ChatGPTNextWeb/NextChat
44.7
Weak · 27 September 2026
38.7k
lines of production code
TypeScript
primary language
4
measurements over time
What this system is
This system is a multi-modal AI chat client that aggregates interactions with a wide variety of large language model providers, including text, voice, and image generation capabilities. It features a modular architecture supporting real-time streaming, local artifact storage, and cloud synchronization via WebDAV or Upstash Redis. The application is designed for broad accessibility, offering PWA and Tauri desktop deployments alongside extensive internationalization and plugin extensibility.
How it got here
2023 — Initial scaffolding and multi-provider integration
21 changes.
The project was initialized and structured into the NextChat product, establishing core infrastructure such as modular state management, centralized configuration, and a plugin system. Significant effort focused on expanding AI model support by integrating numerous LLM providers and adding features like PWA capabilities, desktop app support via Tauri, and cloud synchronization.
2024 — multimodal AI and MCP integration
9 changes.
This period focused on expanding the application's capabilities with real-time voice chat, image generation, and Model Context Protocol (MCP) server integration. It also introduced secure proxy endpoints for external services like Upstash, WebDAV, and Tencent, alongside comprehensive testing for core utilities and configuration logic.
Features
Add Tencent Hunyuan API proxy route
A new API route at app/api/tencent has been introduced to proxy requests to the Tencent Hunyuan model provider. This edge-runtime endpoint handles authentication, forwards requests to the configured Tencent base URL (with automatic https prefixing and trailing slash removal), and manages response headers to prevent browser credential prompts and disable nginx buffering.
app/api/tencent · high confidence
Add Upstash API proxy endpoint
A new API route at /api/upstash/\[action\]/\[...key\] has been added to proxy requests to Upstash services. This endpoint restricts access to \*.upstash.io domains and only permits 'get' and 'set' actions, returning a 403 error for unauthorized requests. It forwards the original request method and authorization headers to the target Upstash endpoint, running in the Edge runtime.
app/api/upstash · high confidence
Add cloud sync support for WebDAV and Upstash Redis
Users can now sync their data to cloud storage providers via two new backends: WebDAV and Upstash Redis. The implementation in app/utils/cloud introduces a unified sync client interface that routes requests to the appropriate provider-specific client (createWebDavClient or createUpstashClient). The WebDAV client handles backup files via standard HTTP methods (GET/PUT) and checks directory existence, while the Upstash client manages data chunking to respect API size limits and uses Bearer token authentication. This change enables seamless cloud synchronization for existing sync workflows.
app/utils/cloud · high confidence
Added Voice Print visualization component
A new VoicePrint React component has been introduced to render an animated, symmetric waveform visualization on a canvas element. It accepts audio frequency data and an active state, applying smoothing and gradient effects to display the audio input visually.
app/components/voice-print · high confidence
Adds PWA support, audio recording, and plugin system
The application now supports installation as a Progressive Web App (PWA) via a new web manifest and service worker, which handles background caching and offline file uploads. A new audio processing capability allows users to record audio directly in the browser using an AudioWorklet processor. Additionally, the app now includes a built-in plugin system defined by a JSON configuration file, pre-loaded with integrations for DALL-E 3, Arxiv Search, and DuckDuckGo Lite Search. Finally, the default Next.js and Vercel branding assets have been removed from the public directory.
public · high confidence
Expanded API provider support and unified routing
The API layer now supports a significantly wider range of model providers, including new integrations for 302.AI, Alibaba (Qwen), GLM, iFLYTEK Spark, SiliconFlow, and XAI, alongside existing support for OpenAI, Azure, Google, Anthropic, Baidu, ByteDance, Moonshot, Stability, and DeepSeek. A new dynamic routing handler in \app/api/\[provider\]/\[...path\]/route.ts\ centralizes request dispatching to these specific providers or a generic proxy fallback. The authentication logic in \auth.ts\ has been refactored to manage system API keys for each provider individually, and all provider handlers now enforce server-side model availability checks via \customModels\ configuration to restrict access to specific models.
app/api · high confidence
Expose server configuration settings via API
A new API endpoint at /api/config now exposes server-side configuration flags to the client, including settings to hide the API key input, disable GPT-4, hide balance queries, disable fast linking, and define custom or default models. This allows the frontend to dynamically adjust its UI and feature availability based on the server's environment variables without hardcoding these restrictions.
app/api/config · high confidence
Initial Tauri desktop app configuration
The src-tauri directory now contains the foundational configuration for the NextChat desktop application. This includes the Tauri configuration file (tauri.conf.json) which sets the app name to 'NextChat', version to '2.16.1', and enables features like clipboard access, window management, and HTTP requests with support for both http and https schemes. The configuration also sets up the build process to use 'yarn export' and configures the app bundle with icons and an updater endpoint. Additionally, a build script (build.rs) and gitignore file for the target directory have been added.
src-tauri · high confidence
Initial project scaffolding and configuration
The repository is initialized with essential configuration files including a Dockerfile, docker-compose.yml, and .env.template to support local and containerized deployment. The Next.js application is configured via next.config.mjs with proxy routes for OpenAI, Azure, Google, and Anthropic APIs, alongside a .babelrc file setting browser targets. Development tooling is established with Jest (jest.config.ts, jest.setup.ts), ESLint (.eslintrc.json), Prettier (.prettierrc.js), and lint-staged (.lintstagedrc.json). Documentation is added in English, Chinese, Japanese, and Korean, along with a LICENSE (MIT) and CODE\_OF\_CONDUCT.md.
(repo-wide) · high confidence
Initial support for Arabic, Bengali, Chinese, Czech, Danish, German, English, Spanish, French, and Indonesian locales
The application now includes initial translation files for Arabic (ar), Bengali (bn), Chinese (cn), Czech (cs), Danish (da), German (de), English (en), Spanish (es), French (fr), and Indonesian (id). These files provide the foundational UI strings for settings, chat actions, export options, and error messages, enabling users to interact with the interface in their preferred language immediately upon selection.
app/locales · high confidence
Introduce Model Context Protocol (MCP) server integration
This change adds the core backend infrastructure for integrating Model Context Protocol (MCP) servers into the application. It introduces a new \app/mcp\ module containing server-side actions (\actions.ts\) to manage MCP client lifecycles (initialization, status tracking, and tool retrieval), a client wrapper (\client.ts\) using the \@modelcontextprotocol/sdk\ to communicate via stdio, and configuration management (\utils.ts\, \types.ts\) for loading server definitions from \mcp\_config.json\. This enables the system to discover, connect to, and execute tools provided by external MCP servers.
app/mcp · high confidence
Introduce built-in mask system with multi-language support
The application now includes a set of built-in masks (pre-configured AI personas) available in Chinese (Simplified and Traditional) and English. This change introduces a new build process that compiles these masks into a static \public/masks.json\ file, which the client fetches at runtime to populate the mask store. Users can now select from predefined roles such as 'AI Text-to-Image', 'Copywriter', 'GitHub Copilot', and 'Prompt Improvement' without needing to manually configure system prompts.
app/masks · high confidence
Introduce new UI components and refactor core chat interface
This update adds several new UI components to the application, including a dedicated Artifacts viewer for rendering HTML previews, a new Auth page for access control, and a reusable IconButton component. It also refactors the core chat interface by introducing a new ChatList component with drag-and-drop reordering for sessions, updates the chat input styling, and adds an ErrorBoundary for better error handling. These changes improve the user experience by providing more robust session management, better visual feedback for artifacts, and a cleaner, more modular component structure.
app/components · high confidence
Introduce real-time voice chat interface and configuration
This change adds a new real-time chat component (\app/components/realtime-chat\) that enables voice-based interactions with AI models. The UI features a central microphone button with pulse animations, allowing users to toggle recording and connect to a real-time session. It supports both text and audio modalities, handling streaming audio playback and transcription. A dedicated configuration panel (\realtime-config.tsx\) allows users to enable the feature, select providers (OpenAI or Azure), configure API keys, endpoints, deployment names, voice selection (alloy, shimmer, echo), and adjust temperature settings.
app/components/realtime-chat · high confidence
Introduce secure WebDAV proxy endpoint with strict access controls
A new WebDAV proxy route has been added at app/api/webdav/\[...path\] to handle backup synchronization. This endpoint enforces strict security measures by validating that the target endpoint is in an allowlist and preventing SSRF attacks. It restricts allowed HTTP methods to MKCOL, GET, and PUT, and limits file access to specific backup paths (e.g., backup.json), ensuring that users can only interact with authorized resources through the proxy.
app/api/webdav · high confidence
Introduction of a new client-side API layer with multi-provider support
The application now includes a new client-side API architecture (\app/client/api.ts\) that centralizes communication with various Large Language Model providers. This change introduces support for multiple AI services including OpenAI, Azure, Anthropic, Google Gemini, Baidu Ernie, ByteDance Doubao, Alibaba Qwen, Tencent Hunyuan, Moonshot, iFLYTEK Spark, DeepSeek, XAI, ChatGLM, SiliconFlow, and 302.AI. The new layer also adds capabilities for Text-to-Speech (TTS) and Speech-to-Text (STT) interactions, as well as vision model support. Additionally, a new controller (\app/client/controller.ts\) has been added to manage streaming chat sessions, allowing users to stop individual or all active message streams.
app/client · high confidence
New LLM platform integrations for 302.AI, Alibaba, Baidu, ByteDance, ChatGLM, and more
This update adds dedicated API client implementations for several new and existing model providers, allowing users to connect to and chat with models hosted on these services. The new platform files include ai302.ts (302.AI), alibaba.ts (Alibaba Qwen/DashScope), baidu.ts (Baidu Ernie), bytedance.ts (ByteDance Doubao), glm.ts (ChatGLM with image/video generation support), iflytek.ts (iFLYTEK Spark), and moonshot.ts (Moonshot). These implementations handle provider-specific request formatting, streaming, and endpoint configuration, expanding the range of available AI models within the application.
app/client/platforms · high confidence
New Stable Diffusion image generation interface
A new UI for generating images via Stability AI has been added, featuring a sidebar for configuring parameters (such as model version, aspect ratio, and style) and a main view for displaying generated images and their status. The interface supports multiple models including Stable Image Ultra, Stable Image Core, and Stable Diffusion 3, and includes mobile-responsive layouts and accessibility improvements.
app/components/sd · high confidence
New audio handling library for recording and playback
Added app/lib/audio.ts, introducing an AudioHandler class that manages microphone recording, audio analysis, and streaming playback. This library enables capturing audio chunks via AudioWorklet, processing them into WAV files for both recorded and played-back audio, and providing frequency data for visualizations.
app/lib · high confidence
New setup and maintenance scripts for deployment and configuration
Added a one-key setup script (setup.sh) that automates environment preparation for Linux (Ubuntu, Debian, CentOS, Arch) and macOS, including dependency installation and environment variable configuration. Introduced a script to delete Vercel deployment previews based on metadata tags, and a proxy initialization script (init-proxy.sh) to configure proxychains for network access. Also added a script (fetch-prompts.mjs) to download and cache prompt lists from external sources with timeout handling and content filtering.
scripts · high confidence
New stream\_fetch command for chunked HTTP responses
The desktop application now exposes a new \stream\_fetch\ command that allows the frontend to initiate HTTP requests and receive the response body as a stream of chunks via window events. This enables handling large responses or server-sent data without blocking the main thread, with a 3-second connection timeout configured for reliability.
src-tauri/src · high confidence
New utility modules for audio, storage, and model management
The app now includes a suite of new utility modules in app/utils. Audio handling is supported via a new TTS player (app/utils/audio.ts) and Microsoft Edge TTS integration (app/utils/ms\_edge\_tts.ts). Data persistence has been enhanced with an IndexedDB storage adapter (app/utils/indexedDB-storage.ts) and a new store creation helper (app/utils/store.ts) that uses it. Model management features a new sorting mechanism (app/utils/model.ts) that prioritizes custom models and supports provider-specific naming. Additionally, new utilities cover Cloudflare AI Gateway URL rewriting (app/utils/cloudflare.ts), Tencent Hunyuan authentication (app/utils/tencent.ts), and Google Analytics event tracking (app/utils/auth-settings-events.ts).
app/utils · high confidence
Architecture
New modular state management architecture for store data
The application's state management has been reorganized into a modular structure within the \app/store\ directory, replacing the previous monolithic approach. This change introduces dedicated stores for specific domains: \access.ts\ for API configuration and provider settings, \chat.ts\ for session and message handling, \config.ts\ for global application settings, \mask.ts\ for prompt templates, \plugin.ts\ for plugin management, \prompt.ts\ for prompt libraries, \sd.ts\ for stable diffusion tasks, \sync.ts\ for cloud synchronization, and \update.ts\ for version tracking. This separation improves code maintainability and allows for more granular control over different aspects of the application's state.
app/store · high confidence
Behavioural changes
8 commits (2 fixes) modifying src-tauri/icons
A change to existing behaviour in src-tauri/icons — 8 commits (2 fixs), 16 files.
src-tauri/icons · medium confidence · unverified
Added pre-commit linting via lint-staged
The repository now automatically runs lint-staged on every commit. This ensures that staged files are linted before being committed, helping to maintain code quality and consistency without requiring manual intervention.
.husky · high confidence
App restructured from Next.js template to NextChat product with artifacts storage
The application has been refactored from the default Next.js starter template into the functional NextChat interface. The root layout now injects client configuration, registers PWA service workers, and conditionally includes Vercel Speed Insights and Google Analytics (GTM/GA) based on server settings. The home page now renders the main \Home\ component instead of the template demo, and the app supports PWA features via a manifest and service worker. A new \app/api/artifacts/route.ts\ endpoint has been added to store and retrieve content in Cloudflare KV using hashed keys, enabling the artifacts feature. Additionally, a \useCommand\ hook and chat command system (supporting prefixes like \:\ and \:\) have been introduced to handle URL-based and input-based commands, while utility functions for copying and downloading have been updated to support Tauri environments.
app · high confidence
Centralized configuration management for build, client, and server environments
The application now uses a unified configuration system located in app/config to manage settings across different runtime environments. The new build.ts module exposes build-time metadata (version, commit hash, mode) and the default input template via the DEFAULT\_INPUT\_TEMPLATE environment variable. The client.ts module bridges build-time constants to the browser by reading meta tags, while the server.ts module consolidates all server-side environment variables (including API keys for providers like Azure, Google, Anthropic, and DeepSeek) and logic for handling access codes and model filtering (such as disabling GPT-4). This change centralizes how configuration is defined, validated, and accessed, ensuring consistent behavior between the build process, the client-side UI, and the server-side API.
app/config · high confidence
Introduce new application styling system with animations and theme support
This change introduces a new set of global styles for the application, including \animation.scss\ for slide-in effects, \globals.scss\ for light/dark theme variables and responsive layout adjustments, \highlight.scss\ for code syntax highlighting using the Tokyo Night theme, \markdown.scss\ for rendering Markdown content with GitHub-style colors, and \window.scss\ for window header styling. These styles provide the visual foundation for the app's UI, including support for mobile responsiveness and accessibility features like focus-visible outlines.
app/styles · high confidence
Test coverage
Added unit tests for core utility functions and model configuration helpers
This update introduces a comprehensive suite of unit tests covering the application's utility layer and model configuration logic. The new tests verify the behavior of the HTTP adapter, string formatting utilities (including token estimation and chunking), and object manipulation helpers like deep cloning and merging. It also adds validation for model availability checks, provider detection, and the parsing of MCP JSON payloads. Furthermore, the test suite covers configuration validators for modal settings and TTS engines, ensuring that parameters like temperature, speed, and max tokens are correctly clamped and validated.
test · high confidence
Dependencies
Migrate to Yarn and introduce Tauri desktop app support
The project has switched its package manager from npm to Yarn (v1.22.19), replacing the \package-lock.json\ with a \yarn.lock\ file and updating the root \package.json\ to reflect this change. Additionally, a new Tauri-based desktop application has been added, evidenced by the introduction of \src-tauri/Cargo.toml\ and \src-tauri/Cargo.lock\ which define the Rust backend dependencies (including Tauri 1.5.4 and its plugins). The \package.json\ scripts have been updated to include \app:dev\ and \app:build\ commands to facilitate development and building of this new desktop client.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 36 → 45 (+8.4)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 68 → 67 (-1.9)
- Architecture 54 (new)
- Maturity 55 → 51 (-4.1)
- Readiness 20 → 41 (+20.8)
- Security 45 → 68 (+22.8)
- Accessibility 40 (new)
Resolved (110)
- Boundary-crossing change coupling: chat.tsx ↔ hooks.ts (app/components/chat.tsx)
- Boundary-crossing change coupling: client.ts ↔ access.ts (app/config/client.ts)
- Boundary-crossing change coupling: client.ts ↔ cn.ts (app/config/client.ts)
- Boundary-crossing change coupling: client.ts ↔ en.ts (app/config/client.ts)
- Boundary-crossing change coupling: home.tsx ↔ client.ts (app/components/home.tsx)
- Boundary-crossing change coupling: mcp-market.tsx ↔ actions.ts (app/components/mcp-market.tsx)
- Boundary-crossing change coupling: settings.tsx ↔ client.ts (app/components/settings.tsx)
- Change coupling: es.ts ↔ it.ts (app/locales/es.ts)
- Change coupling: es.ts ↔ tr.ts (app/locales/es.ts)
- Change coupling: it.ts ↔ tr.ts (app/locales/it.ts)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical IaC: DS-0031 (Dockerfile)
- Critical IaC: DS-0031 (Dockerfile)
- Dimension evaluation failed
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- …and 90 more
New (187)
- Base-context workflow trigger runs with an unscoped token
- Change coupling: auth.ts ↔ access.ts (app/api/auth.ts)
- Change coupling: route.ts ↔ access.ts (app/api/config/route.ts)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical CVE: [GHSA redacted] (yarn.lock)
- Critical vulnerability: [GHSA redacted] (yarn.lock)
- Dependency source pinned to a moving git ref
- Documentation: no project overview (README.md)
- FixmeComment (test/model-available.test.ts)
- Further orphaned files (smaller)
- Further sole-owners (lower concentration)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- …and 167 more
Changes since last survey
- 2 commits — 2 feature/other, 0 fixes
By area
- (repo) — 1 commit
- (root) — 1 commit
Notable commits
- change: Merge pull request #6869 from ChatGPTNextWeb/Leizhenpeng-patch-8
- change: Update README.md
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
ChatGPTNextWeb/NextChat was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit defdcdb55d850cd12c4c657eb83729fd66e215c0 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-d00c643c3f66.