Racinage
Francais

Operations

AI assistant and MCP

Responses keep running during page navigation. Refreshing reconnects to saved hosted response events. Local chat keeps its connection in a shared browser worker when supported and restores the current tool round. If the browser has stopped that worker, Racinage continues from the last encrypted text checkpoint with a new local generation; it does not replay completed actions. Local recovery is limited to the originating browser tab for 20 minutes. Stop explicitly cancels the response.

Last updated 2026-09-05T10:26:48+00:00

The Racinage assistant answers questions about your account access and supported features, understands the selected family, page, record, and current permissions, and can propose typed record changes for review.

Chats receive a short title from their first meaningful message. Rename remains available at any time; automatic naming preserves your custom title. For tree edits, the assistant asks about ambiguous relationships. One known parent is supported without inventing a spouse. It asks before choosing among partners, checks duplicates and distinguishes unlinking from deletion. Other record guidance distinguishes album membership from file deletion, planned costs from recorded contributions, and financial records from actual payments.

Open the assistant

Use the sparkle button on a dashboard page. On desktop, the assistant is a permanent inline rail that narrows the page content instead of covering it. Trees places the button above the tree controls; other pages use a compact button on the assistant’s selected edge. Each page remembers its own open or closed state for your user account, including after reloads and on another device. Route navigation restores that state without an open or close animation. Narrow screens use a full-screen layer so the workspace remains usable.

You can also open Manage > Messages > New and choose Racinage AI to start a fresh private assistant conversation about your account or how Racinage works.

Choose the left or right edge from Manage > Settings > Personal preferences. Right is the default. Resize the open desktop rail by dragging its inner vertical edge or focus that edge and use the arrow keys. Side and width are saved to your user account.

The composer starts as a compact single field with a 100-pixel minimum height. Its text area fills the available field and grows upward as you type, up to 380 pixels, then scrolls for longer prompts. The Send action appears only when the field contains text.

Type @ followed by two or more characters to attach an accessible person, tree, event, project, media record, document, history record, plugin, or system feature. Racinage checks the current family and exact collaboration capabilities again when the prompt is submitted and before a read is performed.

The assistant is limited to Racinage account and feature support. It does not answer unrelated questions and has no internet search, browser, shell, raw SQL, arbitrary web request, super-admin, payment, or plan-entitlement tools.

Attach files to a chat message

On a tree page, the assistant also receives a limited text snapshot of the displayed people: names, relevant profile details, and relationships. This works for any person and for partial views. Large trees use follow-up lookups for details that do not fit in the initial snapshot.

Square image thumbnails remain visible after sending and when you reopen the conversation. Hover a thumbnail to see its filename. These small previews stay private to the chat; older attachments load a preview after access is checked.

You can also paste a copied image or file into the message field with Ctrl+V (Cmd+V on Mac) when your browser provides clipboard files. Images show a small square thumbnail before sending; the filename appears on hover. Pasting ordinary text still inserts text; pasted files use the same supported formats and size limits as the file picker.

Both the user and super-admin assistants include an Attach files button beside a list of formats supported by the selected model. Choose files, add your question, and send. You can remove a queued file before sending. The same controls work with keyboard navigation.

  • Text: UTF-8 TXT, Markdown (.md or .markdown), CSV, and JSON are read as text, not executed or imported into your records. The combined text limit is 24,000 characters.
  • Images: JPEG, PNG, and WebP are available only when model-specific metadata or the reviewed model catalog confirms vision support. Valid images are decoded, resized to at most 1,600 pixels on the longest side, stripped of metadata, and re-encoded as WebP.
  • PDF: available only with confirmed native PDF support and a compatible hosted adapter. Browser-local models do not currently have a PDF decoder. Export a local PDF to text or images first. Unknown capabilities never enable image or PDF uploads.

Each message accepts up to three files, 2 MB per file and 4 MB combined. SVG, archives, executables, Office documents, audio, and video are not supported. Changing the provider or model rechecks the queued files; unsupported files must be removed before sending.

Files and filenames are encrypted with the chat. They are sent only to the selected provider, with no funding-provider or OCR fallback. Provider privacy and retention policies still apply. Files are untrusted source data and cannot grant permissions or bypass confirmation. A configured private malware scanner must accept them before storage. Deleting a message excludes its files from future model context; deleting the conversation removes its stored files too.

For predictable loading and request size, chat history loads filenames rather than file contents. Model context includes files from up to three recent attached messages within an 8 MB encrypted-payload budget; older files may need to be attached again. Normal AI credit, access, and model context limits still apply. This hosted chat feature does not change the Racinage Free executable.

The jump-to-latest button appears only when the message list overflows and you have scrolled up. It remains above message content and disappears again near the latest response.

Credit reservations estimate text and image content separately from file transport. PDF reservations remain conservative when page information is unavailable, so a large PDF may require more available credits than its eventual usage. Provider-reported usage remains authoritative when returned.

Adapter references: OpenAI file inputs, Claude PDF support, OpenRouter native PDF processing, LM Studio model metadata, and Ollama vision.

Choose a provider explicitly

Open Manage > AI Features. Each family user chooses a default provider and model. Racinage never moves a failed prompt to another provider silently.

  • Racinage AI: uses the tested provider and model selected by a super admin. Hosted Lite uses a personal allowance; paid-family allowances require an assigned funded seat.
  • Hosted AI with BYOK: uses your encrypted provider key without consuming funded credits.
  • Ollama: discovers local models from the native Ollama model endpoint.
  • OpenAI Local: uses ChatGPT subscription access through your local Codex harness. Set up OpenAI Local.
  • LM Studio: discovers and tests models through its OpenAI-compatible local server.
  • Advanced local compatible: connects to a loopback-only OpenAI-compatible server.

First-class hosted setup is available for OpenAI, OpenRouter, DeepSeek, Google Gemini, Anthropic Claude, xAI Grok, Mistral AI, GroqCloud, Together AI, Perplexity, and Cerebras Inference. Racinage uses each provider’s vetted OpenAI-compatible or native adapter, exact API host, credential header, model discovery endpoint, and privacy information. Super admins may add other reviewed public HTTPS providers.

Local endpoints must use localhost, 127.0.0.1, or ::1. Local prompts are not sent to a cloud provider as a fallback. A local model must return valid native tool calls to propose CRUD actions; every call is validated by the server. Writing-only models may still summarize and rewrite.

OpenAI Local with your ChatGPT subscription

OpenAI Local uses the official Codex harness on your computer and your account's Codex allowance. Model requests are processed online by OpenAI. Your account must have Codex access and available usage. The existing OpenAI API (BYOK) provider continues to use separate API billing.

  1. Install Node.js 22.13 or newer and the official Codex CLI or Codex desktop app.
  2. Download the OpenAI Local bridge, then run node bridge.mjs in its folder. Keep that process running while chatting.
  3. Open Manage > AI Features > OpenAI Local, paste the pairing code shown in the local terminal, then choose Sign in with ChatGPT. Complete OpenAI's sign-in window.
  4. Use Discover and test to verify the connection, select an available model, and choose OpenAI Local in the chat provider menu.

The default endpoint is http://127.0.0.1:43189. Codex manages sign-in in a separate private profile on your computer; credentials are never sent to Racinage. API-key sessions are rejected. Record requests still pass Racinage's permissions and confirmation checks. This integration exposes no computer or file-editing tools. See Codex authentication.

Refresh reconnects to the same running bridge response. If you stop the bridge or restart your computer, that in-memory response is lost. Sign-in persists. Reopen the bridge before continuing. Your browser may ask for local-network access when the website connects to your computer.

Super-admin provider and access controls

Local, BYOK, and hosted assistants can use the same authorized record actions. The open page and selected tree or permanent partial are the default context; explicitly name another page or record to work with it without navigating there. Person changes update the matching visible tree asynchronously. Structural changes and destructive actions retain their review and confirmation requirements.

AI record editing in the AI Providers settings has separate Local, BYOK, and Hosted switches, enabled by default. Turning one off keeps that provider type information-only and blocks pending edits too. These switches never grant additional account permissions or enable external MCP writes. Local models must return valid native tool calls; models without tool support can still answer questions.

Open admin7839 > APIs & Connectors > AI Providers. Add or edit a vetted provider profile, select its adapter and exact HTTPS host, define its model and pricing policy, then add an encrypted system credential for the correct environment. Test the credential before selecting that profile as the system default. The default funded provider is used automatically for eligible hosted Lite users and eligible paid-family users unless they explicitly select BYOK or local AI.

Universal AI chat is the emergency platform gate. Paid-account AI access can disable or enable inherited Family, Max, and Lifetime access. Funded AI separately controls system-funded use, including the personal hosted Lite allowance. Lite credits can be set to zero independently under plan quotas. Disabling a credential stops new requests. Revoking it immediately destroys its stored ciphertext, but the provider-side key must still be revoked in that provider’s dashboard.

The same page includes User AI access overrides. Select one or more accounts, choose Enabled, Disabled, or Inherit, and add an optional private note. An explicit override takes precedence over the paid-account gate until it is changed back to Inherit, but it cannot bypass the Universal emergency gate. Each affected user receives the note through their enabled interface and email notification channels.

Credits and privacy

One funded credit represents USD $0.01 of actual model cost. Hosted Lite includes 20 personal credits each UTC month, shared by the user across every accessible family account. Family includes 50 monthly credits for each of up to 2 assigned users, Max includes 200 for each of up to 10, and Lifetime includes 500 for each of up to 5. Quotas reset on the first day of each UTC month; unused credits expire without rollover or proration.

When a Lite user also has a funded seat in a paid family, Racinage uses the personal Lite pool first if it can cover the complete estimated request, then the paid-family pool. A request is never split between pools. BYOK and local usage consume neither pool and never silently fall back to funded AI.

Racinage-funded paid-family usage stops when the paid period ends. BYOK and local models may continue during the normal 21-day record-access grace period. Racinage Free for Windows is a separate local app: it receives no hosted funded credits and remains local or BYOK based.

Chats and proposed tool arguments are encrypted. Usage monitoring records only minimized operational metadata such as provider, model, tokens, cost, latency, tool name, confirmation result, status, and a correlation identifier.

Read-only Progress capabilities

Progress is never added to every assistant prompt. The typed progress.summary capability reads only the authenticated participant's cached level, score, 12-week score, streak, points, and badge summary when explicitly invoked. It cannot inspect another participant, change progress, redeem points, or write leaderboard data.

The advanced Progress Coach is also read-only. Family, Max, and Lifetime include it; a Lite account may unlock it permanently with Canopy Points after reaching Branch. It requires an explicitly configured provider and consumes normal AI credits. It cannot override collection state, fair-use suppression, reward limits, plan rules, or permissions. Racinage Free does not expose local Progress data to hosted AI or companion jobs.

Review every change

Reads, explanations, navigation, highlighting, and searches do not need confirmation. Creates and edits show a preview with Apply. Bulk, relationship, archive, safe-setting, share, destructive, and public-impact actions require stronger confirmation and an impact summary.

Protected operations: the assistant cannot handle passwords, payments, purchases, provider credentials, plan changes, entitlements, super-admin data or privileges, family ownership, permissions, security controls, or plugin-data deletion.

Inline writing tools change only the local browser draft. Use the page’s normal Save action to commit the edited record.

Connect an external MCP client

External MCP is available to Family, Max, and Lifetime accounts when enabled for the rollout. Create a family-scoped personal access token from Manage > AI Features, or authorize an approved client through OAuth with PKCE. Tokens are scoped, expiring, revocable, and never grant access to another family.

The Streamable HTTP endpoint is https://racinage.com/mcp. Its only protocol is 2026-07-28: every request is self-contained, with no initialize handshake or Mcp-Session-Id. Send matching MCP-Protocol-Version, Mcp-Method, and, where required, Mcp-Name headers, plus the protocol version and client capabilities in params._meta. Clients may call server/discover to inspect supported versions and capabilities.

Call bootstrap_context before any account-bearing tool or resource. It returns an explicit, short-lived application context handle and revision for the authorized family and page. This is not a transport session: any web server instance can validate the handle from a later independent request. Reads and writes are rejected when the context is missing, expired, or stale.

Modern tool, prompt, and resource lists include deterministic cache hints. Account-specific results remain private and immediately stale; safe static catalogs may be cached briefly. OAuth authorization responses include their issuer for mix-up protection. Racinage accepts only 2026-07-28; clients that still require initialization or transport sessions must upgrade before connecting.

MCP exposes typed, permission-scoped family tools and minimized resources, not raw database access, code execution, internet search, browser or shell access, arbitrary web requests, super-admin functions, commerce changes, or private credential fields. Write tools remain phased separately from read-only access.

Racinage does not currently advertise the Tasks extension or multi-round-trip input requests. Those features will be enabled only when a reviewed long-running or external-write workflow needs them and the server can honor the full capability contract.

Published plugins may contribute reviewed mentions, minimized context, and typed tools through an optional manifest contract. Plugin tools remain scoped to the active installation and pass through the same permission, revision, idempotency, confirmation, and audit checks. A developer MCP endpoint is activated only through a reviewed adapter and exact tool allowlist.

Provider API billing and keys

Cloud AI providers manage API access and billing independently from consumer chat subscriptions. For example, a ChatGPT Pro subscription does not include OpenAI API usage. Create a restricted API key with the chosen provider, then store it only through the encrypted Racinage setup, never in source files or messages. OpenAI users can review its billing separation and API key safety.