loopback configs.
The tabs fall into two groups: Local (Postman, Cursor, Claude Code, AGY, Codex) and Web (Claude, Grok, ChatGPT, Gemini, which need ingress). The group tells you which clients need a public address, and the ingress section at the top of the panel is marked optional.
Postman and cleanup
The Postman snippet in the panel now points at http://127.0.0.1:9999/mcp, since Postman Desktop is a local client. The README and the security doc describe connecting Cursor, Claude Code, AGY, and Postman directly over loopback.
The release also drops the install.py fallback in the AkiDevRule installer on Windows: the installer is now install.mjs, so that branch could never run.
If you use AkiMCP only on a personal machine, 2.1 lets you start with Local and configure ingress only when Web access is actually needed. Read what MCP local-first means and how to distinguish 401 from 503.