Updated:
Tested on: MIDIFabric development build on macOS; connection tested with Codex and Claude Code

MIDIFabric’s effects are small Lua programs. We wanted people to be able to describe an effect in words and have an AI write it, using AI tools they already pay for and trust. This note is about how MIDIFabric talks to those tools, and the decisions behind it.

Why MCP

There were three ways to connect an AI:

  • Call an AI service’s API from MIDIFabric. This needs API keys and separate billing, and it is not what most people already have.
  • Run an AI command-line tool (such as codex exec or claude -p) from inside MIDIFabric. This would quietly use the person’s subscription from inside another product. We could not tell whether the services’ terms allow that, so we decided not to ship it. That is not a claim that it is forbidden; we simply did not want to ship something whose status was unclear.
  • Be an MCP server. MCP (Model Context Protocol) lets an AI tool that you run yourself, such as Codex or Claude Code, call tools that an app provides. You stay in control of the AI, under your own account. MIDIFabric never starts the AI and never touches your AI credentials.

We chose the third. MIDIFabric runs a small MCP server, and you connect your own AI tool to it.

The connection stays inside the Mac

  • The server listens only on 127.0.0.1, the Mac’s own loopback address. Nothing on your network can reach it.
  • It is off until you turn it on in Settings > AI. The default port is 8765; you can change it while the server is stopped.
  • Every request must carry an access token: 256 random bits, created once and kept until you regenerate it. The token is compared in constant time.
  • Requests with an Origin header are rejected, because no browser should ever talk to this server. The Host header must match exactly. Requests over 4 MiB are rejected.
  • All of these checks happen before the request is parsed.

To connect, MIDIFabric gives you two buttons: one copies a ready-made Codex configuration, the other a Claude Code registration command. Both contain the address and the token. MIDIFabric never edits your AI tool’s settings itself; you paste them.

Why plain http on localhost

Traffic on the loopback address never leaves the Mac. A program that could read that traffic could also read the token from the configuration file or from memory, so encryption would not protect anything more. HTTPS would also need a self-signed certificate that each AI tool has to be told to trust, which would turn “paste this command” into a much longer setup.

What the token does and does not protect

The token stops apps that do not have it from using the server. It does not stop an app running as the same user that can read your AI tool’s configuration file, the clipboard or memory, and it does not identify which program is calling; another client with the right token can connect. We chose this trade-off deliberately. The app warns that the copied configuration contains the token and should not be shared.

What the AI can and cannot do

The server offers ten tools. With them, the AI can:

  • read MIDIFabric’s authoring guides and the bundled effect templates,
  • check an effect it has written (compile and initialize it, without playing any MIDI),
  • submit a new effect or a revision of an existing one,
  • list your registered effects and read one in full, including its Lua code.

It cannot see your device list, monitor data, performances, logs or other files, and it cannot change routing, send notes or SysEx, or run commands.

What the AI reads goes to the AI company under your own account and its terms. Your prompt goes straight from you to your AI tool; it never passes through MIDIFabric. We have written down a rule for ourselves: if a future version lets AI tools read more, such as monitor data, we update the in-app description, the manual and the privacy policy in the same change.

A submission is not the same as a working effect

When the AI submits an effect, MIDIFabric checks it and keeps the latest candidate in memory. By default you open it in the editor and press Apply. You can turn on automatic registration in Settings > AI, but it applies only to submissions made after you turn it on, and it goes through the same checks and Apply as a manual registration. Placing the effect on a route is always your own action.

We keep the steps separate on purpose. “The AI submitted it” means it was received. “It passed the check” means it compiles and starts. Neither means it sounds the way you asked; only playing it tells you that.

What we have not done yet

  • We have not tested MCP connections from AI tools other than Codex and Claude Code.
  • iPad: for now this is Mac only. On iPad, we plan to let AI tools running on the same local network connect. Because the connection would then leave the device, we will decide how to protect it at that point.
  • We have not measured systematically how well AI writes effects, and we are not sure it can be measured that way. In our own use, though, it writes them well: some of the effects that come with MIDIFabric were written with AI.

The full list of what AI tools can read is in MIDIFabric’s privacy policy.

← All notes