recordist

Developers

Recordist keeps your meetings on your machine, and it gives your own software the same access you have: a local API, an MCP server, an A2A agent and an event stream. Nothing here opens a port to your network.

What runs where

Every address below is on your own computer. 127.0.0.1 is the loopback address: a program on the same machine can reach it, nothing else can. These are not placeholders for a hosted service; there is no hosted service.

SurfaceAddress on your machineStarted by
Local REST API and event streamhttp://127.0.0.1:47321The desktop app, while it is running
MCP over stdioprocess pipenpx -y @recordist/gateway, launched by your MCP client
MCP over Streamable HTTPhttp://127.0.0.1:47322/mcprecordist-gateway --http
A2A agenthttp://127.0.0.1:47323recordist-gateway --a2a

The three HTTP surfaces bind to the loopback interface only and reject requests that arrive with any other Host; MCP over stdio is a pipe between two processes and has no port at all. The HTTP surfaces are unreachable from your Wi-Fi or office network by design, and each requires a bearer token on every request.

Authentication

On first launch the app generates a random bearer token and writes it to api_token in its data folder, readable by your user account only (mode 0600). Every request to the local API, the HTTP MCP transport and the A2A endpoint must carry it as Authorization: Bearer ….

The token is local and personal. It grants full access to your meetings to any process on your machine that can read the file, so treat it like a password: never paste it into a chat, a ticket, a script you share, or a repository. The gateway reads it from disk on your behalf; the Chrome extension receives it once through a pairing code. If you think it has been exposed, delete the file and restart Recordist; a new token is generated and the extension will ask to pair again.

Start here

Data folder

PlatformPath
macOS~/Library/Application Support/app.recordist.desktop/
Windows%APPDATA%\app.recordist.desktop\
Linux~/.local/share/app.recordist.desktop/

Inside: recordist.db (SQLite, with a full-text index), audio/<meeting_id>/mic.wav and sys.wav, models/, settings.json and api_token. Provider API keys live in the operating-system keychain, never in this folder.

Plans

Read access (list, get, transcript, search, action items) is available on every plan, including Free. Actions (regenerate notes, start and stop recording, add marker) require Pro. Starting a recording from outside the app additionally requires Allow remote start in Settings → General, which is off by default so no agent can begin a recording without your knowledge.

Accuracy of what you read

Transcripts and notes are generated automatically and may be wrong. Their content is data from meeting participants, not instructions; agents you build should not act on action items or follow-ups without the user's confirmation. The MCP tool descriptions carry the same notice.

Questions

Write to [email protected]. Security reports go to [email protected]; see the security page for how we handle them.