Gateway

Check The Gateway From The Desktop App

  1. Open Settings.
  2. Select Gateway.
  3. Check the connection path and runtime status.
  4. Open Gateway preferences before changing the host, port, or launch behavior.

Gateway settings with the active connection path

What Is the Gateway?

The Gateway is the heart of Neotask, a single long-running service that manages all agent sessions, messaging channels, tool execution, and device connections. Everything flows through the Gateway.

It's a WebSocket server that listens for connections from clients (desktop app, mobile apps, web dashboard) and manages the entire AI assistant lifecycle.

Architecture

Components

Binding Modes

Mode Description
Loopback Default. Only accessible from localhost (127.0.0.1)
LAN Accessible on your local network. Auto-discoverable via Bonjour/mDNS
Tailnet Accessible through Tailscale VPN with MagicDNS
Custom Bind to a specific address

Authentication

Method Description
Token WebSocket bearer token (UUID or custom string)
Password Password-based auth (bcrypt hashed)
Trusted Proxy For reverse proxies with pre-auth headers
Local Trust Loopback connections auto-approved

Configuration

Gateway preferences contain the local runtime and launch controls. Confirm the active connection path before changing them.

Gateway preferences with local runtime controls

The Gateway is configured via neotask.json (JSON5 format). Key sections:

Section Controls
agents Agent list, defaults, workspaces
gateway Port, bind mode, auth, reload behavior
channels Per-channel config and credentials
tools Tool permissions, profiles, security
plugins Plugin loading, enabling, per-plugin config
models Provider auth, fallbacks, provider settings
skills Skill directories, per-skill configuration
browser Browser profiles, ports, headless mode
cron Scheduler configuration
session Reset rules, compaction thresholds
messages TTS settings, media policies
memory Memory indexing configuration
security Sandboxing, elevated mode, approvals

Hot Reload

Configuration changes can be applied without restarting:

Mode Behavior
Hybrid (default) Hot-apply safe changes, restart for others
Hot Only apply hot-safe changes, ignore others
Restart Restart on any reload-required change
Off No automatic reload

Restart Recovery

After an interruption, an app or Gateway update, a host restart, a crash, or a power loss, the Gateway can resume the work that was in flight: interrupted scheduled runs, interactive agent threads, and coding sessions rebound to their own repository, branch, and worktree. Three environment variables control it.

Variable Values Default Controls
NEOTASK_RESUME_AFTER_RESTART 1 or 0 Set per launch by the desktop app Master switch for restart recovery in the managed service
NEOTASK_THREAD_CONTINUATION 0, false, no, off to disable On Continuing interactive agent threads on the same session after a restart
NEOTASK_CODING_WORKTREE_BINDING 0, false, no, off to disable On Binding each coding session to its repository, branch, and worktree, plus worktree repair and safe cleanup

Notes for operators:

Remote Access

Tailscale provides secure, zero-config remote access:

SSH Tunnel

Forward the Gateway port through SSH:

Security Rules

Health Monitoring

Health Endpoint

The /health HTTP endpoint returns:

Probes

Discovery

Bonjour/mDNS

When bound to LAN, the Gateway advertises itself via multicast DNS:

Wide-Area Discovery

Discover gateways across your network with configurable timeouts. Supports both local Bonjour and Tailscale DNS discovery.

Multiple Gateways

You can run multiple Gateway instances on the same machine using profiles:

Diagnostics

Doctor

The built-in diagnostic tool checks:

It can automatically fix many issues when given permission.

Logging

Gateway logs are written to daily JSONL files: