Network Security And CORS
Open Ollama to your network safely with host binding, CORS origins, and an authenticating proxy.
TL;DR
- Set
OLLAMA_HOST=0.0.0.0to expose the server on your LAN. - Limit browser callers with the
OLLAMA_ORIGINSCORS allowlist. - Never expose port
11434publicly without an auth proxy.
Bind The Host
Local OnlyThe default binds to localhost for safety.
# Default: OLLAMA_HOST=127.0.0.1Expose On LANBind all interfaces to reach other machines.
export OLLAMA_HOST=0.0.0.0:11434Pick A PortChange the port if 11434 is taken.
export OLLAMA_HOST=0.0.0.0:8080CORS With Origins
OLLAMA_ORIGINSAllowlist web origins that may call the API.
export OLLAMA_ORIGINS=https://app.me.comMultiple OriginsSeparate several origins with commas.
export OLLAMA_ORIGINS=https://a.com,https://b.comAvoid WildcardDo not use a star in production.
# Avoid OLLAMA_ORIGINS=*Protect The Endpoint
No Built-in AuthThe API trusts anyone who can reach it.
# Ollama has no API key or loginAuth ProxyPut an authenticating reverse proxy in front.
# Nginx/Caddy with basic or token authFirewall ItBlock 11434 from the public internet.
# Allow only LAN or VPN to 11434Safe Exposure
Use A VPNReach the server over a private network.
# Expose via VPN, not the open webTLS TerminationTerminate HTTPS at the proxy.
# Proxy adds TLS in front of 11434Rate LimitThrottle requests at the proxy layer.
# Limit requests per IP at the proxyTips
- Keep
OLLAMA_HOSTbound to127.0.0.1unless you truly need LAN access, since the API has no authentication of its own. - Set
OLLAMA_ORIGINSto your specific trusted domains, so only approved web pages can call the server from a browser.
Warnings
- Ollama has no built-in auth; exposing port
11434to the internet lets anyone run your models and read your prompts. - Setting
OLLAMA_ORIGINS=*lets any website call your local server from a browser; scope it to trusted origins instead.
In Practice
Bind the server to the network, restrict CORS origins, and front it with an authenticating proxy.
OLLAMA_HOST=0.0.0.0makes the server reachable on the LAN.OLLAMA_ORIGINSlimits which browser origins may call it.- A systemd reload and restart apply both variables.
- An auth proxy and firewall keep port 11434 off the open web.
# 1. Bind to the LAN (systemd service)
# Environment="OLLAMA_HOST=0.0.0.0:11434"
# 2. Allowlist trusted browser origins
# Environment="OLLAMA_ORIGINS=https://app.me.com"
sudo systemctl daemon-reload
sudo systemctl restart ollama
# 3. Never expose 11434 directly; front it
# with an auth proxy and firewall rules
curl http://localhost:11434/api/tagsFAQ
Set OLLAMA_HOST=0.0.0.0:11434 so the server binds every interface, then restart it. Only do this on a trusted LAN, because the API itself has no authentication.
No. The API trusts anyone who can reach the port. For any exposure beyond localhost, put an authenticating reverse proxy in front and restrict network access with a firewall or VPN.
Set OLLAMA_ORIGINS to the exact web origins allowed to call the API, comma-separated. Avoid the wildcard * in production, which permits any site to reach your server.
Not directly. Because there is no built-in auth, never expose port 11434 to the open web. Use a VPN, or an authenticating proxy with TLS and rate limiting, in front of it.