* fix: don't combine wildcard CORS origins with allow_credentials Combining allow_origins=["*"] with allow_credentials=True makes Starlette's CORSMiddleware reflect the request's Origin header verbatim instead of returning a literal "*" (browsers reject a literal wildcard alongside credentials) - defeating the origin allowlist for any credentialed request. allow_credentials is now tied to whether CORS_ORIGINS was explicitly scoped: False for the default wildcard, True once an operator opts into specific origins. _cors_headers() (the manual CORS builder for error responses raised before CORSMiddleware runs) is updated to match, so it can't grant credentials the real middleware wouldn't. Not independently exploitable today (the frontend never sends credentialed requests, and auth is a Bearer header, not a cookie), but there's no reason to allow it for the default wildcard case. * fix: key allow_credentials on the parsed origins list, not the env var An operator who explicitly sets CORS_ORIGINS=* got allow_credentials=True with a wildcard origin list - the exact reflect-any-Origin behavior this change exists to prevent. Introduce CORS_ALLOW_CREDENTIALS keyed on the parsed list containing '*' and use it at both the middleware registration and the manual error-response headers; replace the tautological formula tests with ones exercising the real parser. --------- Co-authored-by: Luis Novo <lfnovo@gmail.com> |
||
|---|---|---|
| .github | ||
| api | ||
| commands | ||
| docs | ||
| examples | ||
| frontend | ||
| open_notebook | ||
| prompts | ||
| scripts | ||
| tests | ||
| .dockerignore | ||
| .env.example | ||
| .gitattributes | ||
| .gitignore | ||
| .python-version | ||
| .worktreeinclude | ||
| CHANGELOG.md | ||
| CLAUDE.md | ||
| CODE_OF_CONDUCT.md | ||
| CONFIGURATION.md | ||
| CONTRIBUTING.md | ||
| dev-init.sh | ||
| docker-compose.yml | ||
| Dockerfile | ||
| Dockerfile.single | ||
| history.txt | ||
| LICENSE | ||
| logo.png | ||
| MAINTAINER_GUIDE.md | ||
| Makefile | ||
| mypy.ini | ||
| pyproject.toml | ||
| README.dev.md | ||
| README.md | ||
| run_api.py | ||
| screenshot-01-initial-load.png | ||
| screenshot-02-notebooks-list.png | ||
| screenshot-03-notebook-detail.png | ||
| screenshot-04-sources-context-menu.png | ||
| screenshot-05-after-insights-only.png | ||
| screenshot-06-source-card-hover.png | ||
| screenshot-07-after-full-content.png | ||
| screenshot-08-after-exclude-sources.png | ||
| screenshot-09-notes-context-menu.png | ||
| screenshot-10-after-exclude-notes.png | ||
| screenshot-11-after-include-notes.png | ||
| screenshot-12-post-delete-notebooks.png | ||
| SECURITY.md | ||
| supervisord.conf | ||
| supervisord.single.conf | ||
| TRIAGE.md | ||
| uv.lock | ||
Open Notebook
An open source, privacy-focused alternative to Google's Notebook LM!
Join our Discord server for help, to share workflow ideas, and suggest features!
Checkout our website »
📚 Get Started
·
📖 User Guide
·
✨ Features
·
🚀 Deploy
A private, multi-model, 100% local, full-featured alternative to Notebook LM
In a world dominated by Artificial Intelligence, having the ability to think 🧠 and acquire new knowledge 💡, is a skill that should not be a privilege for a few, nor restricted to a single provider.
Open Notebook empowers you to:
- 🔒 Control your data - Keep your research private and secure
- 🤖 Choose your AI models - Support for 18+ providers including OpenAI, Anthropic, Ollama, LM Studio, and more
- 📚 Organize multi-modal content - PDFs, videos, audio, web pages, and more
- 🎙️ Generate professional podcasts - Advanced multi-speaker podcast generation
- 🔍 Search intelligently - Full-text and vector search across all your content
- 💬 Chat with context - AI conversations powered by your research
- 🌐 Multi-language UI - English, Portuguese, Chinese (Simplified & Traditional), Japanese, Russian, and Bengali support
Learn more about our project at https://www.open-notebook.ai
🆚 Open Notebook vs Google Notebook LM
| Feature | Open Notebook | Google Notebook LM | Advantage |
|---|---|---|---|
| Privacy & Control | Self-hosted, your data | Google cloud only | Complete data sovereignty |
| AI Provider Choice | 18+ providers (OpenAI, Anthropic, Ollama, LM Studio, etc.) | Google models only | Flexibility and cost optimization |
| Podcast Speakers | 1-4 speakers with custom profiles | 2 speakers only | Extreme flexibility |
| Content Transformations | Custom and built-in | Limited options | Unlimited processing power |
| API Access | Full REST API | No API | Complete automation |
| Deployment | Docker, cloud, or local | Google hosted only | Deploy anywhere |
| Citations | Basic references (will improve) | Comprehensive with sources | Research integrity |
| Customization | Open source, fully customizable | Closed system | Unlimited extensibility |
| Cost | Pay only for AI usage | Free tier + Monthly subscription | Transparent and controllable |
Why Choose Open Notebook?
- 🔒 Privacy First: Your sensitive research stays completely private
- 💰 Cost Control: Choose cheaper AI providers or run locally with Ollama
- 🎙️ Better Podcasts: Full script control and multi-speaker flexibility vs limited 2-speaker deep-dive format
- 🔧 Unlimited Customization: Modify, extend, and integrate as needed
- 🌐 No Vendor Lock-in: Switch providers, deploy anywhere, own your data
Built With
🚀 Quick Start (2 Minutes)
Prerequisites
- Docker Desktop installed
- That's it! (API keys configured later in the UI)
Step 1: Get docker-compose.yml
Option A: Download directly
curl -o docker-compose.yml https://raw.githubusercontent.com/lfnovo/open-notebook/main/docker-compose.yml
Option B: Create the file manually
Copy this into a new file called docker-compose.yml:
services:
surrealdb:
image: surrealdb/surrealdb:v2
command: start --log info --user root --pass root rocksdb:/mydata/mydatabase.db
user: root
ports:
- "8000:8000"
volumes:
- ./surreal_data:/mydata
restart: always
open_notebook:
image: lfnovo/open_notebook:v1-latest
ports:
- "8502:8502"
- "5055:5055"
environment:
- OPEN_NOTEBOOK_ENCRYPTION_KEY=change-me-to-a-secret-string
- SURREAL_URL=ws://surrealdb:8000/rpc
- SURREAL_USER=root
- SURREAL_PASSWORD=root
- SURREAL_NAMESPACE=open_notebook
- SURREAL_DATABASE=open_notebook
volumes:
- ./notebook_data:/app/data
depends_on:
- surrealdb
restart: always
Step 2: Set Your Encryption Key
Edit docker-compose.yml and change this line:
- OPEN_NOTEBOOK_ENCRYPTION_KEY=change-me-to-a-secret-string
to any secret value (e.g., my-super-secret-key-123)
Step 3: Start Services
docker compose up -d
Wait 15-20 seconds, then open: http://localhost:8502
Step 4: Configure AI Provider
- Go to Models and choose your provider (OpenAI, Anthropic, Google, etc.)
- Click + Add Configuration
- Paste your API key and other info as needed and click Add Configuration
- Click Test to test connection
- Click Sync Models and check models to include
- Under Default Model Assignments, click Auto-Assign Defaults or manually specify which models to use for what
Done! You're ready to create your first notebook.
Need an API key? Get one from: OpenAI · Anthropic · Google · Groq (free tier)
Want free local AI? See examples/docker-compose-ollama.yml for Ollama setup
📚 More Installation Options
- With Ollama (Free Local AI) - Run models locally without API costs
- From Source (Developers) - For development and contributions
- Complete Installation Guide - All deployment scenarios
📖 Need Help?
- 🤖 AI Installation Assistant: CustomGPT to help you install
- 🆘 Troubleshooting: 5-minute troubleshooting guide
- 💬 Community Support: Discord Server
- 🐛 Report Issues: GitHub Issues
Star History
Provider Support Matrix
Thanks to the Esperanto library, we support this providers out of the box!
| Provider | LLM Support | Embedding Support | Speech-to-Text | Text-to-Speech |
|---|---|---|---|---|
| OpenAI | ✅ | ✅ | ✅ | ✅ |
| Anthropic | ✅ | ❌ | ❌ | ❌ |
| Groq | ✅ | ❌ | ✅ | ❌ |
| Google (GenAI) | ✅ | ✅ | ✅ | ✅ |
| Vertex AI | ✅ | ✅ | ❌ | ✅ |
| Ollama | ✅ | ✅ | ❌ | ❌ |
| Perplexity | ✅ | ❌ | ❌ | ❌ |
| ElevenLabs | ❌ | ❌ | ✅ | ✅ |
| Deepgram | ❌ | ❌ | ❌ | ✅ |
| Azure OpenAI | ✅ | ✅ | ✅ | ✅ |
| Mistral | ✅ | ✅ | ✅ | ✅ |
| DeepSeek | ✅ | ❌ | ❌ | ❌ |
| Voyage | ❌ | ✅ | ❌ | ❌ |
| xAI | ✅ | ❌ | ❌ | ✅ |
| OpenRouter | ✅ | ✅ | ❌ | ❌ |
| DashScope (Qwen) | ✅ | ❌ | ❌ | ❌ |
| MiniMax | ✅ | ❌ | ❌ | ❌ |
| OpenAI Compatible* | ✅ | ✅ | ✅ | ✅ |
*Supports LM Studio and any OpenAI-compatible endpoint
✨ Key Features
Core Capabilities
- 🔒 Privacy-First: Your data stays under your control - no cloud dependencies
- 🎯 Multi-Notebook Organization: Manage multiple research projects seamlessly
- 📚 Universal Content Support: PDFs, videos, audio, web pages, Office docs, and more
- 🤖 Multi-Model AI Support: 18+ providers including OpenAI, Anthropic, Ollama, Google, LM Studio, and more
- 🎙️ Professional Podcast Generation: Advanced multi-speaker podcasts with Episode Profiles
- 🔍 Intelligent Search: Full-text and vector search across all your content
- 💬 Context-Aware Chat: AI conversations powered by your research materials
- 📝 AI-Assisted Notes: Generate insights or write notes manually
Advanced Features
- ⚡ Reasoning Model Support: Full support for thinking models like DeepSeek-R1 and Qwen3
- 🔧 Content Transformations: Powerful customizable actions to summarize and extract insights
- 🌐 Comprehensive REST API: Full programmatic access for custom integrations
- 🔐 Optional Password Protection: Secure public deployments with authentication
- 📊 Fine-Grained Context Control: Choose exactly what to share with AI models
- 📎 Citations: Get answers with proper source citations
Podcast Feature
📚 Documentation
Getting Started
- 📖 Introduction - Learn what Open Notebook offers
- ⚡ Quick Start - Get up and running in 5 minutes
- 🔧 Installation - Comprehensive setup guide
- 🎯 Your First Notebook - Step-by-step tutorial
User Guide
- 📱 Interface Overview - Understanding the layout
- 📚 Notebooks - Organizing your research
- 📄 Sources - Managing content types
- 📝 Notes - Creating and managing notes
- 💬 Chat - AI conversations
- 🔍 Search - Finding information
Advanced Topics
- 🎙️ Podcast Generation - Create professional podcasts
- 🔧 Content Transformations - Customize content processing
- 🤖 AI Models - AI model configuration
- 🔌 MCP Integration - Connect with Claude Desktop, VS Code and other MCP clients
- 🔧 REST API Reference - Complete API documentation
- 🔐 Security - Password protection and privacy
- 🚀 Deployment - Complete deployment guides for all scenarios
🗺️ Roadmap
Upcoming Features
- Live Front-End Updates: Real-time UI updates for smoother experience
- Async Processing: Faster UI through asynchronous content processing
- Cross-Notebook Sources: Reuse research materials across projects
- Bookmark Integration: Connect with your favorite bookmarking apps
Recently Completed ✅
- Next.js Frontend: Modern React-based frontend with improved performance
- Comprehensive REST API: Full programmatic access to all functionality
- Multi-Model Support: 18+ AI providers including OpenAI, Anthropic, Ollama, LM Studio
- Advanced Podcast Generator: Professional multi-speaker podcasts with Episode Profiles
- Content Transformations: Powerful customizable actions for content processing
- Enhanced Citations: Improved layout and finer control for source citations
- Multiple Chat Sessions: Manage different conversations within notebooks
See the open issues for a full list of proposed features and known issues.
📖 Need Help?
- 🤖 AI Installation Assistant: We have a CustomGPT built to help you install Open Notebook - it will guide you through each step!
- New to Open Notebook? Start with our Getting Started Guide
- Need installation help? Check our Installation Guide
- Want to see it in action? Try our Quick Start Tutorial
🤝 Community & Contributing
Join the Community
- 💬 Discord Server - Get help, share ideas, and connect with other users
- 🐛 GitHub Issues - Report bugs and request features
- ⭐ Star this repo - Show your support and help others discover Open Notebook
Contributing
We welcome contributions! We're especially looking for help with:
- Frontend Development: Help improve our modern Next.js/React UI
- Testing & Bug Fixes: Make Open Notebook more robust
- Feature Development: Build the coolest research tool together
- Documentation: Improve guides and tutorials
Current Tech Stack: Python, FastAPI, Next.js, React, SurrealDB Future Roadmap: Real-time updates, enhanced async processing
See our Contributing Guide for detailed information on how to get started.
📄 License
Open Notebook is MIT licensed. See the LICENSE file for details.
Community Support:
- 💬 Discord Server - Get help, share ideas, and connect with users
- 🐛 GitHub Issues - Report bugs and request features
- 🌐 Website - Learn more about the project

